26 to 50 of 326 Incident Response Jobs in the UK

Cyber Security Engineer

Hiring Organisation
Anson Mccade
Location
Manchester, North West, United Kingdom
Employment Type
Permanent
Salary
£75,000
operations. This is a technical role suited to an experienced analyst with strong engineering instincts, hands-on coding capabilities, and a deep understanding of incident response, detection engineering, and adversary tradecraft. This position includes approximately one week per month of on-call availability for high-priority incident … ideal for someone who has likely grown from an engineering background and can write scripts (Python, Bash) to automate, enhance, and refine detection and response workflows. Experience with Splunk, SIEM operations, cloud endpoints, networks, and detection engineering will be highly advantageous. NOTE: Candidates for this role must be eligible ...

Cyber Security Engineer

Hiring Organisation
Anson Mccade
Location
Birmingham, West Midlands, United Kingdom
Employment Type
Permanent
Salary
£75,000
operations. This is a technical role suited to an experienced analyst with strong engineering instincts, hands-on coding capabilities, and a deep understanding of incident response, detection engineering, and adversary tradecraft. This position includes approximately one week per month of on-call availability for high-priority incident … ideal for someone who has likely grown from an engineering background and can write scripts (Python, Bash) to automate, enhance, and refine detection and response workflows. Experience with Splunk, SIEM operations, cloud endpoints, networks, and detection engineering will be highly advantageous. NOTE: Candidates for this role must be eligible ...

Cyber Security Engineer

Hiring Organisation
Anson Mccade
Location
Leeds, West Yorkshire, Yorkshire, United Kingdom
Employment Type
Permanent
Salary
£75,000
operations. This is a technical role suited to an experienced analyst with strong engineering instincts, hands-on coding capabilities, and a deep understanding of incident response, detection engineering, and adversary tradecraft. This position includes approximately one week per month of on-call availability for high-priority incident … ideal for someone who has likely grown from an engineering background and can write scripts (Python, Bash) to automate, enhance, and refine detection and response workflows. Experience with Splunk, SIEM operations, cloud endpoints, networks, and detection engineering will be highly advantageous. NOTE: Candidates for this role must be eligible ...

Cyber Security Engineer

Hiring Organisation
Anson Mccade
Location
Bristol, Avon, South West, United Kingdom
Employment Type
Permanent
Salary
£75,000
operations. This is a technical role suited to an experienced analyst with strong engineering instincts, hands-on coding capabilities, and a deep understanding of incident response, detection engineering, and adversary tradecraft. This position includes approximately one week per month of on-call availability for high-priority incident … ideal for someone who has likely grown from an engineering background and can write scripts (Python, Bash) to automate, enhance, and refine detection and response workflows. Experience with Splunk, SIEM operations, cloud endpoints, networks, and detection engineering will be highly advantageous. NOTE: Candidates for this role must be eligible ...

Cyber Security Engineer

Hiring Organisation
Foresters Financial
Location
Kent, South East, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£60,000
environment and you will have on-going opportunities to develop your technical skills and grow within cyber security What you will do: Security Monitoring & Incident Response Actively monitor alerts and telemetry across endpoints, identities, email, and cloud services using Rapid7 SIEM, Microsoft Defender, and Sophos AV. Investigate suspected … malware infections, phishing campaigns, identity compromise, and unauthorised access attempts. Perform triage, root cause analysis, containment, and remediation of security incidents. Lead or support incident response activities in line with internal policies and procedures. Escalate significant incidents appropriately and provide clear, timely updates to stakeholders. Threat Detection & Prevention ...

Cyber Security Analyst

Hiring Organisation
Holt Executive
Location
London, United Kingdom
Employment Type
Permanent
team. This is an excellent opportunity to join a fast-paced cybersecurity environment, helping to protect critical infrastructure and enterprise systems through proactive monitoring, incident response, and threat analysis. Working as part of a 24/7 operational security function, you will play a key role in identifying … monitoring tools, network infrastructure, and endpoint technologies. Investigate and triage security alerts to identify malicious activity and determine attack methods and techniques. Follow established incident response and escalation procedures to contain and mitigate security risks. Ensure all incidents are accurately documented, including indicators of compromise, evidence, and investigation ...

