1 to 25 of 86 Incident Response Jobs in the North West

Director, Digital Forensics & Incident Response (Global)

Location
Manchester, England, United Kingdom
Director, Digital Forensics & Incident Response (Global) Department: Cyber Services and Capabilities Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Reporting To: Matt Hull (Open to Associate Director with progression path to Director) Description The purpose of this role is to lead NCC Group’s global Digital Forensics … Incident Response (DFIR) capability, ensuring effective preparedness, response, recovery, and continuous improvement across cyber incident management and forensic investigations. The global DFIR team will consist of regionally distributed colleagues, delivering a consistent, scalable, and market-leading service that protects client assets, reputation, and business operations. ...

Information Security Engineer

Hiring Organisation
Freshfields Bruckhaus Deringer
Location
Manchester, UK
Employment Type
Full-time
Aside from infrastructure, the candidate should have experience and working knowledge of SIEM and vulnerability management platforms. The role will cover elements of cyber incident response, so a background in supporting a wider incident response function is a necessity. Key ResponsibilitiesCloud Security Assessment & Advisory: Assess … Azure IaaS and Google Cloud environments, including infrastructure. Provide recommendations based on industry best practices and emerging security threats. The ability to provide Cyber Incident Responders subject matter expertise in Cloud security when required. Defender & Security Monitoring Advisory: Evaluate and optimise the use of Azure Defender and other security ...

Senior Security Specialist

Hiring Organisation
Reonomy
Location
Manchester, UK
Employment Type
Full-time
security operations, expanding our offensive security capabilities, and improving how we detect and respond to emerging threats. Working across security engineering, threat intelligence, incident response, and cloud security, you will identify opportunities to improve detection, automate processes, mature security technologies, and strengthen our overall security posture. This … Security Operations and technology teams to drive continuous improvement. Work across the full spectrum of modern cybersecurity. From security engineering and cloud security to incident response, threat intelligence, automation, and offensive security, this role offers technical breadth. You will solve complex security challenges, improve detection and response ...

Security Consultant

Hiring Organisation
Version 1
Location
Manchester, UK
Employment Type
Full-time
define pragmatic remediation roadmaps aligned to business priorities. Lead and support security architecture reviews across cloud, applications, infrastructure, IAM, data protection and detection/response domains. Provide expert consulting to customers on security strategy, risk reduction, control design, and security operating model improvements. Challenge weak security assumptions with confidence … guardrails. Partner with engineering, platform, DevOps and operations teams to embed security into delivery pipelines and infrastructure as code practices. Support threat detection, incident response readiness, use-case tuning, and post-incident improvement activities. Contribute to security standards, policies, patterns, reusable accelerators, and client-facing deliverables including ...

Database Platform Manager

Location
Manchester, England, United Kingdom
fleet reliability and SLOs. This role is weighted toward hands-on technical depth. You should be as credible in a design review or an incident bridge as you are in a planning session with senior stakeholders. Key Responsibilities Technical direction The technical roadmap for the estate. We want someone … performance, high availability and disaster recovery, patching, and backup and recovery Senior escalationpointfor complex L3 work: performance and query tuning, replication and failover, major incident response and post-incident review Automation, infrastructure as code and database CI/CD, with everything in GitHub under proper change management ...

Cyber Security Analyst

Hiring Organisation
The Portfolio Group
Location
Manchester, United Kingdom
Employment Type
Permanent
Salary
£50000 - £55000/annum
infrastructure and established a modern, cloud-first security stack, it is an exciting time to join the business as we mature our detection, response, and automation capabilities across a global estate. You will work collaboratively with the business and the wider IT team - Infrastructure, Network, Development, DevOps, and Service … with Palo Alto Cortex XSIAM and XSOAR, Cortex XDR, Microsoft Purview, Mimecast, Abnormal, Nessus, and Microsoft 365. You will participate in security investigations and incident response, responding to events involving malware, data loss, phishing, or network intrusion, and supporting our data protection and vulnerability management activity. You will ...

