Incident Response Jobs in the South East

1 to 25 of 88 Incident Response Jobs in the South East

Incident Response Specialist

London, South East, England, United Kingdom
QBE Management Services (UK) Limited
Primary Details Time Type: Full time Worker Type: Employee Incident Response Specialist London/Hybrid (2 days a week) The Opportunity QBE Europe is currently recruiting an incident response specialist to join our cyber security team in our London Office. Reporting to regional team leads, the Security Incident Responder will be a key member of … high-level proactive and reactive threat hunting methods, classifying, analysing, prioritising and remediating security alerts/events. The focus is to provide effective, proactive and a highly technical analytical response to cyber security-related incidents to prevent QBE from becoming compromised by modern attack methods and techniques. Your new role Act as point of escalation and mentor to junior … and resources to correlate suspicious events, providing context around the event, determine root cause and provide regular updates and recommend modifications to existing systems and procedures. Perform deep-dive incident analysis of various data sources by analysing and investigating security related logs against medium-term threats and IOCs Actively manage and apply the phases of Incident Response More ❯
Employment Type: Full-Time
Salary: Competitive salary
Posted:

Cyber Incident Manager

Maidenhead, Berkshire, United Kingdom
Hybrid / WFH Options
APM Terminals
how it's done. At Maersk, one of the world's largest and most respected logistics and shipping companies, our Cyber team is pioneering a whole new approach to incident response. This isn't your typical SOC/CERT role: our combined fire team approach team is built on cutting-edge research and designed to drive change, resilience, and … seen before. Here, you'll be part of a dynamic team that works together to defend, adapt, and innovate with freedom and purpose. You won't just work on Incident Management; you'll help improve how it's done. Dive into purple teaming, create and refine world-class detections, shape change projects, and push the boundaries of what's … in innovative projects that allow you to bring your ideas to life, help shape the future of cybersecurity while developing new capabilities that enhance our operations. About the role: Incident Response and Leadership Lead incident management activities in response to all high priority cyber-security incidents, with the ability to remain calm and focused during crisis More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

DevSecOps Engineer - ONSITE

Loughton, Essex, South East, United Kingdom
Hybrid / WFH Options
Profile 29
will focus on creating a business strategy, gap analysis and implementation, for securing their Azure-based infrastructure, integrating security automation, ensuring PCI DSS compliance, vulnerability and penetration testing and incident response. This role will focus on developing and maintaining secure, scalable Azure DevOps pipelines and Infrastructure as Code (IaC) using Terraform. Their ideal candidate will have a strong background … every stage. Cloud Security Implementation: Leverage Azure Security Centre, Microsoft Defender for Cloud, and Microsoft Sentinel for advanced security monitoring. Threat Detection & SOAR Automation: Oversee Security Orchestration, Automation, and Response (SOAR) solutions including SOC Prime. Network & Application Security: Manage Web Application Firewalls (WAF) and Intrusion Prevention Systems (IPS). Vulnerability & Penetration Testing: Review Penetration Testing, vulnerability assessments, and security … proactively identify and remediate risks. PCI DSS Compliance: Conduct security audits, risk assessments, and ensure regulatory compliance. DNS Security: Implement and monitor DNS security solutions to prevent cyber threats. Incident Response: Formulating and documenting a solid process utilising a 3rd party support partner Security Monitoring & Logging: Develop SIEM solutions, logging strategies, and real-time threat intelligence. Monitor, audit More ❯
Employment Type: Permanent, Work From Home
Posted:

Business Information Security Officer (BISO)

London, South East, England, United Kingdom
WTW
Ensure cybersecurity practices and security by design are integrated into business unit initiatives, motivating business units to adopt efficient security controls throughout their lifecycle. Oversight of R&B’s response to Incident, integrating cyber incident response policies with business operations to improve agility and effectiveness in cyber incident management. Work with R&B leaders to … team exercises Foster relationships with internal business units to enhance cyber security communication, including knowledge of threats, vulnerabilities, and mitigation strategies. Provide strategic insights to senior management on cyber incident response readiness and effectiveness. Collaborate with security leadership to enforce cyber security policies and practices, addressing operations and incident response. Provide expertise and knowledge to the business … and technology governance forums. The Requirements Technical skills: A comprehensive understanding of information security services (security operations and offensive security testing) Experience of strategic planning and oversight of cyber incident response and crisis management Strong understanding of cybersecurity standards and frameworks (e.g. ISO27001, NIST, CIS) and their application in strategic planning and policy development Ability to collaborate business More ❯
Employment Type: Full-Time
Salary: Competitive salary
Posted:

