51 to 75 of 2,202 Incident Response Jobs in the UK

Operational Security Manager

Location
Farnborough, England, United Kingdom
will join a growing team of security professionals to protect and maintain the effectiveness of managed service capabilities. The Operational Security Manager supports cybersecurity incident response, investigation, escalation, and regulatory reporting, with a focus on the EU Cyber Resilience Act. Working across Cybersecurity, Product Security, Legal, Compliance, Privacy … Security Manager also provides technical leadership and continuously improves security processes, controls, and supporting technologies. What You'll Be Doing : Support the full cybersecurity incident response lifecycle, including triage, investigation, containment, escalation, remediation, recovery, and post-incident review across enterprise and product environments. Coordinate incident response ...

Lead Security Operations Engineer

Location
Greater London, England, United Kingdom
Define and deliver Pleo's SecOps roadmap for detection, response, and investigation capabilities Build a structured roadmap based on MITRE ATT&CK, NIST, and CIS benchmarks Lead security investigations and digital forensics through incident response Design, tune, and scale SIEM and standardized logging pipelines Strengthen perimeter … configuration, authorization tuning, and suspicious-traffic monitoring Implement DLP controls aligned with sensitive-data locations Improve the on-call rotation, alerting, escalation paths, and response SLAs Automate detection and response workflows using code and AI Reduce SecOps-attributed compliance risk and collect supporting evidence Build dashboards and reporting ...

Security Engineer, Detection and Response

Location
Greater London, England, United Kingdom
specific threats including prompt injection, model extraction, data poisoning, adversarial examples, and unauthorized access to training datasets or model weights Build automated response playbooks and orchestration workflows to contain threats and remediate compromised inference endpoints Lead security incident response coordination across Cloud, AppSec, Enterprise, and AI Security … teams Conduct forensic investigations into training pipeline attacks and model manipulation attempts Draft incident communications for engineering and executive leadership Proactively hunt sophisticated threats across GPU clusters and training infrastructure Analyze model outputs for signs of compromise and reproduce AI-specific vulnerabilities Identify visibility gaps in distributed training environments ...

Senior Incident Response Consultant, Mandiant (Weekend team)

Location
United Kingdom
Senior Incident Response Consultant, Mandiant (Weekend team) Mid Experience driving progress, solving problems, and mentoring more junior team members; deeper expertise and applied knowledge within relevant area. This role follows a weekend schedule covering 10-hour daily shifts from Friday through Monday. Remote location: United Kingdom. Bachelor … investigative experience with network forensics, malware triage analysis, cloud forensics, or disk and memory forensics. 5 years of experience working end-to-end incident response investigations, analysis, or containment actions. Experience in Linux or Unix. Ability to travel up to 30% of the time. Preferred qualifications: Certifications ...

Principal Consultant, Incident Response (Unit 42)

Hiring Organisation
Palo Alto Networks
Location
London, United Kingdom
Salary
£ 80 K
will lead and produce deliverables for reactive services engagements. You will work directly with a variety of customers and key stakeholders to manage incident response engagements from start to finish, providing expert guidance on immediate containment and long-term remediation to enhance their security posture.Key ResponsibilitiesManage and lead … incident response engagements, including scoping work, guiding clients through forensic investigations, and containing security incidents.Perform reactive incident response and host-based analysis on Windows, Linux, and Mac OS X systems to identify Indicators of Compromise (IOCs).Examine firewall, web, database, and other log sources to identify ...

SOC Team Lead

Location
Greater London, England, United Kingdom
Drive performance and operational excellence across Shared Service’s Cyber Services function Act as a technical escalation point and line manager Support threat analysis, incident response, and security assurance activities Foster a proactive culture of cyber hygiene and continuous improvement Collaborate across departments to strengthen Shared Service … security posture Deputise for the Service Desk Manager during high workload or absence periods Lead cyber service operations focused on SLA attainment, incident response, and resolution quality Oversee daily workflow distribution and prioritise emerging threats and investigative escalations Ensure complex or unresolved cybersecurity issues are escalated appropriately Line ...

