1 to 25 of 50 Incident Response Jobs in Central London

SOC Shift Lead

Hiring Organisation
Anson Mccade
Location
City of London, London, United Kingdom
Employment Type
Permanent
join a high-performing cyber security operations team supporting critical, secure infrastructure in a 24/7 environment. This is an opportunity to lead incident response activities, mentor analysts, and play a key role in protecting complex enterprise environments from evolving cyber threats. What You'll Be Doing … Lead the investigation and response to medium and high-severity security incidents. Act as the escalation point for complex cyber security events and threat activity. Conduct root cause analysis and produce detailed incident reports. Coordinate containment, eradication and recovery activities with technical teams. Correlate data across SIEM ...

SOC Analyst

Hiring Organisation
Reed
Location
Central London, London, England, United Kingdom
Employment Type
Full-Time
Salary
£50,000 - £60,000 per annum, Inc benefits
protecting a large-scale, international technology environment. This is an excellent opportunity for a security professional with experience in SOC operations, threat detection, incident response, and threat hunting to join a mature security function that is investing heavily in its cyber capabilities. You'll work within a hybrid … cyber security alerts, incidents and threats Act as the key operational contact for the Managed Security Service Provider (MSSP), ensuring effective monitoring and incident response Prioritise and manage security incidents based on business risk and impact Conduct proactive threat hunting across endpoint, network, identity and cloud environments Develop ...

Senior Cyber Security Engineer

Hiring Organisation
NTT Global Data Centers EMEA UK ltd
Location
City of London, London, United Kingdom
Employment Type
Permanent
tasks specialized at threat hunting, SIEM/SOAR, Network Security and other operational security tasks such as performance and availability monitoring, log monitoring, security incident detection and response, security event reporting, and content maintenance (tuning). What we are looking for Key Responsibilities: Serves as a senior member … optimization of enterprise security platforms, overseeing lifecycle management including break-fix, patching, version upgrades, and integration with broader security ecosystems. Directs complex security incident response efforts across multiple vectorsendpoint protection, EDR, malware analysis, network and computer forensicsensuring rapid containment and root cause analysis. Designs and executes advanced vulnerability ...

Senior Observability Engineer

Hiring Organisation
Jobleads-UK
Location
City Of London, England, United Kingdom
report into the Senior Engineering Manager for SRE and Observability and work as an individual contributor, partnering closely with development squads, platform engineers, and incident response teams. The Bengaluru team is deeply integrated into IG's global engineering community, with real ownership and scope to shape how observability … adoption across the organisation, providing guidance and practical support to help engineering teams embed reliability targets into their day-to-day ways of working. Incident response – Join the support rota and incident response, using observability tooling to accelerate diagnosis and reduce mean time to resolution. Lead ...

Incident Response Engineer - UK Security Operations

Hiring Organisation
Jobleads-UK
Location
City of Westminster, England, United Kingdom
Google Public Sector's UK Security Operations team seeks an experienced Incident Response Engineer to join our Hampshire-based on-site team. You will monitor, detect, and respond to security incidents across critical environments, delivering private cloud security for high-assurance customers. In this mid-level role … will operate 24/7, collaborate with product teams, and help mature incident response capabilities, threat hunting, and SOC dashboards while adhering to DV clearance requirements #J-18808-Ljbffr ...

Head of Cyber Claims - International

Hiring Organisation
Jobleads-UK
Location
City Of London, England, United Kingdom
accountable for developing and implementing cyber claims strategy, best practice and capability across those offices, ensuring a consistent and effective approach to service delivery, incident response and client support. What you’ll do Lead the development and implementation of international cyber claims strategy across jurisdictions outside … required, acting as a referral point to support and supplement local expertise. Establish and embed best practice approaches to cyber claims handling, both initial response and coverage, across global offices. Build and oversee local cyber claims capability in key international markets to ensure consistency of service provision and standards ...

Information Security Team Lead

Hiring Organisation
Jobleads-UK
Location
City Of London, England, United Kingdom
optimise controls across Azure, M365, and infrastructure environments Lead hardening initiatives across IAM, PAM, AD, and network security Drive security automation and DevSecOps practices Incident Response & Threat Detection Lead real‐time response to security incidents Oversee SIEM/SOAR integration, alerting, and playbooks Conduct investigations using … Looking For 7 years in cybersecurity, with 3–4 years in a lead/principal capacity Experience spanning security engineering, SOC/incident response Strong expertise across: SIEM (Sentinel, Splunk, LogRhythm), EDR/XDR (Defender, CrowdStrike, SentinelOne), IAM/PAM/identity security, Vulnerability tooling (Tenable, Pentera, etc. ...

