1 to 25 of 95 Incident Response Jobs in London

Level 2 SOC Analyst

Hiring Organisation
Oscar Technology
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
£33,000 - £40,000 per annum
proactive and skilled Level 2 SOC Analyst to support their growing client base. This role is ideal for someone with hands-on SOC or incident response experience who enjoys analysing complex security events and helping strengthen defensive operations. As a Level 2 SOC Analyst, you will … ownership of advanced investigations and contributing to continuous improvement of our security monitoring services. You'll work across a variety of customer environments, supporting incident response, enhancing detection logic, and ensuring threats are identified and contained quickly. This position includes participation in an on-call rotation for high

Deputy Chief Privacy Officer

Hiring Organisation
A&O Shearman
Location
East London, London, United Kingdom
Employment Type
Permanent, Work From Home
firms risk appetite, client expectations and legal and regulatory changes and attitudes Manage and provide day to day leadership and advice on data incident response globally, ensuring appropriate action is taken to minimize the risks associated with actual or potential exfiltration of data, including forensic document review, legal … regulatory reporting, client and individual notifications and reputation management. Act as a trusted adviser to partners, functional heads and others on data incident management, response and remediation worldwide To support the CPO and CISO in the formulation and delivery of the firms cyber and incident response

Operational security management specialist

Hiring Organisation
BP Energy
Location
Sunbury-On-Thames, London, United Kingdom
Employment Type
Work From Home
will support information security and risk activities within Operational Security Management. Our Security Operations Center (SOC) is the frontline of defense, responsible for incident response, initial triage, and proactive threat hunting. You will work closely with the Cyber Security Incident Response Team (CSIRT) and business units … work as part of a rotation. Where weekend work is done days off during the week will be provided. What you will deliver: Perform incident detection and response within the SOC, including analysis and escalation of security alerts. Investigate security incidents and ensure accurate documentation in SIEM

Cyber Insurance Incident Leader - FINEX

Hiring Organisation
WTW
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
Competitive salary
Secure your future with our defined contribution pension scheme, featuring matched contributions up to 10% from the company. The Role As a Cyber Insurance Incident Manager at Willis, you will serve as an advisor and support lead for internal colleagues and clients facing cyber incidents. This role requires strong … communication skills to support clients through high-stress events such as ransomware attacks, data breaches, and business email compromises. You will help ensure rapid response, align incident actions with insurance policy terms, and manage relationships with insurers, legal counsel, and technical vendors to protect client interests and minimize

Tech lead - SOC responder

Hiring Organisation
Colt Technology Services
Location
Central London, London, United Kingdom
Employment Type
Permanent, Work From Home
with global impact upon Colt, business units, partners, and customers. While working as part of this team, the successful individual will provide world class incident response functions to detect, protect, respond, and sustain operations within cyberspace. Job description: Support SOC Manager to deliver the followingSIEM, IR tools platform … activities, Technology escalation support, Security Solution assessment, build activities , existing Service maturing and Build activities assist Analyse potential infrastructure security incidents to determine if incident qualifies as a legitimate security breach Establishing and governing the security incident response processes, investigations and security operational processes. Maintenance and enhancement

Microsoft Cloud Security Architect Lead

Hiring Organisation
WTW
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
Competitive salary
Role: Agentic AI for Security & Sentinel Advanced Capabilities Lead the adoption and integration of Agentic AI for Security to enable autonomous threat detection, adaptive response, and continuous security posture improvement. Architect and optimise Microsoft Sentinel for SIEM, UEBA, and threat intelligence integration, leveraging Microsoft Sentinel Model Context Protocol … advanced context-aware analytics and automation. Develop and maintain security analytics and data pipelines within Sentinel Data Lake to support large-scale threat detection, incident response, and threat hunting, while optimizing cost and enabling Agentic AI-driven security operations. Integrate and automate security workflows using Microsoft Sentinel Graph

