oxford district, south east england, United Kingdom
Pentest People
a continuous, living threat management system throughout the duration of the contract, rather than a single point-in-time assessment. We’re expanding our IncidentResponse team and looking for a IncidentResponse Analyst to join us in tackling some of the most challenging cybersecurity threats. … a critical role in reducing the impact of cyberattacks and enchanting our clients security posture to prevent future attacks. Key responsibilities include: Conducting initial incident assessments and contribute to IncidentResponse management. Participate in live IncidentResponse operations including digital forensics. Perform security assessments, threat … etc. Proficiency in log analysis of Networking, Windows, Mac and Linux and Cloud. Understanding of evidence collection process based on priority. Strong understanding of incidentresponse following NIST 800-61 guidelines incorporating containment, eradication and recovery phases. Experience with digital forensics and investigations, including evidence collection and chain More ❯
oxford district, south east england, United Kingdom
CyberClan
carefully selected team of experts are capable of solving complex cyber security challenges – keeping data secure and businesses running as usual. CyberClan’s Global IncidentResponse Teams are available 24/7/365 to leap into action, responding to all cyber-attacks with proven defensive methodology, we … position will require extensive and frequent travel to multiple locations and sometimes on short term notice. Reporting to the Global Head of Digital Forensics & IncidentResponse, the successful candidate will work as part of the Post Breach Remediation team and serve as the Incident Commander in all … VPNs, and group policies Liase with DFIR team and Sales to keep open communication regarding compromised client Assist DFIR team with additional workflow through incidentresponse cases Communicate effectively with clients to understand their specific needs, provide updates on remediation progress, and offer guidance on enhancing their cybersecurity More ❯
oxford district, south east england, United Kingdom Hybrid / WFH Options
Lawrence Harvey
a pivotal role at the heart of a rapidly growing mobile-first payments solution organisation, where you can truly shape and affect how the incidentresponse is delivered. You would be reporting to the Security Operations Lead (who reports to the Head of Security) and will be working … responsibilities You will be responsible for building the infrastructure of a new in-house SOC, all the way through to conducting precise and robust incidentresponse against basic and advanced threat actors. You will be responsible for the automation workflow design and use case development. You will work … on the SIEM detection content development and false positive reduction. You will be in charge of robust and detailed incidentresponse to threats, investigation, and triage of day-to-day security events. Key requirements Experience in deploying security related IaC projects at scale. Familiarity with SOAR and optimisation More ❯
Reading, Oxfordshire, United Kingdom Hybrid / WFH Options
GCS
a robust threat-informed defence strategy. You'll also work collaboratively across teams to enhance our threat intelligence capabilities, inform vulnerability management, and strengthen incidentresponse readiness. Your role will involve maintaining threat actor profiles, managing intelligence feeds, supporting compliance, and shaping threat intelligence processes to align with … a Senior Cyber Threat Intelligence Analyst: Cyber Threat Assessment: Support and lead cyber threat assessments and provide recommendations to technical, managerial, and executive stakeholders. IncidentResponse Support: Act as part of the incidentresponse team where appropriate and deliver cyber intelligence insights during security events. Threat More ❯
Reading, Oxfordshire, United Kingdom Hybrid / WFH Options
Thames Water Utilities Limited
a robust threat-informed defence strategy. You'll also work collaboratively across teams to enhance our threat intelligence capabilities, inform vulnerability management, and strengthen incidentresponse readiness. Your role will involve maintaining threat actor profiles, managing intelligence feeds, supporting compliance, and shaping threat intelligence processes to align with … a Senior Cyber Threat Intelligence Analyst: Cyber Threat Assessment: Support and lead cyber threat assessments and provide recommendations to technical, managerial, and executive stakeholders. IncidentResponse Support: Act as part of the incidentresponse team where appropriate and deliver cyber intelligence insights during security events. Threat More ❯
oxford district, south east england, United Kingdom
CyberClan
