51 to 75 of 715 Incident Response Jobs in London

VP, Security Operations

Location
Greater London, England, United Kingdom
Privacy and Enterprise Risk This is a hands‐on leadership role. You need to be technical, in the detail, and able to lead an incident bridge. You will run a global function and own Security Operations end to end: the SOC, incident response, detection engineering and threat … intelligence, along with the people and platforms behind them. THE CHALLENGE: Own incident response. Preparation, triage, containment, eradication, and the post‐incident reviews that make the next incident smaller. You will lead major incidents personally and set the standard for what good looks like. Build ...

Senior SecOps Specialist

Hiring Organisation
Teya Solutions
Location
London, UK
Employment Type
Full-time
closely with Security Engineering, IT, Infrastructure, Platform, Cloud, and Product teams to reduce risk and embed security effectively across the organisation. You operate across incident response, detection engineering, security tooling, vulnerability management, threat intelligence, telemetry, and automation - turning operational insight into stronger controls and better engineering outcomes. ResponsibilitiesSecurity … Operations & Incident Response Lead end-to-end investigation and response of complex security incidents. Act as L3 escalation point for SOC analysts and MSSP. Coordinate across Security, Engineering, IT, Cloud, Legal, and Compliance duringincidents. Make clear, risk-based decisions under pressure with strong documentation. Maintain playbooks, runbooks ...

Vice President, Threat and Vulnerability Management Team Lead

Hiring Organisation
MUFG
Location
London, UK
Employment Type
Full-time
associated post-deployment check-outs. Triage vulnerabilities into "Fix, Acknowledge, and Investigate" categories using industry-aligned risk rating methodologies. Use ServiceNow Application Vulnerability Response (AVR) and Vulnerability Response (VR) modules to manage and report on vulnerabilities and violations across the estate, integrating with dashboards and workflows for visibility … scanning, penetration testing, and security awareness training. Proficiency in using vulnerability scanning tools (e.g. Tenable, Qualys, Rapid7, Veracode, JFrog Xray), threat intelligence platforms, and incident response tools. Prior experience implementing automated solutions for vulnerability scanning, threat detection, and incident response, with a focus on continuous process ...

Cyber Response & Recovery Manager (Reactive DFIR) – German Speaking

Location
Greater London, England, United Kingdom
Role This hands-on position sits within a cyber advisory practice, focusing on reactive digital forensics and incident response. Day to day, the role involves managing medium to large incident response cases, supporting clients in building internal IR capabilities, contributing to runbooks and playbooks, and developing internal … tooling, processes, and team training when not engaged on active cases. Skills & Experience Candidates require a strong technical background in digital forensics and incident response, with proven incident management experience. The role demands eligibility for SC or DV security clearance. Opportunities exist to obtain recognised security certifications ...

Director, R&D, Email & Collaboration Threat Protection

Hiring Organisation
Mimecast
Location
London, UK
Employment Type
Full-time
master them quickly. Our AI leadership extends beyond how we build to what we build. Our Mihra AI agent delivers 7x faster threat response for customers, and we're recognized as "Agents of Change" in Human Risk Management. Engineers here work at the intersection of cutting-edge AI tooling … succession planning for key leadership and senior technical roles. Drive Engineering Excellence: Set and maintain high standards across your squads: testing, observability, release governance, incident response, and secure development practices. Hold the organisation accountable for operational excellence on a zero-downtime, globally distributed platform — including post-incident ...

Senior SOC Analyst - DV Clearance

Hiring Organisation
Salt Search
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£70,000 - £100,000 per annum
security cyber defence team supporting critical national infrastructure and sensitive government programmes. This role requires a proactive security professional with strong monitoring, analysis, and incident triage capabilities within a Security Operations Centre environment. SOC Analyst - Key Responsibilities Monitor and analyse security alerts from SIEM and security tooling platforms Perform … triage and investigation of security events and potential incidents Conduct threat hunting and identify indicators of compromise Escalate and coordinate incident response activities where required Analyse endpoint, network, and cloud security telemetry Develop and improve detection rules and use cases Produce detailed investigation and incident reports Collaborate ...