Security Operations Manager

Hiring Organisation
Urbanberry Recruitment Ltd
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
Salary negotiable
getting organised ahead of their anticipated growth. We’re focused on finding them a Security Operations (SecOps) Manager to enhance their cybersecurity, oversee incident response and ensure the protection of critical systems and data. This position also includes line management of two team members who support IT operations … week, 3 days from home. Key Responsibilities Monitor and analyse alerts from SIEM, EDR, firewalls, and other security platforms Lead and coordinate incident response activities Manage security projects including DPIAs, supplier assurance, penetration testing, and remediation Support evaluation and implementation of emerging technology, including AI security tools Conduct

Security Operations Manager For Travel Company

Hiring Organisation
Urbanberry Recruitment Ltd
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
Salary negotiable
getting organised ahead of their anticipated growth. We’re focused on finding them a Security Operations (SecOps) Manager to enhance their cybersecurity, oversee incident response and ensure the protection of critical systems and data. This position also includes line management of two team members who support IT operations … week, 3 days from home. Key Responsibilities Monitor and analyse alerts from SIEM, EDR, firewalls, and other security platforms Lead and coordinate incident response activities Manage security projects including DPIAs, supplier assurance, penetration testing, and remediation Support evaluation and implementation of emerging technology, including AI security tools Conduct

Threat Intelligence Specialist

Hiring Organisation
Computacenter
Location
London, UK
Employment Type
Full-time
trends, ensuring we stay one step ahead of security threats. Our team combines specialist skills in Threat Intelligence, Threat Hunting, Malware Analysis, Digital Forensics, Incident Response, and Threat Modelling. At our core, we are driven by a mission to "investigate, collate and locate": to unearth new threats, gather … Organisational Aims: Collection of Priority Intelligence Requirements from key stakeholders. Effective tracking of intelligence activities against these PIRs. Reporting of service quality against KPIs. Incident Response Support: Required to work out of hours, when situation dictates, to support Incident Response activities. What you'll need Current

Security Operations Centre Analyst

Hiring Organisation
INTEC SELECT LIMITED
Location
City of London, London, England, United Kingdom
Employment Type
Full-Time
Salary
Salary negotiable
posture through continuous monitoring and analysis. Key Responsibilities Investigate and respond to cyber security incidents, including malware outbreaks, phishing attempts, and insider threats. Lead incident response efforts and conduct digital forensics. Enhance detection and response capabilities through process improvements and automation. Monitor alerts from SOC tools … perform root cause analysis. Collaborate with IT and security teams to remediate vulnerabilities. Gather and analyse threat intelligence to inform detection strategies. Maintain detailed incident records and conduct post-incident reviews. Technical Skills Hands-on experience with SIEM, EDR, IDS/IPS, and SOAR platforms. Strong knowledge

Senior Security Engineer - SIEM, KQL

Hiring Organisation
Harvey Nash
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
£500 - £600 per day
Case Development: Develop and refine detection rules based on threat intelligence and attack patterns Continuously improve detection efficacy and reduce false positives Security Monitoring & Incident Response: Monitor systems for anomalies and malicious activity Contribute to threat hunting and incident response playbooks Provide expert guidance on securing

Senior Security Engineer - SIEM, KQL

Hiring Organisation
Harvey Nash
Location
London, South East, England, United Kingdom
Employment Type
Contractor
Contract Rate
£500 - £600 per day
Case Development: Develop and refine detection rules based on threat intelligence and attack patterns Continuously improve detection efficacy and reduce false positives Security Monitoring & Incident Response: Monitor systems for anomalies and malicious activity Contribute to threat hunting and incident response playbooks Provide expert guidance on securing

Head of IT Security - Wembley

Hiring Organisation
Adecco
Location
Wembley, Middlesex, United Kingdom
Employment Type
Permanent
Salary
GBP 90,000 - 100,000 Annual
will own the strategic and operational delivery of all information and cyber security activities. You'll develop and implement robust security policies, oversee incident response, and ensure compliance with GDPR, PCI DSS, ISO 27001, and Cyber Essentials Plus. You will be the single point of accountability … Cyber Essentials Plus, and ISO/IEC 27001:2022 aligned practices. Lead Data Protection Impact Assessments (DPIAs), data mapping, classification, and retention programs. Oversee incident response, vulnerability management, patch compliance, and secure configuration baselines using SCCM, Ivanti, Intune, GPO, and Azure Defender. Drive SOC integration, threat intelligence

