1 to 25 of 48 Incident Response Jobs in Central London

Senior Cyber Security Engineer

Hiring Organisation
NTT Global Data Centers EMEA UK ltd
Location
City of London, London, United Kingdom
Employment Type
Permanent
tasks specialized at threat hunting, SIEM/SOAR, Network Security and other operational security tasks such as performance and availability monitoring, log monitoring, security incident detection and response, security event reporting, and content maintenance (tuning). What we are looking for Key Responsibilities: Serves as a senior member … optimization of enterprise security platforms, overseeing lifecycle management including break-fix, patching, version upgrades, and integration with broader security ecosystems. Directs complex security incident response efforts across multiple vectorsendpoint protection, EDR, malware analysis, network and computer forensicsensuring rapid containment and root cause analysis. Designs and executes advanced vulnerability ...

Senior Observability Engineer

Hiring Organisation
Jobleads-UK
Location
City Of London, England, United Kingdom
report into the Senior Engineering Manager for SRE and Observability and work as an individual contributor, partnering closely with development squads, platform engineers, and incident response teams. The Bengaluru team is deeply integrated into IG's global engineering community, with real ownership and scope to shape how observability … adoption across the organisation, providing guidance and practical support to help engineering teams embed reliability targets into their day-to-day ways of working. Incident response – Join the support rota and incident response, using observability tooling to accelerate diagnosis and reduce mean time to resolution. Lead ...

Information Security Manager

Hiring Organisation
Jobleads-UK
Location
City of Westminster, England, United Kingdom
proportionate controls are in place. Provide informed input into security testing scope (e.g. Penetration testing, configuration reviews) and review remediation activity with suppliers. Support incident response and operational infosec activities as required, providing cover and acting as an all-round contributor in a small team. Maintain awareness … experience in an information security role with significant exposure to grc, alongside working knowledge of broader cyber security disciplines (e.g. Supplier assurance, security testing, incident response, security operations). Experience of iso 27001 isms implementation and management, and certification process (working with external and internal auditors). Strong ...

Senior Cyber Security Engineer

Hiring Organisation
The Fidelis Partnership
Location
City Of London, England, United Kingdom
monthly reporting. Deliver secure configuration and compliance reporting across the estate, supporting a measurable uplift in security maturity against NIST CSF. Security Operations and Incident Response: Act as the second cyber escalation point within the 24/7 security operating model, providing technical investigation, containment and response as part of the cyber on-call rota and supporting post-incident reviews. Onboard and manage the day-to-day relationship with the outsourced SOC/MDR provider, establishing operational handover processes and driving improvement in detection and response performance (MTTD/MTTR). Provide security input ...

SOC Analyst

Hiring Organisation
Experis
Location
City of London, London, United Kingdom
Employment Type
Contract
Contract Rate
£400 - £500/day
client is seeking a SOC Analyst to join a security operations team in London. The role is focused on real-time monitoring, investigation, and incident response across a modern enterprise security environment. - Key Responsibilities Monitor, triage, and respond to security alerts across multiple platforms, including Microsoft and endpoint … Optimise and tune detection rules, policies, and alerting mechanisms to improve SOC efficiency. Collaborate with internal teams to support security operations, threat analysis, and incident recovery. Produce clear incident documentation, reports, and recommendations for continuous improvement. Contribute to maintaining and enhancing SOC processes, runbooks, and operational workflows. Required ...

Cyber Security Analyst

Hiring Organisation
Digital Waffle
Location
City of London, London, United Kingdom
Analyse logs from endpoints, networks, cloud services and security tools to detect suspicious behaviour Escalate incidents where appropriate and work closely with engineering and incident response teams Develop and improve SIEM detection rules and alert tuning to reduce false positives Produce clear incident reports and maintain accurate … documentation Participate in the on-call rota and support major incident response when required Contribute to the continuous improvement of SOC processes, tooling and operational procedures Skills & Experience Experience working withi n a 24/7 Security Operations Centre ( SOC) or equivalent cyber security environment Strong hands ...