s carefully selected team of experts are capable of solving complex cybersecurity challenges – keeping data secure and businesses running as usual. CyberClan’s Global IncidentResponse Teams are available 24/7/365 to leap into action, responding to all cyber-attacks with Proven defensive methodology. Our … in insurance law and claims handling. This role supports the CERT team with reviewing insurance policies, assisting with claims assessments, and contributing to breach response efforts. Ideal for someone with early in-house or private practice experience who’s ready to grow into a broader commercial legal role. This … role will provide review, assessment, advise and expertise in the management of the claims process to support CyberClan’s delivery of IncidentResponse projects, including analysis of claims and providing recommendation for resolution of those claims. We are seeking an experienced claims professional to join our team and More ❯
oxford district, south east england, United Kingdom
CyberClan
carefully selected team of experts are capable of solving complex cyber security challenges – keeping data secure and businesses running as usual. CyberClan’s Global IncidentResponse Teams are available 24/7/365 to leap into action, responding to all cyber-attacks with proven defensive methodology, we … position will require extensive and frequent travel to multiple locations and sometimes on short term notice. Reporting to the Global Head of Digital Forensics & IncidentResponse, the successful candidate will work as part of the Post Breach Remediation team and serve as the Incident Commander in all … through mitigation and remediation Liase with DFIR team and Sales to keep open communication regarding compromised client Assist DFIR team with additional workflow through incidentresponse cases Monitor network incidents using network monitoring tools and other systems to maintain 99.9% uptime of our network Monitor and take ownership More ❯
oxford district, south east england, United Kingdom
CyberClan
carefully selected team of experts are capable of solving complex cyber security challenges – keeping data secure and businesses running as usual. CyberClan’s Global IncidentResponse Teams are available 24/7/365 to leap into action, responding to all cyber-attacks with proven defensive methodology, we … security teams, customer operation teams as well as breach coach legal teams. This role with be reporting to the Global Head of Digital Forensics & IncidentResponse, the successful candidate will work as part of the Post Breach Remediation team and will collaborate closely with other cross-functional teams … identification of root cause and issue resolution or escalation Identify and escalate priority issues that need immediate attention Meet or exceed customer expectations on response quality, timeliness of responses and overall customer experience Serve as internal and external point of contact on customer escalations and ensure customer issues are More ❯
oxford district, south east england, United Kingdom Hybrid / WFH Options
Accelerant
aligned with best practices. Monitor and address emerging threats, vulnerabilities, and security trends, ensuring timely implementation of countermeasures. Perform vulnerability assessments, threat analysis, and incident response. Participate in Incidentresponse efforts by conducting log analysis, gathering evidence, and executing remediation tasks. Work closely with partners in infrastructure … such as AZ-500/AZ-700/AZ -305. Background in computer networking. Experience with a scripting language for task automation. Previous incidentresponse participation. Previous experience working as a security or infrastructure engineer in a cloud environment. Enjoy our comprehensive benefits package designed to meet More ❯
oxford district, south east england, United Kingdom
Americold Logistics, LLC
aligned with global business risk/objectives. This role is focused on technical operations and support of various information security tools including event/incident management (SIEM), cloud security, endpoint detection and response, email security, and vulnerability management. This position will be responsible for supporting the Director IT … cloud security, certificate management, network security, and vulnerability management. Respond to critical incidents in a timely manner in partnership with security operations, legal, compliance, incidentresponse teams, etc. Qualifications & Experience: Bachelor’s degree; Preferred Management Information Systems, Computer Science, Engineering, or related discipline. 5-10 years of information …/IP, Storage devices, network devices, fail-safe strategies, system architecture, LAN and WAN and intranet/internet security environments including firewalls, intrusion detection, incidentresponse, vulnerability testing, operating system hardening, regulatory compliance, and data classification. Experience in IAM, SEIM, Log Management, Patch Management, Vulnerability Management, eDiscovery, Cloud More ❯
oxford district, south east england, United Kingdom
LT Harper - Cyber Security Recruitment
Operations Centre (SOC) practices. This role is ideal for someone with a strong ability to analyse and enhance SOC effectiveness, from threat detection to incidentresponse, and provide clear and appropriate advice and guidance. Key Responsibilities of the SecOps Consultant Collaborate with clients to improve SOC operations, particularly … operational needs. Monitor emerging threats and trends, advising stakeholders on potential impacts and mitigation strategies. Deploy, configure, and manage security tools to optimize detection, response, and reporting functions. Skills & Knowledge Solid understanding of SOC best practices, incidentresponse, and regulatory frameworks (e.g., GDPR, NIST, ISO 27001). More ❯