Senior Security Platform Engineer

Hiring Organisation
NTT Global Data Centers EMEA UK ltd
Location
Hemel Hempstead, Hertfordshire, South East, United Kingdom
Employment Type
Permanent
tasks specialized at threat hunting, SIEM/SOAR, Network Security and other operational security tasks such as performance and availability monitoring, log monitoring, security incident detection and response, security event reporting, and content maintenance (tuning). What we are looking for Key Responsibilities: Serves as a senior member … optimization of enterprise security platforms, overseeing lifecycle management including break-fix, patching, version upgrades, and integration with broader security ecosystems. Directs complex security incident response efforts across multiple vectorsendpoint protection, EDR, malware analysis, network and computer forensicsensuring rapid containment and root cause analysis. Designs and executes advanced vulnerability ...

Cyber Incident Response Manager

Hiring Organisation
Ashdown Group
Location
City, London, United Kingdom
Employment Type
Permanent
Salary
GBP 100,000 Annual
Incident Response Manager (Cyber Threat) - Global financial services company - Full time permanent role - Salary up to £110,000 plus bonus. Hybrid working (twice a week in the London office) A large global financial services firm is looking for an Incident Response Manager within its cyber threat ...

Security Lead

Hiring Organisation
Method-Resourcing
Location
Maidenhead, Berkshire, South East, United Kingdom
Employment Type
Contract, Work From Home
Contract Rate
Up to £500 per day
improvement Lead security engagement within client Design Authority and Enterprise Architecture forums Manage integration with the client SOC, including security reporting, SIEM alignment, and incident response coordination Oversee security incident management in line with the client Cyber Security Incident Response Plan Own joiner/mover … Strong understanding of NCSC HMG IAS5, Cyber Assessment Framework (CAF), ISO 27001, and GDPR Hands-on experience integrating with a UK Government SOC, including incident response and security reporting Strong working knowledge of Oracle Cloud security (OCI IAM, Vault, network security, audit, PAM) Experience securing Oracle SaaS applications ...

Cyber Security Analyst

Hiring Organisation
Hays Technology
Location
Newport, Gwent, United Kingdom
Employment Type
Permanent
Salary
£42000 - £48000/annum £42k - £48k
will require knowledge and understanding of attack and exploitation techniques and adversarial TTP's. Help to provide resilience to our threat monitoring and response capabilities. Handle security incident response with internal teams and other third parties to ensure that the incident response life cycle … Good knowledge and understanding of SOC processes and procedures. Basic experience using SIEM systems such as MS Sentinel, LogRhythm, AlienVault, Splunk Good understanding of incident response stages and handling. Basic knowledge and experience using leading endpoint detection and threat management products and managing their operation. Good knowledge ...

Cyber Security Engineer

Hiring Organisation
Job Board Direct
Location
Omagh, County Tyrone, Northern Ireland, United Kingdom
Employment Type
Permanent, Work From Home
This position offers an exciting opportunity to work in a fast-paced environment, handling cutting-edge technology and complex challenges in cybersecurity. Key Responsibilities: Incident Response (IR): Investigate and respond to security incidents, ensuring rapid containment, eradication, and recovery. Conduct root cause analysis of security breaches and create … detailed incident reports. Collaborate with stakeholders to refine and enhance the incident response plan and playbooks. Security Operations Center (SOC): Monitor and analyse security alerts and logs from various tools such as SIEM, IDS/IPS, and endpoint detection systems. Identify and escalate potential security threats ...

Tech lead - SOC responder

Hiring Organisation
Colt Technology Services UK
Location
London, United Kingdom
Employment Type
Permanent, Work From Home
with global impact upon Colt, business units, partners, and customers. While working as part of this team, the successful individual will provide world class incident response functions to detect, protect, respond, and sustain operations within cyberspace. This role operates at a Tier 3 level , with the expectation that … operational activities, Technology escalation support, Security Solution assessment, existing Service maturing and Build activities assist Analyse potential infrastructure security incidents to determine if incident qualifies as a legitimate security breach Establishing and governing the security incident response processes, investigations and security operational processes Maintenance and enhancement ...

Cyber Security Operations Manager

Hiring Organisation
Infosec
Location
Bournemouth, Dorset, South West, United Kingdom
Employment Type
Permanent
Salary
£80,000
strengthening and evolving their cyber defence capability. This is a high-impact leadership role where you'll own security operations end-to-end , lead incident response, and work closely with the CISO to drive continuous improvement across a mature but evolving cyber function. What you'll be doing … Leading and developing a Cyber Security Operations team Acting as incident commander during cyber events and investigations Maturing SOC, CSIRT and incident response capabilities Driving threat hunting, detection and monitoring improvements Owning vulnerability management and pen test governance Ensuring alignment with ISO27001, NIST, GDPR and regulatory expectations ...