Information Security Analyst - Audit, Compliance & Cybersecurity

Southampton, Hampshire, United Kingdom
Hybrid / WFH Options
NICE
ISO 42001, GDPR, and DORA. This role focuses on internal audits, regulatory compliance, and readiness for external audits while also contributing to Cybersecurity Operations Center (CSOC) activities, including incident monitoring and response. How will you make an impact? Internal Audit Execution: Conduct internal audits to evaluate and enhance IT controls, compliance with standards, and risk management processes. Audit Preparation … audit teams to streamline processes and provide requested documentation and evidence. Security Monitoring: Use tools such as Rapid7 InsightIDR or other SIEM solutions to assist with security monitoring and incident detection. Incident Response Support: Participate in incident response efforts, documenting security incidents and assisting in containment and recovery actions. Threat Identification: Contribute to analyzing cybersecurity … Plus. Familiarity with CSOC tools such as Rapid7 InsightIDR or other SIEM solutions. Hands-on experience in internal and external audits, compliance assessments, and process improvement. Basic understanding of incident response frameworks and cybersecurity best practices. Exceptional analytical, organizational, and communication skills. Commitment to continuous learning and professional development in audit, compliance, and security. You will have an More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Incident Responder / IR Consultant - London

London, South East, England, United Kingdom
Circle Recruitment
Incident Responder/IR Consultant Hybrid - LondonUp to £65k + Bonus + Good bens. I'm currently working with an established cyber security business that's looking for an Incident Responder (IR/DFIR Consultant) to join their team. As an Incident Responder, you'll take the lead on active engagements involving real-world attacks such as … ransomware, data breaches, insider threats, and more. You'll conduct forensic investigations, advise clients on containment and recovery strategies, work on delivery and implementation, and produce detailed post-incident reports. This is a hands-on, client-facing role that requires a calm head, deep technical knowledge, and the ability to own high-impact situations from start to finish. You … will be working on back-to-back incidents (occasionally concurrent) so this role would suit someone who enjoys the high-pressure environment of incident response and enjoys being busy. Responsibilities: Co-ordinate and manage cyber security incident response for a diverse client base, ensuring effective containment, investigation, and recovery. Conduct in-depth digital forensic analysis of More ❯
Employment Type: Full-Time
Salary: £55,000 - £65,000 per annum
Posted:

SRE/Infrastructure Engineer

Basingstoke, Hampshire, United Kingdom
InfoSum Limited
as the monitoring and deployment services that enable the rest of engineering to develop, deliver and maintain our platform services. You will also be instrumental in both monitoring and incident response, playing a key role in ensuring maximum reliability and minimal downtime. You will collaborate with teams across the company, including developers, customer support, product owners and sales … to track the health, performance, and availability of infrastructure components and applications. Configure alerting mechanisms to notify teams of potential issues and proactively address them before they impact users. Incident Response and Root Cause Analysis: Participate in incident response activities to identify, troubleshoot, and resolve incidents. Communicate incident status and updates to ensure both internal More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Senior Security Operations Engineer