Security Architect - SC Cleared

Hiring Organisation
Sanderson Government and Defence
Location
London, United Kingdom
Employment Type
Contract, Work From Home
Contract Rate
£545 - £590 per day
solutions into operational security environments. Ensure operational teams have the controls, monitoring capabilities, and processes required to manage secure services. Collaborate with Security Operations, Incident Response, Engineering, and Platform teams to maintain secure systems. Drive continuous improvement within security monitoring and incident response capabilities. Stakeholder Engagement … supporting government departments, public sector organisations, or Critical National Infrastructure programmes. Knowledge of: Zero Trust Architecture Secure by Design Principles DevSecOps Methodologies Security Operations & Incident Response Identity & Access Management (IAM) Data Protection & Privacy Controls Enterprise Security Architecture Frameworks Familiarity with: NCSC Cloud Security Principles ISO 27001 NIST Cybersecurity ...

Senior Observability Engineer

Location
Greater London, England, United Kingdom
report into the Senior Engineering Manager for SRE and Observability and work as an individual contributor, partnering closely with development squads, platform engineers, and incident response teams. The Bengaluru team is deeply integrated into IG’s global engineering community, with real ownership and scope to shape how observability … adoption across the organisation, providing guidance and practical support to help engineering teams embed reliability targets into their day-to-day ways of working.**Incident response*** Join the support rota and incident response, using observability tooling to accelerate diagnosis and reduce mean time to resolution.* Lead ...

Tech lead - SOC responder

Hiring Organisation
Colt Telecom
Location
London, UK
Employment Type
Full-time
with global impact upon Colt, business units, partners, and customers. While working as part of this team, the successful individual will provide world class incident response functions to detect, protect, respond, and sustain operations within cyberspace. This role operates at a Tier 3 level, with the expectation that … checksResponsible for operational activities, Technology escalation support, Security Solution assessment, existing Service maturing and Build activities assistAnalyse potential infrastructure security incidents to determine if incident qualifies as a legitimate security breachEstablishing and governing the security incident response processes, investigations and security operational processesMaintenance and enhancement of formal ...

Tech lead - SOC responder

Hiring Organisation
Colt Technology Services UK
Location
London, United Kingdom
Employment Type
Permanent, Work From Home
with global impact upon Colt, business units, partners, and customers. While working as part of this team, the successful individual will provide world class incident response functions to detect, protect, respond, and sustain operations within cyberspace. This role operates at a Tier 3 level , with the expectation that … operational activities, Technology escalation support, Security Solution assessment, existing Service maturing and Build activities assist Analyse potential infrastructure security incidents to determine if incident qualifies as a legitimate security breach Establishing and governing the security incident response processes, investigations and security operational processes Maintenance and enhancement ...

Security Operations Specialist

Location
Greater London, England, United Kingdom
with global impact upon Colt, business units, partners, and customers. While working as part of this team, the successful individual will provide world class incident response functions to detect, protect, respond, and sustain operations within cyberspace. This role operates at a Tier 3 level , with the expectation that … operational activities, Technology escalation support, Security Solution assessment, existing Service maturing and Build activities assist Analyse potential infrastructure security incidents to determine if incident qualifies as a legitimate security breach Establishing and governing the security incident response processes, investigations and security operational processes Maintenance and enhancement ...

Tech Lead - SOC Responder

Hiring Organisation
Hackajob Ltd
Location
South West London, London, United Kingdom
Employment Type
Permanent, Work From Home
with global impact upon Colt, business units, partners, and customers. While working as part of this team, the successful individual will provide world class incident response functions to detect, protect, respond, and sustain operations within cyberspace. This role operates at a Tier 3 level , with the expectation that … operational activities, Technology escalation support, Security Solution assessment, existing Service maturing and Build activities assist Analyse potential infrastructure security incidents to determine if incident qualifies as a legitimate security breach Establishing and governing the security incident response processes, investigations and security operational processes Maintenance and enhancement ...