Incident Manager

Hiring Organisation
Falcon Smart IT (FalconSmartIT)
Location
London Area, United Kingdom
Title: Incident Manager Job Location: Central London, UK/Onsite Job Type: FTE Job Description: Role Summary The Incident Manager owns end-to-end incident response for critical insurance systems and services, focusing on minimizing customer and business impact across all platforms. This role leads major … incident handling, coordinates cross-functional and vendor teams, ensures regulatory and audit readiness, and drives continuous improvement to reduce recurrence and improve resilience. Key Responsibilities 1. Lead major incident response and coordination across application teams, infrastructure, security, vendor partners, and business stakeholders to restore services quickly. 2. ...

Cyber Operations & Incident Response Manager

Hiring Organisation
Prime Personnel
Location
London, United Kingdom
Employment Type
Permanent
Salary
GBP 100,000 Annual
Global SME financial seeks a Cyber Operations and Incident Response Manager to lead and line-manage London-based cyber security team (x3/x4), assure the local delivery of globally-prioritised work, and act as Incident Commander and first point of escalation for cyber security in London. … role additionally leads the Endpoint, Platform and Incident Response capability, owning the global prioritis click apply for full job details ...

Senior SOC Analyst - DV Cleared

Hiring Organisation
CBSbutler Holdings Limited trading as CBSbutler
Location
Portsmouth, Hampshire, United Kingdom
Employment Type
Contract
Contract Rate
£590 - £630/day
Cyber Security Operations Centre supporting critical national security environments. This is an opportunity to work at the forefront of cyber defence, leading threat detection, incident response, vulnerability management, and continuous improvement of security monitoring capabilities. As a Senior SOC Analyst, you will play a key role in protecting … complex enterprise environments through the management and optimisation of security tooling, threat detection, incident response, and forensic investigations. You will work closely with internal and external stakeholders to enhance SOC capabilities, improve security visibility, and strengthen cyber resilience. Key Responsibilities Maintain and optimise SOC Protect, Detect and Respond ...

Senior SOC Analyst

Hiring Organisation
CBSbutler Holdings Limited trading as CBSbutler
Location
Corsham, Wiltshire, United Kingdom
Employment Type
Contract
Contract Rate
GBP 575 - 650 Daily
Cyber Security Operations Centre supporting critical national security environments. This is an opportunity to work at the forefront of cyber defence, leading threat detection, incident response, vulnerability management, and continuous improvement of security monitoring capabilities. As a Senior SOC Analyst, you will play a key role in protecting … complex enterprise environments through the management and optimisation of security tooling, threat detection, incident response, and forensic investigations. You will work closely with internal and external stakeholders to enhance SOC capabilities, improve security visibility, and strengthen cyber resilience. Key Responsibilities Maintain and optimise SOC Protect, Detect and Respond ...

CSOC Consultant

Hiring Organisation
Experis
Location
Corsham, Wiltshire, South West, United Kingdom
Employment Type
Contract
Contract Rate
£700 - £750 per day + Inside IR35
opportunity to play a key role in protecting critical systems and services, working alongside security, infrastructure, and cloud teams to enhance security monitoring, incident response, threat detection, and operational resilience. The successful candidate will bring a strong background in cyber security operations, ideally gained within Defence, Government … other highly regulated environments. Responsibilities Support the operation and continual improvement of cyber security monitoring and incident response capabilities. Investigate and manage cyber security incidents, ensuring appropriate containment, remediation, and reporting. Analyse security alerts, events, and threat intelligence to identify potential risks and vulnerabilities. Develop and refine detection ...

L3 SOC ENGINEER

Hiring Organisation
Ibex Recruitment LTD
Location
Manchester, Lancashire, United Kingdom
Employment Type
Permanent
Salary
GBP Annual
Analyst/Senior Cyber Security Specialist to join their growing cyber security function. This is an exciting opportunity for someone with strong incident response and threat detection expertise to work in a fast-paced environment protecting critical systems and infrastructure. The Role As a Level 3 SOC Analyst … analysts Conduct proactive threat hunting activities and identify emerging attack patterns Develop and optimise SIEM detection rules, correlation logic, and automation workflows Improve incident response processes, runbooks, and security operations procedures Analyse security alerts and telemetry to identify threats and vulnerabilities Collaborate with technical teams to strengthen cyber ...

