151 to 175 of 2,202 Incident Response Jobs in the UK

Senior SecOps Specialist

Hiring Organisation
Teya Solutions
Location
London, United Kingdom
Salary
£ 80 K
work closely with Security Engineering, IT, Infrastructure, Platform, Cloud, and Product teams to reduce risk and embed security effectively across the organisation.You operate across incident response, detection engineering, security tooling, vulnerability management, threat intelligence, telemetry, and automation - turning operational insight into stronger controls and better engineering outcomes.ResponsibilitiesSecurity Operations … Incident Response• Lead end-to-end investigation and response of complex security incidents.• Act as L3 escalation point for SOC analysts and MSSP.• Coordinate across Security, Engineering, IT, Cloud, Legal, and Compliance duringincidents.• Make clear, risk-based decisions under pressure with strong documentation.• Maintain playbooks, runbooks ...

Security Operations Manager

Location
Greater London, England, United Kingdom
their business. Job Description This is a hands-on leadership role. You need to be technical, in the detail, and able to lead an incident bridge. You will run a global function and own Security Operations end to end: the SOC, incident response, detection engineering and threat … intelligence, along with the people and platforms behind them. THE CHALLENGE: Own incident response. Preparation, triage, containment, eradication, and the post-incident reviews that make the next incident smaller. You will lead major incidents personally and set the standard for what good looks like. Build ...

Vice President, Threat and Vulnerability Management Team Lead

Hiring Organisation
MUFG
Location
London, United Kingdom
Salary
£ 100 K
patch deployments and associated post-deployment check-outs.Triage vulnerabilities into “Fix, Acknowledge, and Investigate” categories using industry-aligned risk rating methodologies.Use ServiceNow Application Vulnerability Response (AVR) and Vulnerability Response (VR) modules to manage and report on vulnerabilities and violations across the estate, integrating with dashboards and workflows … vulnerability scanning, penetration testing, and security awareness training.Proficiency in using vulnerability scanning tools (e.g. Tenable, Qualys, Rapid7, Veracode, JFrog Xray), threat intelligence platforms, and incident response tools.Prior experience implementing automated solutions for vulnerability scanning, threat detection, and incident response, with a focus on continuous process improvement.Risk ...

Senior Associate, Digital Forensics and Incident Response

Hiring Organisation
Kroll
Location
United Kingdom
Salary
£ 60 K
Senior Associate, Digital Forensics & Incident ResponseWhen a cyber incident strikes, clients need clarity, speed and confidence. Kroll’s DFIR experts respond to more than 2,000 incidents each year, combining deep technical expertise with commercial judgement to help organisations contain threats, understand their impact and move forward decisively. … Looking ForYou are technically strong, client-focused and calm under pressure, with the judgement to turn complex evidence into actionable advice.3+ years’ experience in incident response, digital forensics, cyber investigations or a related field.Hands-on strength in incident response, forensics, malware analysis, network security or security ...

Cyber Response & Recovery Manager (Reactive DFIR) – German Speaking

Location
Greater London, England, United Kingdom
Role This hands-on position sits within a cyber advisory practice, focusing on reactive digital forensics and incident response. Day to day, the role involves managing medium to large incident response cases, supporting clients in building internal IR capabilities, contributing to runbooks and playbooks, and developing internal … tooling, processes, and team training when not engaged on active cases. Skills & Experience Candidates require a strong technical background in digital forensics and incident response, with proven incident management experience. The role demands eligibility for SC or DV security clearance. Opportunities exist to obtain recognised security certifications ...

Information Security Consultant

Location
United Kingdom
parts of their security programme they cannot resource internally — from regulatory compliance and risk management through to board-level reporting and incident readiness. As an Information Security Consultant you will act as the vCISO lead on a portfolio of client engagements. You will be the security voice … controlled engagement documentation in the shared client collaboration space. Supply chain and third‐party assurance Conduct vendor and supplier due diligence, including questionnaire design, response review and risk identification. Support clients with inbound third‐party due diligence requests, compliance questionnaires and cyber insurance proposal forms, including evidence gathering. Training ...