Senior Cyber Detection and Response Engineer

Location
Greater London, England, United Kingdom
Senior Cyber Detection and Response Engineer (London, UK) Summary of Position As a critical technology provider to around 100 of the world's leading financial institutions, Pirum’s security posture is a commercial asset as much as a risk management function. Our customers conduct rigorous third-party security assessments … protect our systems and data directly affects our ability to win and retain business. We are looking for a Senior Detection and Response Engineer to lead Pirum's detection and response capability, enabling us to detect, investigate and contain threats at machine speed across our AWS, on-premises ...

SOC Team Lead

Location
Greater London, England, United Kingdom
your unique needs. We help organisations improve processes such as threat management by building an identity management programme, and establishing prevention, detection and response capabilities to cyber-attacks. The SOC Team Lead drives performance and operational excellence acrossShared Service’s Cyber Services function. Acting as both a technical escalation … point and line manager, they support the team in threat analysis, incident response, and security assurance activities. They foster a proactive culture of cyber hygiene and continuous improvement while collaborating across departments to strengthenShared Service's security posture. The Team Leader also deputises for theService DeskManager during high ...

Cyber Security Architect & Engineering Lead

Location
Greater London, England, United Kingdom
establish practical controls for Microsoft 365 Copilot, AI agents, custom AI applications and related technologies. Provide senior technical oversight across security monitoring, detection engineering, incident response and recovery capability. Lead or support the response to complex or high-severity security incidents, working with internal teams, external … security, API security and secure software development. Experience of security architecture review, threat modelling, technical standards, reference architecture and control design. Practical experience across incident response, detection engineering, threat hunting, vulnerability or exposure management and security automation. Ability to automate security and assurance processes using tools such ...

Incident Response Engineer, UK Security Operations, Hampshire

Location
City of Westminster, England, United Kingdom
Incident Response Engineer, UK Security Operations, Hampshire Google London, UK Mid Experience driving progress, solving problems, and mentoring more junior team members; deeper expertise and applied knowledge within relevant area. Must be a British citizen to meet compliance and security clearance requirements. Office location will be a satellite … more programming languages. Active, or the ability to obtain, a Developed Vetting (DV) UK security clearance. Preferred qualifications: Security+ or similar Cyber Security/Incident Response related certifications. Experience responding to security incidents on Kubernetes. Experience analyzing, triaging, and remediating common information security incidents. Understanding of common attacker ...

Associate Director, Cybersecurity

Location
Greater London, England, United Kingdom
business teams to protect research data, intellectual property, scientific platforms, regulated data and contract‐bound information. Own and continuously improve Nxera’s cyber incident response capability, including playbooks, escalation routes, tabletop exercises, communication protocols and post‐incident reviews. Manage the relationship and operational effectiveness of external cybersecurity … Microsoft Entra ID, Azure security, Intune, Microsoft Defender, Conditional Access, endpoint protection, data loss prevention, logging and monitoring. Experience with cybersecurity governance, risk management, incident response, vulnerability management, third‐party security assurance and security control improvement. Experience managing external cybersecurity partners/vendors, such as SOC/ ...

Principal Product Cybersecurity Assurance

Location
Greater London, England, United Kingdom
Review and provide guidance on security risk assessments, risk mitigation plans, mitigation gap analysis, and security management documentation in support of system cybersecurity certification. Incident Response & Lifecycle Security Establish and maintain a Product Security Incident Response (PSIR) process, encompassing coordinated vulnerability disclosure, patch deployment pipelines … post-field incident analysis. Define and oversee security monitoring requirements for deployed fleets, ensuring field data feeds back into risk files and security artefacts in line with post-market surveillance obligations. Commercial & Bid Support Support the production of work package descriptions and cost estimates for product bids, services ...

Senior SOC Analyst

Hiring Organisation
Anson Mccade
Location
London, United Kingdom
Employment Type
Permanent
Salary
£50,000
recovery. The successful candidate will correlate events across multiple data sources, produce detailed investigation reports, help improve detection coverage and playbooks, and participate in incident response exercises. Whats on offer £45,000£51,000 base salary Additional 25% shift premium Permanent position Exposure to complex incidents within … modern, security-sensitive environment Opportunity to develop incident response and threat analysis expertise Onsite London role operating across a 28-day shift pattern Company benefits package Excellent skill up and career progression opportunities What you need Experience within a SOC, incident response or threat analysis role ...