Senior DFIR Investigator

Location
City Of London, England, United Kingdom
build resilience against cyber threats. We're seeking a Senior DFIR Investigator to join our Global Security Services team. Working at the forefront of incident response, you'll lead complex investigations for organisations around the world, helping clients understand what happened, contain threats and recover with confidence. This … actor activity, attack techniques, malware and potential data exposure. Produce high‐quality forensic reports, attack timelines and actionable recommendations for clients. Deploy and utilise incident response tooling to collect, preserve and analyse forensic evidence. Provide trusted technical guidance to clients throughout the incident response lifecycle. Work ...

Senior Cyber Security Engineer

Hiring Organisation
Comtecs
Location
City of London, London, United Kingdom
Employment Type
Permanent
Cyber Security Specialist/Cyber Security Engineer - CISSP, CEH, CCNA Security, Incident Response, Threat Monitoring, Vulnerability Management, Security Architecture, Azure, Windows Server Infrastructure. Permanent. London Hybrid. c.£90k - £100k + Bons +Benefits Global Law Firm seeks an experienced IT Cyber Security Specialist to join its Infrastructure Engineering team … identify vulnerabilities, respond to incidents and strengthen the firm's overall security posture. This is a hands-on technical role covering Cyber Security Engineering, Incident Response, Threat Monitoring, Vulnerability Management and Security Architecture (Infrastructure focussed) using tools such as MS Defender and MS Sentinel. You'll work across ...

Cyber Security Engineer - MS Sentinel, Defender, SSO, PKI, SC-100/200, CISSP

Hiring Organisation
Comtecs Ltd
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£90,000 - £100,000 per annum
Cyber Security Specialist/Cyber Security Engineer - CISSP, CEH, CCNA Security, Incident Response, Threat Monitoring, Vulnerability Management, Security Architecture, Azure, Windows Server Infrastructure. Permanent. London Hybrid. c.£90k - £100k + Bons +Benefits Global Law Firm seeks an experienced IT Cyber Security Specialist to join its Infrastructure Engineering team … identify vulnerabilities, respond to incidents and strengthen the firm's overall security posture. This is a hands-on technical role covering Cyber Security Engineering, Incident Response, Threat Monitoring, Vulnerability Management and Security Architecture (Infrastructure focussed) using tools such as MS Defender and MS Sentinel. You'll work across ...

Embedded Cyber Detection and Response Deputy Team Lead

Hiring Organisation
Control Risks
Location
London, United Kingdom
Salary
£ 80 K
DescriptionThe Cyber Detection and Response Deputy Team Lead serves as the operational second-in-command of the Cyber Detection and Response Team (DART), bridging the gap between hands-on cyber operations and team leadership. The role supports the Team Lead in the ongoing development, maturation, and delivery … client's detection and response capabilities, while providing technical leadership and operational oversight across day-to-day security operations.This position remains actively involved in threat detection, incident response, threat hunting, and detection engineering activities while also assuming supervisory and coordination responsibilities. The Deputy Team Lead acts ...

NMC Cyber Incident Responder (Digital Forensics)

Location
United Kingdom
Join Police Digital Service as NMC Cyber Incident Responder (Digital Forensics) Salary starting at £55,000 pa + 10% shift allowance As a member of the National Management Centre (NMC) Cyber Incident Response team, you will lead and support the investigation of cyber security incidents affecting … policing. This role combines digital forensics, incident response and stakeholder engagement, requiring the ability to identify, contain and investigate sophisticated cyber threats across diverse technology estates. You will conduct forensic examinations of compromised systems, analyse host, network and memory-based evidence, and support the collection and preservation ...