Soc Operations Manager

Hiring Organisation
Morson Edge
Location
City of London, London, United Kingdom
Employment Type
Contract
Contract Rate
£800 - 950 per day
apply. The Role - As SOC Operations Manager, you'll lead the day-to-day operation of the Security Operations Centre, ensuring security monitoring, incident response and cyber defence capabilities are operating effectively. You'll be responsible for developing the SOC function, leading analysts and engineers, improving operational maturity … excellence and stakeholder management. Responsibilities - Lead and develop a high-performing SOC team, providing coaching, mentoring and technical leadership. Oversee the detection, investigation and response to cyber security incidents. Drive continual improvement across SOC processes, playbooks and operational procedures. Monitor and improve key SOC performance metrics including MTTD, MTTR ...

Platform & Workplace Engineering Director

Hiring Organisation
Jobleads-UK
Location
City Of London, England, United Kingdom
responsible for leading both our Cloud Platform and Enterprise Service orgs: Leading and developing two engineering teams — Cloud Platform (cloud infrastructure, observability, SRE, incident response) and Enterprise Services (IT support, IAM, Okta, Slack and core SaaS) — setting technical direction, hiring and performance standards across both. Delivering the reliability … performance and cost-efficiency of the cloud platform underpinning production services, including SLOs, on‐call and incident response practices, and post‐incident learning, in line with the broader infrastructure strategy. Executing the roadmap for enterprise services and identity, treating internal IT as an engineering discipline — automation‐first ...

Information Security Senior Consultant

Hiring Organisation
Jobleads-UK
Location
City Of London, England, United Kingdom
Role Title: Information Security Senior Consultant – Detection and Response (Europe & Americas) About Westpac: Westpac is one of the world’s oldest banks and a leading financial services organisation with a strong presence across Australia, New Zealand and key international markets. We support individuals, businesses and institutions through a broad … with our customers and communities. About the Team: This role is a core part of Westpac’s global 24/7 cybersecurity monitoring and incident response capability - the bank’s first line of cyber defence. How will I help? You will be responsible for analysing and responding ...

Cyber Threat Lead

Hiring Organisation
Jobleads-UK
Location
City Of London, England, United Kingdom
track the cyber threats that BA faces and produce finished intelligence products for stakeholders across the organisation Support the Cyber Threat Intelligence and Cyber Incident Managers during cyber incident response activities Support the implementation of the broader BA/IAG Cyber Strategy What you’ll bring … stakeholders Experience in threat modelling using frameworks such as STRIDE, PASTA, attack trees (Desirable) Ability to remain calm and prioritise under pressure Understanding of incident response methodology Strong understanding of actor methodology including their tactics, techniques and procedures Your experience: Holding or working towards relevant cyberintelligence certifications e.g. ...

SOC Engineer

Hiring Organisation
Invitise Ltd
Location
City of London, London, United Kingdom
Employment Type
Contract, Work From Home
Contract Rate
Up to £450 per day
primarily remote role with occasional on-site visits to London. You will be working within a security operations function, supporting the monitoring, detection and response to security threats across the organisation's estate. You will bring solid hands-on experience across SIEM and log management tooling, working independently … following: Hands-on experience with Splunk in a SOC environment Cribl experience for log management and data pipeline optimisation Security monitoring, threat detection and incident response Working within a security operations centre at a mid-senior level SC clearance held or ability to pass Interested? Please apply below. ...

SOC Manager - DV Cleared

Hiring Organisation
CBSbutler Holdings Limited trading as CBSbutler
Location
Hounslow, London, Westminster Abbey, United Kingdom
Employment Type
Contract
Contract Rate
£550 - £600/day
with technical awareness , placing you at the centre of a live Security Operations Centre where you'll maintain situational awareness across multiple domains, coordinate incident response, and ensure effective operational decision-making. You'll act as the operational lead within a fast-paced control room environment, working closely … domains. Monitor live environments and assess alerts and incidents in real time. Perform initial triage and validation of alerts, reducing noise and ensuring accurate incident classification. Manage incident prioritisation and escalation in accordance with operational procedures. Coordinate response activities across SOC, NOC, Infrastructure and Security teams. Support ...

Duty Manager - NOC/SOC - DV Cleared

Hiring Organisation
CBSbutler Holdings Limited trading as CBSbutler
Location
Hounslow, London, Westminster Abbey, United Kingdom
Employment Type
Permanent
Salary
£60000 - £65000/annum +£!0K Bonus
This is a unique hybrid position that combines operational leadership with technical awareness . You'll take ownership of the live operational picture, coordinating incident response across cyber, network, infrastructure and physical security teams while ensuring informed, timely decision-making. This role is ideal for someone who thrives … fast-paced control room environment and can confidently lead operational response without needing to be a deep technical specialist. Key Responsibilities Maintain a single operational view across cyber, network, service and physical security domains. Monitor live operational environments and assess alerts and incidents in real time. Perform initial triage ...