Staff Software Engineer - Databases SRE | UK | Remote

Hiring Organisation
Grafana Labs
Location
United Kingdom
Salary
£ 70 K
SLOs and reliability modelsProactively reduce SLO burn to prevent repeat incidentsServing as a primary escalation point and on-call for relevant incidentsLead customer-impacting incident response and post-incident reviewsContribute to design docs and code reviewsInfluence feature design to ensure production scalability and operabilityBuild automation to eliminate … funded usage budget so you can iterate quickly without unnecessary friction. We encourage pragmatic AI-assisted development: faster prototyping, test generation, refactors, documentation, and incident follow-ups—always paired with strong code review and quality standards. You’ll also have access to frontier models (e.g., GPT-Codex 5/ ...

Director, R&D, Email & Collaboration Threat Protection

Hiring Organisation
Mimecast
Location
London, United Kingdom
Salary
> £ 150 K
eager to master them quickly.Our AI leadership extends beyond how we build to what we build. Our Mihra AI agent delivers 7x faster threat response for customers, and we're recognized as "Agents of Change" in Human Risk Management. Engineers here work at the intersection of cutting-edge … clear succession planning for key leadership and senior technical roles.Drive Engineering Excellence: Set and maintain high standards across your squads: testing, observability, release governance, incident response, and secure development practices. Hold the organisation accountable for operational excellence on a zero-downtime, globally distributed platform — including post-incident ...

Director, MTA Engineering

Location
Greater London, England, United Kingdom
eager to master them quickly.Our AI leadership extends beyond how we build to what we build. Our Mihra AI agent delivers 7x faster threat response for customers, and we're recognized as "Agents of Change" in Human Risk Management. Engineers here work at the intersection of cutting-edge … succession planning for key leadership and senior technical roles.* **Drive Engineering Excellence:** Set and maintain high standards across your squads: testing, observability, release governance, incident response, and secure development practices. Hold the organisation accountable for operational excellence on a zero-downtime, globally distributed platform — including post-incident ...

Senior Platform Engineer

Location
Greater London, England, United Kingdom
systems. Improve developer experience through automation, self-serve tooling and infrastructure-as-code practices that increase engineering velocity. Own and evolve our observability, incident response and reliability practices to minimise downtime and improve system performance. Partner closely with product and engineering teams to support new services, migrations … distributed systems fundamentals. Experience improving CI/CD pipelines and deployment automation in fast-moving engineering teams. Comfortable debugging production issues and participating in incident response in high-availability environments. Clear communication skills and the ability to work closely with software engineers across multiple teams. You get excited ...

Director, ProdSecOps

Hiring Organisation
Genius Sports
Location
London, United Kingdom
Salary
£ 120 K
program leadership role responsible for embedding security into how products are designed, built, and shipped — and for owning the full threat detection and incident response pipeline end-to-end.The Director sets direction for a global team spanning secure development lifecycle, security architecture, threat modeling, vulnerability and exposure management … offensive security, cloud security, security monitoring, and incident management. The role translates cyber risk into business risk and drives the conversation leadership can act on.Strong experience across both Product Security and SecOps is required. This is a leader-coach role in a lean, high-ownership team operating ...

SOC Analyst

Location
Farnborough, England, United Kingdom
security alerts, intrusions, or unauthorised, unexpected, or illegal activity Respond to incidents using a catalogue of playbooks Escalate complex incidents to Tier 2 Incident Response Teams Review and develop security controls in line with the evolving technical environment Triage and review vulnerability scanning reports and feed results back … threats and trends Research and develop understanding of security as a discipline Requirements Previous experience in Security, SOC or related technical field Focus on Incident Management Focus on Vulnerability Management Relevant qualification(s) in Cyber Security, or other related technical roles Knowledge of key concepts of Cloud Computing Knowledge ...