oxford district, south east england, United Kingdom Hybrid / WFH Options
Lawrence Harvey
in place, this is a relatively greenfield SOC buildout, where you will work alongside the SOC Manager to shape their SOC monitoring, detection and response function. Key Responsibilities: Act as a lead and technical escalation point on the most complex incidents and investigations. Work closely with Security Engineering team … to recommend system tuning/configuration improvements. Mentor and train junior team members through complex incidentresponse investigations. Key Requirements: Significant experience working in a SOC environment, dealing with and responding to escalated and most high profile incidents. Comprehensive knowledge of the Microsoft Security stack – Defender, Sentinel, etc … Knowledge of various IncidentResponse techniques and procedures. Experience working in hybrid-cloud SOC environments – Azure/AWS preferably. If you’re an experienced SOC Analyst, looking to shape how one of the most innovative Mobile Payments FinTech firms build out their cyber defence capability and leave a More ❯
oxford district, south east england, United Kingdom
Arcus Search
The scope of work includes replacing the existing Trend Micro infrastructure and rolling out CrowdStrike across all server environments to enhance threat detection and response capabilities. Job Title: Security Consultant Job Type: 3 month Contract Contract: Outside I35 Location: Remote Responsibilities: Collaborate with delivery teams and the client to … develop SOC playbooks supporting both SIEM and SOC operations. Design and implement SOAR workflows to automate incidentresponse processes. Configure correlation searches and alerting mechanisms, optimising rules to minimise false positives. Serve as the Subject Matter Expert (SME) for SIEM deployment, supporting data ingestion from sources such as … AWS and Qualys. Assist in the integration of SIEM alerts with Jira, enabling streamlined alert tracking and incident management. Define and configure alert severity levels within SIEM, SOAR, and Jira to align with established Service Level Agreements (SLAs). Build and customise dashboards to support real-time reporting and More ❯
oxford district, south east england, United Kingdom
Ranger Technical Resources
manage system health. Skills and Strengths: AWS (Amazon Web Services) Auto Scaling Fargate Route53 Observability tools (New Relic, DataDog, Splunk) Containerization (Docker, Kubernetes, Fargate) IncidentResponse IaC (Terraform, CloudFormation, Helm, CDK) Scripting (Ansible, Bash, Python, GO) CI/CD Primary Job Responsibilities: Design and support EC2/ECS … solutions to improve scalability and efficiency. Implement security best practices across AWS environments, ensuring compliance with industry standards and safeguarding cloud infrastructure. Develop automated incidentresponse mechanisms and self-healing solutions to minimize downtime and enhance fault tolerance. Diagnose and resolve infrastructure, networking, and application-related performance issues More ❯
oxford district, south east england, United Kingdom
Newstone Talent Solutions
developer experience across the organisation. This is a key role within a modern, cloud native environment where you’ll combine SRE principles (reliability, observability, incidentresponse) with cutting-edge platform engineering (GitOps, IaC, DevSecOps). You'll play a critical part in enabling product teams to ship faster … itself. Responsibilities: Architect and operate scalable, secure infrastructure in Azure (AKS, Functions, SQL, Cosmos DB, etc.) Apply SRE best practices: SLOs, alerting, observability, and incident management Build and maintain Infrastructure as Code (Terraform, v1.7+) and GitOps workflows Enhance CI/CD pipelines (Azure DevOps) with security scanning, automation, and … for development teams Improve monitoring across systems using tools like Datadog, Grafana, ELK, and synthetic checks Participate in the on-call rota and lead incidentresponse and post mortems Promote FinOps best practices and cost optimisation strategies Contribute to internal platform governance, documentation, and coaching Experience required - Non More ❯
oxford district, south east england, United Kingdom Hybrid / WFH Options
Intec Select
infrastructure. Role & Responsibilities: Monitor networks and systems for security breaches, intrusions, and abnormal system behavior Investigate security incidents, perform root cause analysis, and provide incidentresponse support Conduct regular vulnerability assessments and penetration testing; assist in remediation efforts Maintain and manage SIEM (Security Information and Event Management) tools More ❯
oxford district, south east england, United Kingdom Hybrid / WFH Options
Dynamic Search Solutions