Platform & Workplace Engineering Director

Hiring Organisation
Jobleads-UK
Location
City Of London, England, United Kingdom
responsible for leading both our Cloud Platform and Enterprise Service orgs: Leading and developing two engineering teams — Cloud Platform (cloud infrastructure, observability, SRE, incident response) and Enterprise Services (IT support, IAM, Okta, Slack and core SaaS) — setting technical direction, hiring and performance standards across both. Delivering the reliability … performance and cost-efficiency of the cloud platform underpinning production services, including SLOs, on‐call and incident response practices, and post‐incident learning, in line with the broader infrastructure strategy. Executing the roadmap for enterprise services and identity, treating internal IT as an engineering discipline — automation‐first ...

SOC Manager

Hiring Organisation
Randstad Technologies Recruitment
Location
City of London, London, United Kingdom
Employment Type
Contract
Contract Rate
£600 - £700/day Negotiable
leadership position-not a hands-on technical analyst role. You will take full ownership of the Cyber Security Operations Centre (CSOC), driving strategy, managing incident response, and directing internal teams and external vendors. Key Responsibilities Define and lead the CSOC strategy, operations, and governance. Take command of major … incident response, managing remediation and stakeholder communication. Oversee threat intelligence, vulnerability management, and security monitoring capabilities. Manage relationships with external agencies, Managed Security Service Providers (MSSPs), and technology partners. What We Need From You Proven experience as a SOC Manager (previous leadership experience is essential; this ...

Lead Product Manager AIOPs

Hiring Organisation
Jobleads-UK
Location
City Of London, England, United Kingdom
partner with AIOps vendors, IT Operations, infrastructure, platform engineering, SRE, service management, and application teams to reduce operational noise, improve service reliability, and accelerate incident response across a complex enterprise environment. Responsibilities Execute the enterprise AIOps strategy, operating model, and adoption plan across the organization. Build scalable observability … service management, and application teams to operationalize AIOps capabilities at scale. Establish governance, success metrics, and operating rhythms to measure improvements in alert quality, incident reduction, MTTD, MTTR, service health, and product adoption. Drive adoption of AIOps capabilities by aligning use cases, implementation priorities, and operational workflows with business ...

Blockchain Security Operations Vice President

Hiring Organisation
Jobleads-UK
Location
City Of London, England, United Kingdom
vulnerabilities and compromises, utilizing advanced tools and techniques to detect anomalies and contribute to the development of strategies for security investigation, threat mitigation, and incident response Collaborate with cross-functional teams to ensure a coordinated approach to blockchain and enterprise security, sharing insights, and promoting best practices across … Degree in Computer Science, Cybersecurity, Data Science, or related disciplines 5+ years of experience in cybersecurity operations, with a focus on threat detection, incident response, and security infrastructure management Demonstrated expertise in multiple security domains, including network security, malware analysis, threat hunting, and security architecture and design, with ...

Blockchain Cyber Intelligence Vice President

Hiring Organisation
Jobleads-UK
Location
City Of London, England, United Kingdom
vulnerabilities and compromises, utilizing advanced tools and techniques to detect anomalies and contribute to the development of strategies for security investigation, threat mitigation, and incident response Produce actionable threat intelligence products including IOC development, exploit analysis reports, and threat actor tracking to inform detection engineering and security operations … Computer Science, Cybersecurity, Data Science, or related disciplines 5+ years of experience in cybersecurity threat intelligence or operations, with a focus on threat detection, incident response, and security infrastructure management Demonstrated expertise in multiple security domains, including network security, malware analysis, threat hunting, threat intelligence production, and security ...