Senior Cyber Security Analyst

Hiring Organisation
Lightsource bp
Location
London, UK
Employment Type
Full-time
risk and lead the remediation of identified vulnerabilities across Lightsource bp's IT systems globally. You will be responsible for threat detection, investigation, and incident response, leveraging a modern security technology stack with a strong focus on the Microsoft Defender ecosystem. Working across multiple business areas and time … team Experience & Knowledge Required Experience: 5+ years of professional experience in cybersecurity, with at least 2+ years in a Security Operations Center (SOC) or incident response role Advanced proficiency with Microsoft Defender XDR and expert-level knowledge of Microsoft Sentinel, including KQL query writing and analytics rule development ...

AI Security Consultant

Location
Greater London, England, United Kingdom
supporting secure AI adoption, reviewing LLM-based applications, advising on SOC automation, developing AI security guardrails, and helping organisations use AI to enhance detection, response, reporting and risk management. The right candidate will combine strong cyber security fundamentals with curiosity and practical knowledge of AI security. You should … business risk. Support the design and implementation of security controls across areas such as access management, data protection, logging and monitoring, vulnerability management, incident response and third-party risk. Help clients interpret security requirements, assess control maturity and develop actionable improvement roadmaps. Translate technical findings into clear, business ...

Information Security Technical Lead

Hiring Organisation
Davies
Location
London, UK
Employment Type
Full-time
will be part of the wider infrastructure team and work closely with development teams, clients, risk and compliance to drive security automation, threat detection, incident response, and risk reduction across the enterprise platform stack. Key ResponsibilitiesSecurity Leadership & Team Management: Lead a team of engineers, setting direction, managing workloads … well as vendor solutions & systems. Collaborate on implementing & Integrating security controls into pipelines including security scans, policy enforcement, and dependency checking. Security Monitoring & Incident Response: Monitor security alerts and events from SIEM, EDR, firewall, IDS/IPS, & other security tools. Triage and prioritise alerts based on severity ...

Security Operations Vice President

Hiring Organisation
JP Morgan Chase
Location
London, UK
Employment Type
Full-time
strengthen our data. As a member of the Attack Analysis team, you will fit into a Global team providing 24/7 monitoring and Incident Response, acting as the frontline defense for attacks against the firms' infrastructure. As a SOC Manager, you will serve as the direct manager … metrics to ensure the team is meeting overall alert and case goals as well as identifying opportunities to improve and tune alerts. In an incident response scenario, the SOC Manager is responsible for assigning, coordinating and documenting the outcome of specific analysis workstreams and preparing communications to senior ...

Cyber Security Engineer

Hiring Organisation
Picture More
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£70,000 - £77,000 per annum
play a key role in a growing SecOps function protecting a modern Microsoft and cloud environment. This is a highly technical role focused on incident response, SIEM optimisation, vulnerability management, and security engineering, helping drive a Zero Trust journey and supporting ISO 27001 & CIS controls. What … doing: Lead and support incident response, threat monitoring and root-cause analysis Tune and optimise SIEM & CrowdStrike EDR for maximum effectiveness Drive vulnerability management, remediation and risk reduction Secure cloud and infrastructure across Intune, Entra ID, Palo Alto, Cisco, Mimecast and more Implement key security controls including ...

Senior Linux DevOps Engineer

Hiring Organisation
RedTech Recruitment Ltd
Location
City of London, London, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£90,000
Terraform and Ansible Experience building and managing CI/CD pipelines using GitLab CI/CD, GitHub Actions, Jenkins or similar Experience with incident response, root cause analysis and driving improvements to the reliability and performance of production systems Commercial experience with Microsoft Azure or another major cloud … automate large-scale Linux-based production environments Build and improve containerised environments using Docker and Kubernetes Diagnose complex infrastructure, networking and performance issues, supporting incident response and root cause analysis Develop automation, Infrastructure as Code and CI/CD processes to improve engineering efficiency and reliability Implement ...