Production Engineer

Hiring Organisation
Jobleads-UK
Location
City Of London, England, United Kingdom
trade flow, and post-trade issues. Lead the ‘follow the sun’ support model coordination, working closely with global teams in APAC and US. Drive incident management practices, trend identification, and post-mortem analysis. Collaborate with development teams to influence platform improvements based on support insights. Occasional weekend work will … with the resilience to handle high-pressures production incidents Desired Experience with Site Reliability Engineering (SRE) practices, including monitoring, incident response, and post-mortem analysis Proven experience applying AI or machine-learning models to optimise workflows, identify patterns, and drive intelligent automation solutions Hands-on experience with containerization ...

Cyber Security Analyst

Hiring Organisation
Norton Blake
Location
City of London, London, United Kingdom
Anomaly Detection (NAD), and cloud security technologies. Oversee vulnerability management and coordinate remediation efforts across global systems. Design and operate SOAR workflows to automate response playbooks and improve operational efficiency. Support the operational management of Secure Email Gateways (SEG), Secure Web Gateways (SWG), Firewalls, and CASB. Monitor third-party … vendor SLAs and participate in service performance reviews. Maintain accurate operational documentation, security playbooks, and incident reports. What We Are Looking For Essential Experience & Skills: 4–6 years of experience within cyber security operations (SOC, security tooling, incident response). Strong hands-on experience with Microsoft Entra ...

Production Engineer

Hiring Organisation
Jobleads-UK
Location
City Of London, England, United Kingdom
order routing, trade flow, and post-trade issuesLead the 'follow the sun' support model coordination, working closely with global teams in APAC and USDrive incident management practices, trend identification, and post-mortem analysis. Collaborate with development teams to influence platform improvements based on support insightsOccasional weekend work will … hoursPositive approach to the day-to-day, with the resilience to handle high-pressure production incidentsDesiredExperience with Site Reliability Engineering (SRE) practices, including monitoring, incident response, and post-mortem analysisProven experience applying AI or machine-learning models to optimise workflows, identify patterns, and drive intelligent automation solutionsHands ...

SRE Managing Consultant

Hiring Organisation
Akkodis
Location
City of London, London, United Kingdom
Employment Type
Permanent
Salary
£90000 - £100000/annum
modern engineering and traditional ITSM/ITIL practices Establish SLIs, SLOs, and Error Budgets Shape observability strategies using metrics, logs, and traces Design incident response models and post-incident learning loops Reduce toil through automation and engineering excellence Deliver SRE capability assessments and roadmaps … Looking For Extensive experience in SRE, cloud operations, or DevOps Proven consulting or advisory background Experience with AWS, Azure, or GCP Strong observability and incident management expertise Ability to obtain UK SC clearance Modis International Ltd acts as an employment agency for permanent recruitment and an employment business ...

DevSecOps Engineer

Hiring Organisation
Digital Waffle
Location
City of London, London, United Kingdom
practice implementation Work closely with development teams to identify and remediate security vulnerabilities Develop monitoring, logging and compliance controls across cloud platforms Support security incident response and vulnerability remediation activities Promote DevSecOps best practices and contribute to a strong security culture Skills & Experience Commercial experience in a DevSecOps ...

Head of Information Security

Hiring Organisation
Jobleads-UK
Location
City Of London, England, United Kingdom
including IAM, SIEM, and data classification Anticipate emerging threats, leverage AI/ML for predictive security, and set the technology vision Lead the Security Incident Response Programme Governance, risk, and compliance (GRC) Define and own the GRC programme, including the ISMS, policy framework, risk registers, and audit readiness ...

Platform Operations Director

Hiring Organisation
ClearCourse
Location
City of London, London, United Kingdom
Relationships: CTTO - Direct line manager. Governance, infrastructure risk, and FinOps accountability. CISO (Head of Security) - Close working relationship. Security operations implementation, IAM policy, and incident escalation. Director of Platform Engineering - Coordinates on DevSecOps integration and CI/CD infrastructure requirements. • Head of Infrastructure & Cloud - Direct report. Hosting strategy, cloud … internal IT operations across a distributed estate - multiple sites or subsidiaries Commercial awareness: has owned cloud cost management and FinOps outcomes with measurable results Incident management and on-call leadership - has run major incident response at group level Strong vendor management: MSP relationships, colocation contracts, cloud provider ...