Global DFIR Director: Lead Cyber Incident Excellence

Location
Manchester, England, United Kingdom
Group plc seeks a Director, Digital Forensics & Incident Response (Global) to lead the global DFIR capability, setting strategic direction and ensuring effective preparedness, response, recovery, and continuous improvement across cyber incident management and forensic investigations. The role requires driving operational excellence, collaborating with NCC Group leaders … expanding security services through incident response opportunities. #J-18808-Ljbffr ...

Cloud Security Engineer - Manchester - National Security West

Hiring Organisation
Hackajob Ltd
Location
Manchester, North West, United Kingdom
Employment Type
Permanent, Part Time, Work From Home
Salary
£95,000
security services and implementing cloud security best practices, including identity, monitoring, threat detection and data protection. Understanding of Security Operations, including monitoring, alerting, incident response, threat detection, and SIEM platforms such as Microsoft Sentinel or Splunk. Strong understanding of Identity and Access Management (IAM), least-privilege access principles … . Designing and implementing secure AWS architectures that align with security and compliance requirements. Building and maintaining security monitoring, alerting and automated response capabilities across cloud environments. Integrating cloud platforms with security tooling, including SIEM solutions such as Microsoft Sentinel and Splunk. Leveraging AWS security services and promoting security ...

Cloud Security Engineer - London - National Security West

Hiring Organisation
Hackajob Ltd
Location
Manchester, North West, United Kingdom
Employment Type
Permanent, Part Time, Work From Home
Salary
£95,000
security services and implementing cloud security best practices, including identity, monitoring, threat detection and data protection. Understanding of Security Operations, including monitoring, alerting, incident response, threat detection, and SIEM platforms such as Microsoft Sentinel or Splunk. Strong understanding of Identity and Access Management (IAM), least-privilege access principles … . Designing and implementing secure AWS architectures that align with security and compliance requirements. Building and maintaining security monitoring, alerting and automated response capabilities across cloud environments. Integrating cloud platforms with security tooling, including SIEM solutions such as Microsoft Sentinel and Splunk. Leveraging AWS security services and promoting security ...

Cloud Security Engineer – London – National Security West

Hiring Organisation
BAE Systems
Location
Manchester, United Kingdom
Employment Type
Full Time
security services and implementing cloud security best practices, including identity, monitoring, threat detection and data protection. Understanding of Security Operations, including monitoring, alerting, incident response, threat detection, and SIEM platforms such as Microsoft Sentinel or Splunk. Strong understanding of Identity and Access Management (IAM), least-privilege access principles … . Designing and implementing secure AWS architectures that align with security and compliance requirements. Building and maintaining security monitoring, alerting and automated response capabilities across cloud environments. Integrating cloud platforms with security tooling, including SIEM solutions such as Microsoft Sentinel and Splunk. Leveraging AWS security services and promoting security ...

Product Security Engineer

Location
Manchester, England, United Kingdom
real control rather than a manifest scan, build-pipeline isolation, third-party risk as runtime telemetry. When the next big supply-chain incident lands, we should know within hours whether it touches us. Detect, respond, contain Runtime detection that catches what actually happens, not what a vendor template guesses … might. Incident response codified as automation: containment, rotation, isolation, evidence capture. Forensics tooling that works on our stack. Adversary emulation against our real attack surface. The metric is mean-time-tocontain, not control coverage. Secure the agentic development surface Our engineers ship with AI agents in the loop ...

WAF Security Engineer

Location
Manchester, England, United Kingdom
code approaches Contribute to platform modernisation, service improvements, refactoring, automation and technical-debt reduction Improve monitoring, alerting and telemetry to strengthen platform reliability and incident response Support diagnosis and resolution of major incidents with Security Engineering, Network and Cloud teams Embed secure-by-design patterns and guardrails Produce … including design, implementation, and optimization of security controls. Proficient in Infrastructure as Code, CI/CD pipelines, and automation to enhance platform reliability and incident response. Highest-signal resume keywords Web Application Firewall (WAF) Technologies Infrastructure as Code (IaC) CI/CD Pipelines Application Security Python Scripting Hard Skills ...