SOC Manager - DV Cleared

Hiring Organisation
CBSbutler Holdings Limited trading as CBSbutler
Location
Hounslow, London, Westminster Abbey, United Kingdom
Employment Type
Contract
Contract Rate
£550 - £600/day
with technical awareness , placing you at the centre of a live Security Operations Centre where you'll maintain situational awareness across multiple domains, coordinate incident response, and ensure effective operational decision-making. You'll act as the operational lead within a fast-paced control room environment, working closely … domains. Monitor live environments and assess alerts and incidents in real time. Perform initial triage and validation of alerts, reducing noise and ensuring accurate incident classification. Manage incident prioritisation and escalation in accordance with operational procedures. Coordinate response activities across SOC, NOC, Infrastructure and Security teams. Support ...

Cyber Security Consultant

Hiring Organisation
Experis
Location
West End, London, United Kingdom
Employment Type
Contract
Contract Rate
£560 - £610/day
Cyber Security Consultant - Incident and Vulnerability Management Duration: 30/11/2026 Pay: up to £610 per day (umbrella) Location: Preston, London or Birmingham UK, Hybrid - 30% office 70% home CONTRACTOR MUST BE MOD SC CLEARED AND BE A SOLE UK NATIONAL Role Summary The Security Incident … transition to a multi-supplier (SIAM) model within a Defence environment. The role focuses on understanding, aligning and governing existing high-severity security incident management (S3/S4) and vulnerability management processes across suppliers. Ensuring a consistent, risk-based approach in line with client policy and regulatory requirements, supported ...

SC Cleared DevOps Engineer (On-prem)

Hiring Organisation
VIQU IT Recruitment
Location
City of London, London, United Kingdom
Employment Type
Contract
Contract Rate
£600 - 800 per day + Inside IR35
release processes. * Familiar with Observability functions, designing and operating end-to-end logging, metrics, tracing, dashboards, and alerting systems using ELK, Splunk, Prometheus, Grafana. * Incident-management leadership — owning major incident response, prioritisation, real-time coordination, stakeholder communication, and supporting post-incident reviews and reliability improvements. * Thorough ...

Crisis Management & Scenario Testing Specialist

Hiring Organisation
WTW
Location
City of London, London, England, United Kingdom
Employment Type
Full-Time
Salary
Competitive salary
testing capabilities. The successful candidate will play a critical role in maintaining operational readiness across the organisation by coordinating crisis management activities, supporting major incident response efforts, managing scenario testing programmes, and driving remediation and continuous improvement initiatives. The role will work closely with business, technology, cyber security … operation of the crisis management framework and act as a key coordinator during significant disruption events, helping ensure effective response, communication, governance and recovery activities across the enterprise. What you'll bring: Proven experience within operational resilience, crisis management, business continuity, incident management, operational risk or a related ...

Duty Manager - NOC/SOC - DV Cleared

Hiring Organisation
CBSbutler Holdings Limited trading as CBSbutler
Location
Hounslow, London, Westminster Abbey, United Kingdom
Employment Type
Permanent
Salary
£60000 - £65000/annum +£!0K Bonus
This is a unique hybrid position that combines operational leadership with technical awareness . You'll take ownership of the live operational picture, coordinating incident response across cyber, network, infrastructure and physical security teams while ensuring informed, timely decision-making. This role is ideal for someone who thrives … fast-paced control room environment and can confidently lead operational response without needing to be a deep technical specialist. Key Responsibilities Maintain a single operational view across cyber, network, service and physical security domains. Monitor live operational environments and assess alerts and incidents in real time. Perform initial triage ...

Lead DevOps Engineer

Hiring Organisation
Jobleads-UK
Location
City Of London, England, United Kingdom
cloud infrastructure, delivery platforms, and operational capabilities. You will remain hands‐on across the engineering lifecycle, from architecture and infrastructure design through deployment, observability, incident response, and continuous improvement. We expect you to operate with a high degree of autonomy, make strategic and architectural decisions within your area … incidents, identify root causes, and turn lessons into measurable engineering improvements. Use approved generative AI tools for infrastructure development, automation, testing, pipeline improvement, documentation, incident analysis, and troubleshooting. Provide technical guidance through design reviews, code reviews, pairing, coaching, and hands‐on problem‐solving. WHAT YOU’LL BRING: Significant hands ...