Security Platform Engineer, Red Team, UK Security Operations

Hiring Organisation
Jobleads-UK
Location
City of Westminster, England, United Kingdom
path reviews. You will build and maintain the platforms necessary for developing and deploying proof-of-concept (PoC) exploits and validations, ensuring detection and response capabilities across cloud infrastructure. In this engineering-centric role, you will require deep technical expertise in cloud environments, Kubernetes security, and platform automation. … will work closely with Incident Response, Platform Engineering and Security Architects to ensure that security validation and defensive hardening are seamlessly integrated into infrastructure and operational workflows. Your role will require participation in a rotating on-call schedule outside of core business hours and over the weekend ...

Threat Detection Engineer - Hybrid / Remote

Hiring Organisation
Additional Resources
Location
Westminster, City of Westminster, Greater London, United Kingdom
Employment Type
Permanent
Salary
£60000 - £80000/annum
that supports precision medicine Key Responsibilities Design and develop threat-led detections using threat intelligence and threat-hunting outputs Create novel analytic techniques for incident detection Collaborate with an MSP SOC to maintain and tune the detection catalogue Build automated reporting dashboards using Microsoft Sentinel workbooks Support security initiatives … Employment Business and an Employment Agency as defined within The Conduct of Employment Agencies & Employment Businesses Regulations 2003. Keywords: Cyber Threat Engineer, Detection & Response Engineer, SIEM Engineer, Security Detection Engineer,T hreat Hunting Engineer, Security Automation Engineer, SOC Engineer, Incident Response Engineer, Cloud Security Engineer, Network Security ...

M365 Security Consultant (App sec/SCA/SAST/DAST , CI/CD Security, DevSecOps )

Hiring Organisation
Jobleads-UK
Location
City Of London, England, United Kingdom
across endpoints, identities, networking, cloud, and collaboration platforms in the Microsoft ecosystem. Handle L2-level incidents leveraging Microsoft Sentinel and Microsoft Defender tools. Support incident response, triage, threat modelling, and vulnerability remediation within Azure-hosted environments. Create, run, and troubleshoot Azure Logic Apps, playbooks, and Sentinel automation components. … Sentinel (architecture, deployment, analytics rules, workbooks, playbooks); Microsoft Defender for Endpoint and Defender for Cloud; SIEM/SOC operations; Azure Logic Apps; vulnerability remediation; incident response. Threat Hunting & Detection Hands‐on experience using KQL, Microsoft Defender XDR, and threat intelligence sources to hunt threats and support investigations. Cyber Defence ...

Site Reliability Engineer (SRE) / Platform Engineer

Hiring Organisation
Adecco
Location
City of London, London, United Kingdom
Employment Type
Contract
enable efficient and reliable software delivery. Work closely with development teams to improve platform resilience, scalability, and operational performance. Implement monitoring, alerting, and incident response processes to support production systems. Drive automation initiatives to reduce operational overhead and improve system reliability. We're Looking For: Proven experience … using FastAPI . Strong knowledge of Terraform and Infrastructure as Code principles. Experience designing highly available, resilient, and secure cloud environments. Strong troubleshooting and incident management skills within production environments. Experience with CI/CD pipelines, Git, GitHub, and DevOps best practices . Strong understanding of cloud networking concepts ...

Infrastructure Engineer

Hiring Organisation
Halian Technology Limited
Location
Central London, London, United Kingdom
Employment Type
Permanent
Salary
£70,000
while contributing to our modern infrastructure strategy. What youll be doing As an Infrastructure Engineer, you will: Participate in a 24/7 major-incident on-call rota Develop, support, and enhance infrastructure across multiple office locations and cloud environments Design and implement standardised templates, configuration baselines, and self … third-party vendors to ensure the health and availability of hosted or outsourced services Collaborate with the Security Operations Centre on threat detection and incident response activities Take ownership of incidents and problems through to resolution or formal handover Conduct root-cause analysis to identify and address underlying ...