NMC Cyber Incident Responder (Digital Forensics)

Hiring Organisation
Police Digital Services
Location
Wigan, Greater Manchester, North West, United Kingdom
Employment Type
Permanent, Work From Home
Join Police Digital Service as NMC Cyber Incident Responder (Digital Forensics) Salary starting at £55,000 pa + 10% shift allowance As a member of the National Management Centre (NMC) Cyber Incident Response team, you will lead and support the investigation of cyber security incidents affecting … policing. This role combines digital forensics, incident response and stakeholder engagement, requiring the ability to identify, contain and investigate sophisticated cyber threats across diverse technology estates. You will conduct forensic examinations of compromised systems, analyse host, network and memory-based evidence, and support the collection and preservation ...

Privacy Operations Manager

Hiring Organisation
Thomson Reuters
Location
London, United Kingdom
Salary
£ 70 K
sectoral (HIPAA, GLBA, FedRamp, CJIS, etc.) privacy regulation, and other applicable data protection laws. This role will also manage the operational aspects of cyber incident management, coordinate incident response activities and ensuring effective execution of the organization's cyber incident response processes. The ideal candidate … CCPA, PIPEDA, among othersBuild out and maintain data inventory, and data mapping initiativesIdentify privacy risks and work with stakeholders to implement mitigation strategiesSupport privacy incident response and breach notification processesConduct privacy audits and assessments of internal processes and third-party vendorsCyber Incident ManagementSupport ...

Senior Cyber Security Analyst

Hiring Organisation
Anson Mccade
Location
Central London, London, United Kingdom
Employment Type
Permanent
Blue Team within a dynamic Cyber Practice. This senior role offers the chance to work on high-profile client engagements, delivering threat detection, monitoring, incident response, and security operations expertise. The role is ideal for a self-motivated professional with strong technical skills, inquisitive thinking, and a passion … protecting enterprise systems from evolving cyber threats. The Role The Cyber Security Operations Specialist will use advanced tools and threat intelligence to ensure effective incident detection and response across client environments. Working closely with security analysts and wider teams, the role combines detection engineering, monitoring, incident response ...

Senior Security and Cyber Operations Manager

Hiring Organisation
McCabe & Barton
Location
City of London, London, United Kingdom
Employment Type
Permanent
Financial Services organisation is looking for a Senior Security and Cyber Operations Manager to take ownership of its security operations, cyber defence, monitoring and incident response capabilities. This is a senior, hands-on role within the CISO function, responsible for strengthening the organisations cyber defence capability and ensuring … very flexible working. You will work closely with Technology, Cloud, Data, Architecture, Risk and external security partners, with responsibility for security tooling, detection coverage, incident response, operational cyber risk and service performance. Key Responsibilities Own and continually improve the organisations security operations and cyber defence capability Lead security ...

Security Engineer, Incident Response

Hiring Organisation
Twilio
Location
United Kingdom
Salary
£ 70 K
basis for team gatherings, functional off-sites or customer meetings. .See yourself at TwilioJoin the team as Twilio’s next Security Engineer, Incident ResponseAbout the jobThe Security Incident Response Team (SIRT) is looking for a Security Engineer who is passionate about solving Twilio’s mission of security … reliability by working across the organization to lead the technical response to security events and incidents across Twilio’s global infrastructure, services and applications by effectively conducting triage, containment, remediation and driving post-incident betterments. You will work within a team that partners with R&D Engineering ...

Enterprise Incident Manager Senior

Location
Gateshead, England, United Kingdom
Ready to take your career globally? Make your mark at one of the biggest names in payments. We’re looking for a Enterprise Incident Manager Senior to join our ever-evolving team and help support delivery that shapes the future of global commerce. Ready to take your career globally … Make your mark at one of the biggest names in payments. We’re looking for a Enterprise Incident Manager Senior to join our ever-evolving team and help support delivery that shapes the future of global commerce. What you’ll own Enterprise Incident Leadership Lead the Enterprise Incident ...