Head of IT Security - Wembley

Hiring Organisation
Adecco
Location
Wembley, London, England, United Kingdom
Employment Type
Full-Time
Salary
£90,000 - £100,000 per annum
will own the strategic and operational delivery of all information and cyber security activities. You'll develop and implement robust security policies, oversee incident response, and ensure compliance with GDPR, PCI DSS, ISO 27001, and Cyber Essentials Plus. You will be the single point of accountability … Cyber Essentials Plus, and ISO/IEC 27001:2022 aligned practices. Lead Data Protection Impact Assessments (DPIAs), data mapping, classification, and retention programs. Oversee incident response, vulnerability management, patch compliance, and secure configuration baselines using SCCM, Ivanti, Intune, GPO, and Azure Defender. Drive SOC integration, threat intelligence

SOC Principal Analyst

Hiring Organisation
QBE Management Services (UK) Limited
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
Competitive salary
threat hunting methods, classifying, analysing, prioritising and remediating security alerts/events. The focus is to provide effective, proactive and a highly technical analytical response to cyber security-related incidents to prevent QBE from becoming compromised by modern attack methods and techniques. Main responsibilities: Act as point of escalation … events, providing context around the event, determine root cause and provide regular updates and recommend modifications to existing systems and procedures. Perform deep-dive incident analysis of various data sources by analysing and investigating security related logs against medium-term threats and IOCs Actively manage and apply the phases

Cyber Security Analyst

Hiring Organisation
Accenture
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
Competitive salary
with the organisation. As part of our Blue Team, you’ll use the latest intelligence and tooling to analyse information systems to ensure effective incident detection and response. Job Description If you are looking to make your mark on a rapidly growing SecOps team with some very exciting clients … keen interest when it comes to technical cybersecurity topics such as threat hunting, attacker tactics and techniques, monitoring and alerting, threat intelligence, and incident readiness and response. Key responsibilities of the role are summarised below: · Security monitoring and incident response · Detection engineering - Develop, maintain, and enhance security

DevOps Lead

Hiring Organisation
Michael Page Technology
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
£80,000 - £95,000 per annum
followed Define, build, and configure monitoring, alerting, and instrumentation - choosing the right approach (build or buy) on a case-by-case basis Lead incident response: coordinate teams during outages, drive root cause analysis, and implement preventive measures Manage and develop a small team comprising DevOps and technical support … just configure it - but pragmatic enough to know when off-the-shelf is the right choice Calm under pressure with a systematic approach to incident management Able to quickly understand and troubleshoot unfamiliar systems across the full stack Experienced in leading small teams and developing people Strong communicator

Threat Intelligence Specialist

Hiring Organisation
QBE Management Services (UK) Limited
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
Competitive salary
threat actor profiles, and campaign assessments. Translate complex technical findings into concise, risk-based intelligence for decision-making. Collaborate with SOC, Detection Engineering, and Incident Response teams on purple-team exercises and threat-hunting. Maintain trusted relationships with industry and intelligence communities. Provide SME-level advice and challenge … other platforms to manage workflows and document intelligence findings. About You We’re looking for someone with a strong technical background in threat intelligence, incident response, or threat hunting, ideally within enterprise or global environments. You’ll be confident in analysing complex threats and communicating your findings clearly

Lead - SOC incident manager

Hiring Organisation
Colt Technology Services
Location
Central London, London, United Kingdom
Employment Type
Permanent, Work From Home
Company description: As the Lead - SOC Incident Manager, your role will encompass communicating cybersecurity incidents to key partners across the enterprise as well as being the main interface between the Colt business units and the cybersecurity groups. You will be the subject matter expert responsible for coordinating cyber security … incidents across the enterprise. Job description: You will play a key role within the SOC to manage incidents: Coordinate response efforts to cyber security incidents caused by internal and external threats to reduce the impact of these incidents to Colt and its customers. Act as the bridge between