Senior DFIR / Incident Response / Digital Forensics

Location
Knutsford, England, United Kingdom
DFIR Lead Cyber Operations Analyst , a VP-level role at the centre of the bank’s cyber defence, delivering advanced digital forensics and incident response. You will analyse malware, malicious samples and network activity to support complex investigations, working closely with internal teams, external partners and law enforcement. This … support may be required, including extended hours and weekend work. To be successful in this role, you will need the following: Digital forensics and incident response expertise, including host, network, cloud and live forensic analysis, supported by rigorous documentation practices. Excellent written and verbal communication skills, with ...

Platform Engineer, Azure Infrastructure

Location
Manchester, England, United Kingdom
compliance Collaborate with developers to improve CI/CD pipelines, deployment strategies, and overall developer experience Enhance observability and reliability, refining alerting, monitoring, and incident response Collaborate on cloud optimization projects, improving performance, cost efficiency, and security posture Mentor and guide team members, fostering a culture of technical … compliance Collaborate with developers to improve CI/CD pipelines, deployment strategies, and overall developer experience Enhance observability and reliability, refining alerting, monitoring, and incident response Collaborate on cloud optimization projects, improving performance, cost efficiency, and security posture Mentor and guide team members, fostering a culture of technical ...

On-Call DFIR Lead - Cyber Operations & Incident Response

Location
Knutsford, England, United Kingdom
seeking a DFIR Lead Cyber Operations Analyst at VP level in Knutsford. In this key role, you will deliver advanced digital forensics and incident response while leading complex investigations. You will collaborate with internal teams and law enforcement, and produce clear reports under pressure. Ideal candidates will have ...

Cloud Security Engineer

Hiring Organisation
Experis
Location
Knutsford, Cheshire, United Kingdom
Employment Type
Contract
highly available cloud services. Support business stakeholders in adopting modern cloud-native architectures and security best practices. Develop and implement automation for security monitoring, incident response, remediation, and operational processes. Ensure cloud platforms comply with organisational security standards, governance requirements, and software development lifecycle practices. Identify, assess … gaps. Contribute to cloud architecture reviews, security assessments, and threat modelling activities. Work with security tooling and SIEM platforms to improve visibility, detection, and response capabilities. Support incident, problem, and change management processes while maintaining operational excellence. Develop Infrastructure as Code (IaC) solutions to standardise and automate cloud ...

Senior SOC Analyst - Manchester

Hiring Organisation
Hackajob Ltd
Location
Manchester, North West, United Kingdom
Employment Type
Permanent
Salary
£95,000
/7 operation with four shift teams working in a standard rotation. They are responsible for utilising the SOC's Security Incident and Event Management (SIEM) toolsets to detect and investigate potential Security and Service Incidents occurring within the monitored networks. These roles require a minimum of SC clearance … using the Protective Monitoring platform and Internet resources to identify cyber-attacks/security incidents. Categorise all suspected incidents in line with the Security Incident policy Recognise potential, successful and unsuccessful intrusion attempts and compromises through reviews and further analysis of relevant event detail and incident summary information. ...

SRE Managing Consultant - Cloud Operating Model

Location
Manchester, England, United Kingdom
Model & Ways of Working**: Define and implement SRE ways of working and engagement patterns, aligning reliability practices with existing ITSM/ITIL processes (e.g., incident, problem, release and change) and modern engineering delivery.* **Reliability Measures (SLIs/SLOs) & Error Budgets**: Establish service measures and targets (SLIs/SLOs … Insight:** Shape observability approaches (metrics/logs/traces) and operational monitoring models that make reliability risks visible and actionable, improving operational decision-making.* **Incident Excellence & Continuous Learning:** Design incident analysis and improvement loops, including practical approaches that strengthen incident response and drive learning through post ...