SOC Shift Lead

Hiring Organisation
Searchability NS&D
Location
Hemel Hempstead, England, United Kingdom
busy Security Operations Centre while remaining hands-on with technical investigations. You will act as the senior escalation point during your shift, leading incident response, mentoring analysts and ensuring high standards across investigations. You will also: Lead Major Incident investigations and technical response activities Analyse advanced … Lead Strong experience leading complex cyber security investigations Commercial experience with Microsoft Sentinel and Splunk Enterprise Security Excellent understanding of MITRE ATT and CK, incident response and threat-informed defence Strong networking knowledge including TCP/IP, DNS, HTTP/S, SMTP, LDAP and VPN technologies Experience analysing ...

Performance & Observability Engineer

Location
Greater London, England, United Kingdom
infrastructure, and networking. Implement Service Level Indicators (SLIs), Service Level Objectives (SLOs), and Error Budgets to track system health. Automate root cause analysis and incident detection through advanced monitoring techniques. Incident Response & Reliability Engineering Reduce Mean Time to Detect (MTTD) and Mean Time to Resolve (MTTR) through … improved observability. Integrate monitoring and alerting tools with incident response platforms (ie: ServiceNow). Develop self-healing and auto-remediation mechanisms to reduce operational toil. Improve alerting strategies by reducing false positives and improving signal-to-noise ratio. Governance, Compliance & Reporting Define observability best practices and governance models ...

Senior Backend Engineer (Go), Tenant Scale: Gitaly

Hiring Organisation
GitLab
Location
United Kingdom
Salary
£ 70 K
functional outcomes.Improve engineering practices through mentoring, documentation, knowledge sharing, design reviews, and constructive code reviews.Take operational ownership of the systems you work on, including incident response, post-incident improvements, capacity and performance analysis, and customer escalations.Identify opportunities to improve work beyond an individual change through automation, reusable … explain complex technical concepts and make trade-offs clear.Professional experience with Go or another backend or systems language.Experience operating production systems, participating in incident response, and turning operational learnings into durable improvements.Experience with Ruby, Git internals, gRPC, or Git server infrastructure is highly desirable.About the teamThe Gitaly team ...

Information Security Analyst - SecOps Response

Location
Cardiff, Wales, United Kingdom
asking that you attend the office a minimum of 1 day per week. About the Role We’re seeking a passionate and skilled Incident Responder to join our growing Security Operations team, and proactively defend Starling’s customers, assets, and systems against emerging threats. This role will be supporting …/7 operational capabilities (On-call rota). Reporting to the Information Security Lead - SecOps Response, the analyst’s main responsibilities include: Conducting incident response activities to investigate and contain cyber security incidents Developing and maintaining incident response and readiness processes Analyse logs from ...

Information Security Analyst - SecOps Response

Location
Manchester, England, United Kingdom
asking that you attend the office a minimum of 1 day per week. About the Role We’re seeking a passionate and skilled Incident Responder to join our growing Security Operations team, and proactively defend Starling’s customers, assets, and systems against emerging threats. This role will be supporting …/7 operational capabilities (On-call rota). Reporting to the Information Security Lead - SecOps Response, the analyst’s main responsibilities include: Conducting incident response activities to investigate and contain cyber security incidents Developing and maintaining incident response and readiness processes Analyse logs from ...

Information Security Analyst - SecOps Response

Location
Southampton, England, United Kingdom
asking that you attend the office a minimum of 1 day per week. About the Role We’re seeking a passionate and skilled Incident Responder to join our growing Security Operations team, and proactively defend Starling’s customers, assets, and systems against emerging threats. This role will be supporting …/7 operational capabilities (On-call rota). Reporting to the Information Security Lead - SecOps Response, the analyst’s main responsibilities include: Conducting incident response activities to investigate and contain cyber security incidents Developing and maintaining incident response and readiness processes Analyse logs from ...

Information Security Analyst - SecOps Response

Location
Greater London, England, United Kingdom
asking that you attend the office a minimum of 1 day per week. About the Role We’re seeking a passionate and skilled Incident Responder to join our growing Security Operations team, and proactively defend Starling’s customers, assets, and systems against emerging threats. This role will be supporting …/7 operational capabilities (On-call rota). Reporting to the Information Security Lead - SecOps Response, the analyst’s main responsibilities include: Conducting incident response activities to investigate and contain cyber security incidents Developing and maintaining incident response and readiness processes Analyse logs from ...