Site Reliability Engineer- eDV Cleared

Hiring Organisation
Searchability NS&D
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
£50,000 - £95,000 per annum, Negotiable
Clearance - London Based or ability to travel to London.- Experience as in a Site Reliability Engineering role SITE RELIABILITY ENGINEER ESSENTIAL SKILLS- Reliability, incident response/incident management experience - Experience with Monitoring and Observability tools such as Prometheus, Grafana and OpenSearch- Automation tools (Go, Bash)- Experience with

Test Environment Manager

Hiring Organisation
Adroit People Ltd
Location
London, United Kingdom
Employment Type
Permanent
Salary
£90,000
performance: Use observability tools like Prometheus and Grafana to track the health of test environments, identify bottlenecks, and resolve issues proactively, not reactively. Manage incident response: Lead the incident management process for test environment issues, conducting blameless post-mortems to understand the root causes and implement lasting … associated with test environments to free up engineering time for more strategic work. Strategic and cultural responsibilities Drive continuous improvement: Analyze environment performance data, incident reports, and post-mortems to identify opportunities for continuous improvement and innovation. Balance reliability and speed: Use an "error budget" for test environments.

Cyber Security Engineer (Hedge Fund) - Python/Powershell/SQL/Tableau BI/NIST/CISSP/CISA - PERM

Hiring Organisation
Scope AT Limited
Location
City, London, United Kingdom
Employment Type
Permanent
Salary
GBP Annual
technical environments. Stay current with emerging threats, regulatory changes, and industry best practices in risk management, compensating controls, and evolving enterprise technologies. Assist with incident response planning and post-incident risk evaluation, leveraging broad technical knowledge to assess impacts and recommend improvements. Qualifications/Skills Required Demonstrated

IT Security Analyst

Hiring Organisation
The Bridge IT Recruitment
Location
City, London, United Kingdom
Employment Type
Permanent
Salary
GBP 50,000 - 55,000 Annual
Cyber Security, Computer Science, or equivalent experience. Proven experience within a SOC (Security Operations Centre) or NOC (Network Operations Centre). Strong understanding of incident response methodologies and the MITRE ATT&CK framework. Experience using SIEM, IDS/IPS, vulnerability scanners, and Azure security tools. Technical expertise … Microsoft Defender, EDR (Endpoint Detection and Response), and network architecture. Practical experience managing cyber incidents and implementing secure configurations. Excellent analytical and problem-solving skills, with clear documentation and communication abilities. Familiarity with NIST, ISO 27001, and CIS Controls frameworks. Ability to work under pressure, prioritise effectively, and maintain

IT Security Analyst

Hiring Organisation
The Bridge IT Recruitment
Location
London, Fleet Street, United Kingdom
Employment Type
Permanent
Salary
£50000 - £55000/annum
Cyber Security, Computer Science, or equivalent experience. Proven experience within a SOC (Security Operations Centre) or NOC (Network Operations Centre). Strong understanding of incident response methodologies and the MITRE ATT&CK framework. Experience using SIEM, IDS/IPS, vulnerability scanners, and Azure security tools. Technical expertise … Microsoft Defender, EDR (Endpoint Detection and Response), and network architecture. Practical experience managing cyber incidents and implementing secure configurations. Excellent analytical and problem-solving skills, with clear documentation and communication abilities. Familiarity with NIST, ISO 27001, and CIS Controls frameworks. Ability to work under pressure, prioritise effectively, and maintain

Global Delivery Director - Secure Data

Hiring Organisation
Boston Consulting Group
Location
London, United Kingdom
Employment Type
Permanent
Salary
GBP Annual
improve scalability and reduce manual intervention. Operational Security, SRE & Assurance: Ensure security platforms are resilient, continuously monitored, and designed for 24x7 support and incident response readiness. Embed security telemetry and observability to enable proactive threat detection and automated response. Apply SRE principles to improve reliability, performance, and maintainability