SOC Analysts - L2 and L3 (SC and DV-Cleared)

Hiring Organisation
Pigment Consulting
Location
Manchester, North West, United Kingdom
Employment Type
Contract
Investigation of phishing, malware, credential compromise and suspicious activity. Supporting containment, eradication and recovery. Developing and improving detection rules and playbooks. Producing high-quality incident documentation and reports. Supporting and mentoring Tier 1 analysts. Tier 3 SOC Analyst As a Tier 3 Analyst, you'll provide advanced technical investigation … senior escalation point for complex incidents. Responsibilities include: Leading complex and high-severity security investigations. Advanced threat hunting and incident response. Malware, endpoint, network and forensic investigation. Developing advanced detections and response capabilities. Root-cause analysis and post-incident investigation. Supporting major incident response. Working closely ...

Vice President, Production Services Application Support

Hiring Organisation
Hackajob Ltd
Location
Manchester, North West, United Kingdom
Employment Type
Permanent
coverage across on-site and offshore support hours. Use SQL scripting, automation, monitoring, and observability tools to improve operational resilience, service health, reliability, and incident response. To be successful in this role, we're seeking the following: Excellent SQL scripting skills. Strong scripting and automation skills using languages such … Proven skills and track record in AI automation, including the use of intelligent automation capabilities to reduce manual effort, improve operational efficiency, and enhance incident response workflows. Experience applying AI and automation solutions for alert correlation, anomaly detection, predictive monitoring, and service optimisation. Strong understanding of Site Reliability ...

Junior Cyber Security Analyst

Hiring Organisation
The Portfolio Group
Location
Manchester, United Kingdom
Employment Type
Permanent
Salary
£35000/annum
first security stack already in place, it is an exciting time to join the business and learn your craft as we mature our detection, response, and automation capabilities across a global estate. You will work alongside the wider IT team - Infrastructure, Network, Development, DevOps, and Service Desk - gaining … understanding of how security supports the business. The purpose of this role is to build a working knowledge of security operations, protective monitoring, and incident handling by working closely with, and learning from, the wider InfoSec team. Reporting to the Associate Director - Cyber Security, with day-to-day guidance ...

Information Security Manager

Hiring Organisation
Adele Carr Recruitment Limited
Location
Liverpool, Merseyside, United Kingdom
Employment Type
Full-Time
Salary
£55,000 - £65,000 per annum
Head of Information Security & Continuity, the role plays a key part in embedding a strong security culture, managing security risk, and ensuring effective response to cyber incidents. The Information Security Manager works closely with Technology, Risk, Compliance, and business teams to ensure that security controls are proportionate, effective … track remediation of vulnerabilities and audit findings Monitor the threat landscape and coordinate responses to emerging risks and vulnerabilities Lead the investigation and response to information security incidents, ensuring lessons learned and improvements are implemented Support internal and external audits, including ISO 27001 certification and surveillance activities Manage third ...

Senior Security Engineer

Location
Manchester, England, United Kingdom
many of these technologies/areas as possible is highly desirable: Security Frameworks (NIST, CIS etc.) PAM Tools and Technologies AWS Security Incident Response Endpoint Security (including mobile devices, Windows and Linux) Job Benefits We have a high-performance culture which is balanced evenly with world-class well ...

Software Engineering Manager

Hiring Organisation
Drive Further
Location
Cheadle, England, United Kingdom
C#, Angular, SQL Server Stay hands-on when needed: design, code, pair, review PRs, unblock the team Drive quality, reliability and security: testing approach, incident response, post-incident improvements Hire, onboard and develop engineers (including onshore/offshore collaboration) What we need from you 8+ years building ...

Service Reliability Engineer - Manchester

Hiring Organisation
Fitch Group
Location
Manchester, United Kingdom
Employment Type
Full Time
driven automation and blameless postmortems. Champion AI‐enabled operations using AWS Bedrock/SageMaker and Model Context Protocol (MCP) for log analysis, anomaly detection, incident triage, and workflow orchestration; establish adoption guardrails. Define and enforce cloud guardrails and security controls (SCPs/IAM boundaries, OPA policies, tagging, centralized logging … core infrastructure fundamentals (networking, storage, DNS) and APM/telemetry tooling. What Would Make You Stand Out: Practical experience with agentic AI for operations—incident triage, runbooks, and change management—with clear guardrails, auditability, and human-in-the-loop controls. Supporting AI/ML workloads at scale: SageMaker endpoints ...