based clients, this role also requires eligibility to obtain SC Clearance. Roles & Responsibilities Create, maintain, and optimise Logic Apps and Sentinel playbooks to automate incident detection and response workflows in Microsoft Sentinel. Develop and implement API integrations between Microsoft Sentinel and other systems to enhance data collection, cross … as expected, identifying opportunities for further improvements. Skills & Experience Hands-on experience with Microsoft Sentinel: proven track record in developing playbooks, automation workflows, and incidentresponse processes within Microsoft Sentinel. Experience in building and maintaining workflows with Azure Logic Apps to automate processes. Strong experience in API development More ❯
oxford district, south east england, United Kingdom
Burman Recruitment
implementation of security strategies. Develop and enforce cybersecurity policies, standards, and best practices. Conduct vulnerability assessments and manage compliance with security frameworks. Oversee security incidentresponse, forensic investigations, and risk mitigation strategies. Monitor networks and systems, ensuring proactive threat detection and response. Collaborate with internal stakeholders and external More ❯
our existing suite of tools and controls to keep pace with changing threats. Collaborate with the managed SOC provider to ensure timely and effective response to security incidents. Assist in the development and maintenance of the organisation’s incidentresponse plan. Collaborate in assessing and closing out More ❯
our existing suite of tools and controls to keep pace with changing threats. Collaborate with the managed SOC provider to ensure timely and effective response to security incidents. Assist in the development and maintenance of the organisation's incidentresponse plan. Collaborate in assessing and closing out More ❯
oxford district, south east england, United Kingdom
LHH
reviews and assurance of designs working with System Integrators & partner resources. Conduct threat modeling and risk assessments on network infrastructure and recommend mitigations. Support incidentresponse teams during network-related security incidents and perform root cause analysis. Evaluate and recommend security tools and technologies, and stay informed on More ❯
oxford district, south east england, United Kingdom
PayPoint plc
and take corrective actions. Triage and escalate incidents based on severity, organizational policies, and operational impact, ensuring timely resolution and minimal downtime. Perform initial incidentresponse actions , including containment, mitigation, and support for recovery, working closely with IT and security teams. Collaborate with IT and security teams to … Ensure the availability and performance of services, proactively identifying potential issues that could affect users, and collaborating with teams to resolve operational incidents. Maintain incident logs, documentation, and reports , tracking all events and resolutions for auditing, compliance, and continuous improvement purposes. Analyse trends in security threats and vulnerabilities , staying … ahead of emerging risks and continuously refining response strategies to mitigate future incidents. Participate in threat hunting and vulnerability assessments, working with cross-functional teams to identify and close gaps in security while ensuring business operations run smoothly. Support internal and external stakeholders to ensure security configurations, operational practices More ❯
oxford district, south east england, United Kingdom
Emeria
ecosystem. You are passionate about leveraging Microsoft security technologies to protect critical assets and data, with a focus on proactive monitoring, threat detection, and incident response. Your hands-on expertise with Microsoft Defender solutions and Azure-based security tools will be crucial in maintaining a secure and resilient IT … Group Policy (GPO) to secure endpoints, user accounts, and cloud applications. Monitor security alerts and incidents through Microsoft Sentinel, conducting thorough investigations and leading response efforts to mitigate risks. Perform proactive threat hunting using data from Defender, Sentinel, and Entra logs to detect potential security incidents. Optimise and maintain … threat detection rules, automation playbooks, and alert tuning within Sentinel and Defender solutions to reduce false positives and enhance response efficiency. Manage access control policies and identity protection configurations to secure user authentication and reduce the risk of account compromise. Regularly assess the security posture of Microsoft 365 and More ❯
oxford district, south east england, United Kingdom Hybrid / WFH Options
Aveni
AI & Data Security – Driving best practices for AI-first security and compliance. Business-Focused Security Strategy – Supporting sales, contracts, and client security due diligence. IncidentResponse & Risk Management – Leading security response planning and mitigation strategies. Collaboration & Stakeholder Engagement – Partnering with engineering, product, and leadership teams to drive More ❯
oxford district, south east england, United Kingdom
Acumin
innovation Security Architecture & Operations: Oversee the design and operation of our global cloud security infrastructure across AWS, GCP, and/or Azure. Drive robust incidentresponse, threat detection, and remediation processes. Risk Management & Compliance: Lead risk assessments and ensure adherence to international compliance standards (SOC 2, ISO More ❯