Production Engineer

Hiring Organisation
Jobleads-UK
Location
City Of London, England, United Kingdom
trade flow, and post-trade issues. Lead the ‘follow the sun’ support model coordination, working closely with global teams in APAC and US. Drive incident management practices, trend identification, and post-mortem analysis. Collaborate with development teams to influence platform improvements based on support insights. Occasional weekend work will … with the resilience to handle high-pressures production incidents Desired Experience with Site Reliability Engineering (SRE) practices, including monitoring, incident response, and post-mortem analysis Proven experience applying AI or machine-learning models to optimise workflows, identify patterns, and drive intelligent automation solutions Hands-on experience with containerization ...

Wiz Security Engineer

Hiring Organisation
VIQU IT
Location
London, South Kensington, United Kingdom
Employment Type
Contract
Contract Rate
£450 - £550/day
Cloud Hardening: Design secure baselines for Kubernetes and cloud-native resources. Vulnerability Management: Prioritize and remediate software supply chain risks from development to production. Incident Response: Scale detection and response solutions to triage alerts and stop malicious activity. Experience: 5 to 7+ years in cloud security engineering ...

Head of Information Security

Hiring Organisation
Jobleads-UK
Location
City Of London, England, United Kingdom
including IAM, SIEM, and data classification Anticipate emerging threats, leverage AI/ML for predictive security, and set the technology vision Lead the Security Incident Response Programme Governance, risk, and compliance (GRC) Define and own the GRC programme, including the ISMS, policy framework, risk registers, and audit readiness ...

Platform Operations Director

Hiring Organisation
ClearCourse
Location
City of London, London, United Kingdom
Relationships: CTTO - Direct line manager. Governance, infrastructure risk, and FinOps accountability. CISO (Head of Security) - Close working relationship. Security operations implementation, IAM policy, and incident escalation. Director of Platform Engineering - Coordinates on DevSecOps integration and CI/CD infrastructure requirements. • Head of Infrastructure & Cloud - Direct report. Hosting strategy, cloud … internal IT operations across a distributed estate - multiple sites or subsidiaries Commercial awareness: has owned cloud cost management and FinOps outcomes with measurable results Incident management and on-call leadership - has run major incident response at group level Strong vendor management: MSP relationships, colocation contracts, cloud provider ...

Infrastructure Engineer

Hiring Organisation
Halian Technology Limited
Location
Central London, London, United Kingdom
Employment Type
Permanent
Salary
£70,000
while contributing to our modern infrastructure strategy. What youll be doing As an Infrastructure Engineer, you will: Participate in a 24/7 major-incident on-call rota Develop, support, and enhance infrastructure across multiple office locations and cloud environments Design and implement standardised templates, configuration baselines, and self … third-party vendors to ensure the health and availability of hosted or outsourced services Collaborate with the Security Operations Centre on threat detection and incident response activities Take ownership of incidents and problems through to resolution or formal handover Conduct root-cause analysis to identify and address underlying ...

Security Platform Engineer, Red Team, UK Security Operations

Hiring Organisation
Jobleads-UK
Location
City of Westminster, England, United Kingdom
path reviews. You will build and maintain the platforms necessary for developing and deploying proof-of-concept (PoC) exploits and validations, ensuring detection and response capabilities across cloud infrastructure. In this engineering-centric role, you will require deep technical expertise in cloud environments, Kubernetes security, and platform automation. … will work closely with Incident Response, Platform Engineering and Security Architects to ensure that security validation and defensive hardening are seamlessly integrated into infrastructure and operational workflows. Your role will require participation in a rotating on-call schedule outside of core business hours and over the weekend ...

Threat Detection Engineer - Hybrid / Remote

Hiring Organisation
Additional Resources
Location
Westminster, City of Westminster, Greater London, United Kingdom
Employment Type
Permanent
Salary
£60000 - £80000/annum
that supports precision medicine Key Responsibilities Design and develop threat-led detections using threat intelligence and threat-hunting outputs Create novel analytic techniques for incident detection Collaborate with an MSP SOC to maintain and tune the detection catalogue Build automated reporting dashboards using Microsoft Sentinel workbooks Support security initiatives … Employment Business and an Employment Agency as defined within The Conduct of Employment Agencies & Employment Businesses Regulations 2003. Keywords: Cyber Threat Engineer, Detection & Response Engineer, SIEM Engineer, Security Detection Engineer,T hreat Hunting Engineer, Security Automation Engineer, SOC Engineer, Incident Response Engineer, Cloud Security Engineer, Network Security ...