Cyber Security Manager

Location
Greater London, England, United Kingdom
honestly where the monitoring gaps are, and close them. From there you work with the team to design and build the agentic detection and response capability, validated against attacks from our own internal red team. You will run operations by hand while that is being built, and you will … this is the right role. If you want a mature toolchain and a large team to inherit, it is not. Key Responsibilities Detection and incident response Own alert triage, investigation and response end to end, be the named person who declares an incident, runs ...

SecOps Engineer

Location
Manchester, England, United Kingdom
infrastructure, identity platforms, cloud services, and business systems. Configure, maintain, and optimise security technologies to safeguard hybrid environments, enabling proactive threat detection and resilient incident response through close collaboration with infrastructure, operations, and cloud teams. Coordinate vulnerability management activities across endpoints, servers, cloud services, and network infrastructure, including … high-risk vulnerabilities Contribute to the evolution of automated security operations and threat detection workflows, using scripting and orchestration tools to enhance efficiency and response capabilities over time, in collaboration with infrastructure and operations teams. Maintain and enforce information security policies, procedures, and standards in alignment with regulatory frameworks ...

Sr. Analyst, Falcon Complete (Remote, GBR)

Hiring Organisation
CrowdStrike
Location
United Kingdom
Salary
£ 70 K
opportunity to rapidly accelerate your skills Do you crave new and innovative work that actually matters to your customer Do you have an Incident Response or Information Security background that you’re not fully utilizing Are you capable of leading teams and interacting well with customers … learn from and mentor on a daily basis What You'll Do:Conduct monitoring and perform in-depth analysis of security alerts.Exercise incident handling processes across Windows, Mac, and Linux platforms.Perform malware analysis.Perform remote remediation of malware or malicious activity.Develop and improve processes for incident detection, triage ...

Information Security Analyst - SecOps Response

Hiring Organisation
Starling Bank
Location
London, United Kingdom
Salary
£ 80 K
Technology, we're asking that you attend the office a minimum of 1 day per week.About the RoleWe’re seeking a passionate and skilled Incident Responder to join our growing Security Operations team, and proactively defend Starling’s customers, assets, and systems against emerging threats. This role will … supporting our 24/7 operational capabilities (On-call rota).Reporting to the Information Security Lead - SecOps Response, the analyst’s main responsibilities include:Conducting incident response activities to investigate and contain cyber security incidentsDeveloping and maintaining incident response and readiness processesAnalyse logs from ...

Senior SOC Analyst - DV Clearance

Hiring Organisation
Salt Search
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£70,000 - £100,000 per annum
security cyber defence team supporting critical national infrastructure and sensitive government programmes. This role requires a proactive security professional with strong monitoring, analysis, and incident triage capabilities within a Security Operations Centre environment. SOC Analyst - Key Responsibilities Monitor and analyse security alerts from SIEM and security tooling platforms Perform … triage and investigation of security events and potential incidents Conduct threat hunting and identify indicators of compromise Escalate and coordinate incident response activities where required Analyse endpoint, network, and cloud security telemetry Develop and improve detection rules and use cases Produce detailed investigation and incident reports Collaborate ...

Senior Cyber Analyst

Hiring Organisation
Methods Consulting
Location
London, United Kingdom
Salary
£ 100 K
your unique needs. We help organisations improve processes such as threat management by building an identity management programme, and establishing prevention, detection and response capabilities to cyber-attacks. Role SummaryThe Senior Cyber Analyst is the senior technical lead within the Cyber Services function, responsible for complex cyber investigations, incident response, threat detection, and security platform optimisation. Acting as the highest technical escalation point within cyber operations, the role provides leadership, mentoring, and strategic direction to ensure customers maintain a strong and resilient security posture.RequirementsIncident Response & Threat ManagementLead the investigation and resolution of complex cyber security incidents ...