Senior Security Engineer

Hiring Organisation
Richmond Square Consulting Limited
Location
Manchester, North West, United Kingdom
Employment Type
Permanent
experience. This is a senior, hands-on role working across firewalling, on-premise and cloud security, secure infrastructure, network security, workload segmentation, hardening, monitoring, incident response and security architecture. The environment is highly secure and regulated, with a strong focus on enterprise firewalling, Elastic/Elasticsearch, VMware-based … Server environments, Active Directory, Group Policy and endpoint configurations Implementing, auditing and remediating against CIS Benchmarks, STIGs and security hardening standards Supporting vulnerability management, incident response, root cause analysis and remediation planning Embedding security into DevSecOps/CI/CD practices, including automated security testing and policy ...

Cyber Security Manager

Hiring Organisation
Ashdown Group
Location
Lincoln, Lincolnshire, East Midlands, United Kingdom
Employment Type
Permanent
Salary
£65,000
across the business. The Role Youll lead day-to-day cyber security operations, working closely with IT and business stakeholders to ensure robust monitoring, incident response, and risk management processes are in place. This is a hands-on role with both operational and strategic elements. Key Responsibilities Overseeing … cyber operations, including threat monitoring and incident response Managing vulnerabilities and supporting remediation activities Supporting the development and delivery of cyber security strategy Collaborating with internal teams and third-party providers Driving awareness, training, and continuous improvement initiatives About You Experience in cyber security operations, SOC, or incident ...

SC Cleared - Cybersecurity Consultant - Remote - 3 Month Rolling Contract

Hiring Organisation
The Huntsmith Limited
Location
London, South East, England, United Kingdom
Employment Type
Contractor
Contract Rate
Salary negotiable
frameworks such as NIST CSF, IEC 62443 and other recognised industry standards. Assess critical network infrastructure, including segmentation, remote access, identity, monitoring, resilience and incident response capabilities. Review OT architecture, asset inventories, data flows, firewall rules, network zones and conduits. Identify security gaps, operational risks, vulnerabilities and control … senior business stakeholders. Produce high-quality client deliverables, including assessment reports, risk registers, maturity scorecards, architecture recommendations and implementation roadmaps. Contribute to OT incident response planning, tabletop exercises, cyber resilience testing and recovery planning. Support pre-sales activity, including solution shaping, proposal input and client presentations where required. ...

OT Security Engineer

Hiring Organisation
Sanderson Recruitment
Location
Bristol, Avon, South West, United Kingdom
Employment Type
Contract
Contract Rate
£500 - £550 per day
system environments. This role sits within a Security Operations function but is heavily engineering focused, combining hands on OT security tooling, detection engineering and incident response to strengthen resilience across critical infrastructure. Key Responsibilities: Act as the OT security engineering SME, supporting both operational and project based activities … equivalent) Develop and refine detection rules, alerting logic and monitoring coverage across OT and IT/OT convergence points Lead technical investigations and incident response for OT-related cyber events Analyse industrial network traffic to identify anomalies, threats and protocol misuse Integrate OT telemetry into SIEM ...

Cyber Security Manager ( Hybrid )

Hiring Organisation
Michael Page Technology
Location
Birmingham, West Midlands, England, United Kingdom
Employment Type
Full-Time
Salary
£70,000 - £75,000 per annum
Cyber Security Manager is responsible for security operations, risk management, incident response, policy development and user awareness. The role will manage external 3rd party and internal virtual resources. Client Details The client is a well-established, multi-site professional services organisation operating at national scale. With a strong … matters, providing clear guidance to leadership and technical teams Lead engagement with a third-party Security Operations Centre (SOC), ensuring effective monitoring, detection and response Oversee incident management, including coordination, post-incident reviews and continuous improvement actions Own and manage key security platforms, including security awareness ...

Cyber Security Engineer

Hiring Organisation
DCV Technologies Limited
Location
Tring, Hertfordshire, South East, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£60,000
network estate (including Cisco Meraki). The role is hands-on and operational, partnering with IT teams to implement security controls, support monitoring and incident response through Sophos MDR, and improve cyber resilience by supporting Disaster Recovery (DR) testing and Business Continuity (BC) readiness. Key Responsibilities Cloud Security … ensure changes follow change control. Enable and review network security logging/alerting (e.g., syslog/SIEM integrations where applicable). Monitoring, Detection & Incident Response (Sophos MDR) Act as the internal technical point of contact for Sophos MDR and ensure smooth collaboration with MDR analysts. Maintain coverage ...