London, South East, England, United Kingdom
Holland & Barrett International Limited
automation, cloud technology, and fast-paced problem-solving—and want your work to have a real impact—this could be the perfect role for you. Key Responsibilities Lead security incident response and threat detection efforts, prioritising the protection of customer data and experience Build automated detection and remediation workflows using SOAR, SIEM, and scripting (Python, SQL) Apply deep … facing and payment systems into the security monitoring platform Perform threat hunting and detection engineering to identify and address emerging risks Support security audits, compliance (PCI-DSS), and post-incident reviews Mentor junior team members and contribute to a culture of continuous improvement Participate in the on-call rotation to ensure fast, effective incident response during critical … events Key requirements: Proven Experience: 4+ years in Security Operations or Incident Response, ideally in ecommerce, retail, or fintech environments Technical Depth: Hands-on expertise with SIEM, SOAR, EDR, automation tools, Python, SQL, and cloud-native security tooling Cloud Security: Strong knowledge of AWS and Azure, especially services like WAF, Shield, IAM, and API Gateway Forensic Skills: Experience More ❯
Employment Type: Full-Time
Salary: Competitive salary
Posted:

Senior Cyber Security Consultant

Crawley, West Sussex, South East, United Kingdom
Henderson Scott
is a pivotal opportunity for an experienced Senior Consultant to lead large-scale cybersecurity projects across a diverse client base. The role focuses on cyber resilience, including threat intelligence, incident response, risk management, compliance, and security architecture. You will act as a trusted advisor, delivering tailored solutions that help clients enhance their cyber posture and protect their critical … the end-to-end delivery of cyber resilience projects, ensuring solutions are scalable, secure, and aligned with client goals Design and implement advanced cyber resilience solutions and frameworks Manage incident response, guiding teams through breach containment and recovery Engage directly with clients to identify requirements, provide expertise, and drive successful outcomes Facilitate Agile ceremonies to support efficient project … members, encouraging skill development and knowledge sharing Contribute to business development by producing high-quality proposals and identifying growth opportunities Skills & Experience ? Extensive expertise in threat intelligence, risk management, incident response, compliance (e.g. GDPR, ISO 27001), and security architecture ? Proficiency with tools such as Rapid7 InsightIDR/InsightVM, SentinelOne, Fortinet, Netskope, SOAR automation (Rapid7 InsightConnect), and cloud security More ❯
Employment Type: Permanent
Salary: £80,000
Posted:

Security Engineer

London, South East, England, United Kingdom
Hybrid / WFH Options
Randstad Technologies
Location: United Kingdom 100% Remote? Duration: 6 Months Clearance: Active SC Clearance is required Are you a hands-on Security Engineer with deep expertise in SIEM , Azure Sentinel , and incident response Join a dynamic cyber security team to support a critical national infrastructure (CNI) project involving the deployment of Windows Hello for a major UK utility company. What … You'll Be Doing: Supporting and tuning Microsoft Sentinel and other SIEM platforms (KQL scripting) Managing escalated incidents from L1 analysts and leading full incident response lifecycle (MIM) Conducting in-depth data analysis , threat hunting, and forensic investigations Maintaining and enhancing SOC documentation, SOPs, and playbooks Collaborating with cross-functional teams and contributing to security strategy Ensuring security … MITRE ATT&CK We're Looking for Someone With: Expert-level SIEM experience (Azure Sentinel highly preferred) Strong knowledge of Kusto Query Language (KQL) Demonstrated experience in cybersecurity incident response & breach handling Familiarity with threat intelligence, vulnerability management , and cloud security tools Proactive mindset with ability to work independently in high-pressure environments Active SC Clearance Ready to More ❯
Employment Type: Contractor
Rate: £430 - £570 per day
Posted:

Cyber Security Manager

South Croydon, Surrey, England, United Kingdom
Hybrid / WFH Options
Gold Group Ltd
a leading organisation based in Croydon, who are looking to employ an experienced Cyber Security Manager with an in-depth knowledge of Cybersecurity frameworks, tools, and technologies, ISO27001 adoption, Incident management and Change management. This role involves the development and implementation of security strategies, policies, and procedures to protect against cybersecurity threats, as well as actively monitoring and responding … per week Some of the main duties of the Cyber Security Manager will include: * Security Strategy & Implementation: Design, implement, and maintain comprehensive cybersecurity policies, procedures, and controls* Threat Detection & Response: Continuously monitor the digital environment for potential vulnerabilities and security breaches* Incident Management : Lead incident response activities, coordinating with IT teams to mitigate risks and minimise … damage. Responsible for writing incident reports, gathering input across the technical and business teams to then share the report and project management of any improvement change actions* Security Integration & System Management: Collaborate with IT and development teams to ensure security is embedded in all new and existing applications, systems, and network infrastructure* Risk Management & Compliance: Ensure compliance with industry More ❯
Employment Type: Full-Time
Salary: £70,000 per annum
Posted:

IT Security Consultant

Bedford, Bedfordshire, South East, United Kingdom
Hybrid / WFH Options
Total IT
will play a pivotal role in safeguarding IT infrastructure and clients' digital assets. This position demands a proactive approach to security, encompassing the monitoring and protection of systems, strategic response to cyber threats, and the development of comprehensive security practices and strategy. You will serve as a key advisor to both clients and internal teams, guiding them through the … complexities of cyber security with your expertise. Responsibilities: Lead and support in the investigation and management of security incidents, ensuring a strategic response to mitigate risks. Implement and oversee security solutions for clients, ensuring their IT environments are resilient against cyber threats. Act as a primary point of contact for clients, providing expert advice on cyber security measures, best … practices, and threat management. Develop and maintain documentation, including best practice guides and incident reports, to educate clients and team members on security awareness. Conduct vulnerability assessments and participate in the development of incident response protocols to enhance security posture. Offer technical guidance to team members, fostering a culture of continuous learning and improvement within the security More ❯
Employment Type: Permanent, Work From Home
Salary: £40,000
Posted:

IT Specialist Senior IT Security Specialist - Ashford or Cairns

Ashford, Kent, United Kingdom
Hybrid / WFH Options
MAF Australia
responsible for implementing and managing security infrastructure, responding to threats, and ensuring compliance across systems. You'll work with various cyber security solutions while driving security best practices and incident response. If you have experience in cybersecurity tools, governance, and access management-and want to use your skills to support a mission that changes lives-this is your chance … Operations Specialist you will play a critical role in protecting our digital infrastructure. You'll lead the implementation and management of SIEM systems, Fortinet security tools, and endpoint detection & response (EDR) while conducting vulnerability assessments and penetration testing to stay ahead of cyber threats. You'll enhance identity and access management (IAM) by maintaining Active Directory, Entra ID, MFA … and Zero Trust security principles. Your expertise in network security, VPNs, SD-WAN, and Microsoft Defender solutions will help safeguard our systems, while your contributions to incident response, governance, and security strategy will shape the future of our cybersecurity posture. If you're passionate about cybersecurity and want to make a meaningful impact, then this role is for More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Senior Security Engineer - SIEM, KQL

London, South East, England, United Kingdom
Harvey Nash
log parsing Threat Detection & Use Case Development: Develop and refine detection rules based on threat intelligence and attack patterns Continuously improve detection efficacy and reduce false positives Security Monitoring & Incident Response: Monitor systems for anomalies and malicious activity Contribute to threat hunting and incident response playbooks Provide expert guidance on securing applications and infrastructure Security Advisory More ❯
Employment Type: Contractor
Rate: £600 - £800 per day
Posted:

Cyber Security Analyst

London, South East, England, United Kingdom
Hybrid / WFH Options
SNG (Sovereign Network Group)
incidents and escalate as appropriate Collaborate with the SOC and internal teams to respond to and resolve security events Drive vulnerability remediation across infrastructure and cloud environments Participate in incident response activities, forensic investigations, and risk mitigation Participate in an on-call rota for out-of-hours cyber incident response What We're Looking For Experience More ❯
Employment Type: Full-Time
Salary: £48,000 - £60,000 per annum
Posted:

Cyber Security Analyst

Basingstoke, Hampshire, England, United Kingdom
Hybrid / WFH Options
SNG (Sovereign Network Group)
incidents and escalate as appropriate Collaborate with the SOC and internal teams to respond to and resolve security events Drive vulnerability remediation across infrastructure and cloud environments Participate in incident response activities, forensic investigations, and risk mitigation Participate in an on-call rota for out-of-hours cyber incident response What We're Looking For Experience More ❯
Employment Type: Full-Time
Salary: £48,000 - £60,000 per annum
Posted:

Cyber Threat Intelligence Lead

Rickmansworth, Hertfordshire, South East, United Kingdom
Hybrid / WFH Options
Senior plc
and experience: An experienced threat intelligence lead (or similar). Expert in cybersecurity, with a focus on threat management and defensive security in regulated environments. Proficient in threat management, incident response and remediation tools. Strategic development in cyber threat intelligence research, process automation, knowledge sharing and team training. Skilled in using threat frameworks (e.g. MITRE ATT&CK, Cyber … Kill chain). Experienced in using OSINT and security analysis tools (e.g. Shodan, Censys, Qualys, Virus Total, EDR, AV). Experience supporting incident response or vulnerability management programs. Professional certifications in Cyber and Information Security (e.g. OCSP, GREM, CEH). Strong analytical and problem-solving abilities, translating complex technical issues into actionable recommendations. An excellent communicator with the More ❯
Employment Type: Permanent, Work From Home
Posted:

Senior Security Operations Analyst SOC

London, South East, England, United Kingdom
Hybrid / WFH Options
Client Server Ltd
incidents using SIEM tools (Splunk) to create detection use cases, analyse security event data for proactive threat hunting and conduct research on the latest threats and vulnerabilities to enhance incident response readiness and capabilities. Location/WFH: You'll join the team in the Frankfurt office three days a week with flexibility to work from home the other … two days. About you: You are degree educated in Cyber Security or Computer Science You have strong experience in Security Operations and Incident Response You have experience of performing analysis with SIEM technologies, Splunk preferred You have experience with proactive threat hunting using MITRE ATT&CK or similar frameworks You have a deep understanding of security appliances/ More ❯
Employment Type: Full-Time
Salary: £90,000 - £100,000 per annum
Posted:

Cloud Security Engineer - July 2025

London, South East, England, United Kingdom
Tenth Revolution Group
Center, VPC Service Controls, Azure Security Center, Azure AD, and Microsoft Defender for Cloud. Conduct security assessments, vulnerability scans, and penetration testing. Monitor cloud environments for threats and lead incident response efforts. Integrate security into the CI/CD pipeline and ensure secure configurations. Develop and enforce cloud security policies aligned with regulatory and internal frameworks. Provide guidance … Qualifications 6+ years of experience in cloud or information security. Proven experience securing Google Cloud Platform (GCP) environments. Strong understanding of cloud security principles and native controls. Experience with incident response and threat modelling. Relevant certifications such as: Google Professional Cloud Security Engineer Azure Security Engineer Associate (AZ-500) Certified Cloud Security Professional (CCSP) Key Attributes Strong verbal More ❯
Employment Type: Contractor
Rate: £400 - £480 per day
Posted:

Senior Security Engineer

London, South East, England, United Kingdom
Hybrid / WFH Options
Crone Corkill
basis until the move has been completed Maintain Nessus vulnerability management, update systems, run scans and provide reports Cover email security using Mimecast Enterprise Real world threat modelling and incident response (mainly L3/L4 when required) Make suggestions and influence various areas of the business/group from a security perspective Automate tasks and processes to make … expertise (full lifecycle ideal) Microsoft Defender for EDR/XDR/MDR Nessus for vulnerability management Mimecast for email security SCCM/Intune for patch management L3/L4 Incident Response experience Threat Intelligence/modelling experience Automating tasks using PowerShell, Python etc What’s in it for you? In return you’ll be joining a well established More ❯
Employment Type: Contractor
Rate: Competitive salary
Posted:

Contract Security Engineer Azure/GCP

London, South East, England, United Kingdom
Tenth Revolution Group
Defender for Cloud). Conduct regular security assessments, vulnerability scanning, and penetration testing of cloud infrastructure and applications. Monitor cloud environments for security threats, anomalies, and incidents, and lead incident response efforts. Collaborate with development, operations, and compliance teams to integrate security best practices into the CI/CD pipeline and ensure secure configurations. Develop and enforce security … of GCP security services and best practices. Solid understanding of cloud security principles, including shared responsibility model, cloud native security controls, and infrastructure as code security. Experience with security incident response and threat modelling. Google Professional Cloud Security Engineer Azure Security Engineer Associate (AZ-500) Certified Cloud Security Professional (CCSP) This is very much a hands-on role More ❯
Employment Type: Contractor
Rate: £400 - £450 per day
Posted:

Deputy Director Head of Service Operations - DEFRA - SCS1

Reading, Berkshire, United Kingdom
Manchester Digital
what users need, when they need it. Provision of effective cyber security protective monitoring, vulnerability management in conjunction with technical teams and suppliers, and a responsive and effective cyber incident response capability. Lead on software licencing (circa £40m/y) seeking to ensure legal compliance and cost effectiveness Provide a comprehensive inventory of the IT estate to enable … Certification in ITIL mandatory. A thorough understanding of modern IT technologies and management approaches. Knowledge and experience in leading in an operational environment. Knowledge of cyber security and cyber incident response Desirable a certification in Service Operations. Skills Required Strategic thinking and strategy development, especially in the area of IT services. Exceptional leadership skills, including in operational crisis More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Information Security Officer UK Head Office - Basingstoke

Basingstoke, Hampshire, United Kingdom
Once For All Limited
the organization's digital assets. They work closely with the CISO,Legal, Compliance, technical and business teams to ensure proactive protection against cyber threats, regulatory compliance,risk management and response to security incidents. The role will build relationships with departments to ensure identification and continuous progression of security threats in ourfast-paced SaaS technology business. This role blends operational … threats. • Deliver Information Security and Cybersecurity project management. • Monitor and manage digital access controls across cloud platforms, internal systems, and third-party tools. • Assist in the detection, investigation, and response to security incidents, including unauthorized access, phishingattempts, and data anomalies. • Collaborate with cybersecurity teams and other third parties to analyse threat intelligence feeds and proactively identifyemerging risks. • Participate in … and continuous improvement of security operations. Cybersecurity Management: • Supervise technological security measures including SIEM, DLP, IDS/IPS, Firewall, WAF, cryptological mechanisms, EDR • Analyse security alerts and conduct technical incident investigations. • Run and monitor vulnerability tests and periodic scans of key assets • Collaborate on managing security patches and updates with Internal IT, CloudOps and Engineering teams • Document technical findings More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Operational Security Architect - DV Cleared

Basingstoke, Hampshire, United Kingdom
Experis - ManpowerGroup
information transfers, and maintaining compliance with strict regulatory standards. What You'll Bring Proven experience in Operational Security Management , with a deep understanding of security policies, risk mitigation, and incident response . Experience as a Security Officer (STRAPSO highly desirable) with strong asset management skills. MUST have NIST Secure by Design (SbD) experience Strong leadership skills , capable of … working across teams and disciplines to enhance security operations. Expertise in incident classification, response, and reporting , with the ability to identify, assess, and mitigate evolving threats. Ability to manage security training , document security policies, and conduct audits to ensure ongoing compliance. Excellent communication skills , capable of advising both technical and non-technical stakeholders. Secure Your Future. Shape the More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Senior Software Engineer, Fleet

Fleet, Hampshire, United Kingdom
Hayden AI Technologies, Inc
cutting-edge innovation. As part of our team, you'll have the opportunity to work on impactful projects that drive the future of intelligent transportation systems. Responsibilities: Participate in incident prevention, response, and remediation efforts, learning and applying best practices. Design, build, and maintain scalable cloud services that support device observability, OTA updates, and fleet operations. Lead efforts … CI/CD pipelines for cloud services, enabling efficient, secure, and automated delivery processes. Set and uphold high standards for software engineering and DevOps practices across the team, including incident response, monitoring, and postmortems. Collaborate with cross-functional teams-including hardware, product, and other engineering teams-to define system requirements and deliver robust end-to-end solutions. Drive More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:
Incident Response
the South East
10th Percentile
£42,000
25th Percentile
£49,000
Median
£55,000
75th Percentile
£72,500
90th Percentile
£77,500