Senior Security Consultant (Incident Response)

Location
Birmingham, England, United Kingdom
Select how often (in days) to receive an alert: Create Alert Senior Security Consultant (Incident Response) Job ID:44293 Location:UK : Home Based Position Category:Consulting Position Type:Employee Regular Senior Security Consultant Role Purpose: This is a new, exciting opportunity for a Senior Security Consultant to join … LRQA’s existing dynamic Cyber Incident Response Team. This role follows a hybrid working arrangement and will involve working on client sites and from the office from time to time. We support remote work across the UK; however, the main office is in Birmingham. Applicants are required ...

Cyber Defence Senior Analyst

Location
Belfast, County Antrim, United Kingdom
based in Belfast. They will perform a critical role in solidifying the firm's security posture, focusing on the in-depth analysis, and effective response to cyber security events and incidents within their time-zone. They will also contribute to the effectiveness and cohesion of the Cyber Defence team … firm’s Managed Security Service Provider (MSSP) to identify potential incidents. Assist and advise junior colleagues during investigations where additional experience is required. Incident Response: Conduct initial triage and investigation of confirmed incidents. Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence ...

Cyber Defence Senior Analyst

Hiring Organisation
A&O Shearman
Location
Downpatrick, County Down, United Kingdom
Employment Type
Permanent
Salary
GBP Annual
based in Belfast. They will perform a critical role in solidifying the firm's security posture, focusing on the in-depth analysis, and effective response to cyber security events and incidents within their time-zone. They will also contribute to the effectiveness and cohesion of the Cyber Defence team … firm's Managed Security Service Provider (MSSP) to identify potential incidents. Assist and advise junior colleagues during investigations where additional experience is required. Incident Response: Conduct initial triage and investigation of confirmed incidents. Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence ...

Senior Cyber Security Analyst

Hiring Organisation
Tria Recruitment
Location
London, United Kingdom
Salary
£ 80 K
individual capable of leading cyber incidents operationally, technically and commercially from end-to-end.You will act as a senior technical subject matter expert across incident response, detection engineering, cloud security and vulnerability management, while also providing calm, structured leadership during high-pressure situations.The environment is heavily Microsoft-focused … secure-by-design principlesDetection engineering and automationThreat and vulnerability managementYou will work closely with global technology and cyber teams to continuously improve monitoring, detection, response and remediation capabilities across hybrid cloud and on-premise environments.Key ResponsibilitiesIncident Response & Major Incident ManagementLead the end-to-end management of cyber ...

Director, Cyber Defense

Hiring Organisation
Kyndryl
Location
London, United Kingdom
Salary
£ 120 K
defense mission across a globally distributed security organization. This role reports to the Vice President and Deputy CISO, Cyber Operations.You will own the full incident response lifecycle, run follow-the-sun security operations across AMER, EMEA, and APAC, direct the cyber threat intelligence program, and drive the conversion … Lead 24/7 global security operations through a follow-the-sun model spanning AMER, EMEA, and APAC regions.Own the full incident response lifecycle, triage through post-incident review, with forensic preservation standards maintained throughout.Coordinate with the Incident Commander function with clear escalation authorities, runbooks ...

Principal Cyber Security Operations Analyst

Location
City Of London, England, United Kingdom
will join us on our journey and undertake a highly influential role responsible for strengthening and enhancing Post Office's cyber detection, investigation and response capabilities. You will work collaboratively with technology teams, business stakeholders and security specialists across the organisation, providing technical leadership, supporting strategic cyber security objectives … driving operational excellence across our Cyber Detect and Response function. This role offers a unique opportunity to make a tangible impact by protecting a complex and nationally significant organisation, helping to improve cyber resilience, reduce operational risk and safeguard services relied upon by Postmasters, customers, colleagues and communities across ...

Senior Specialist Engineer - Networks

Hiring Organisation
National Health Service
Location
London, United Kingdom
Salary
£ 70 K
configured, resilient, secure, and performant. Beyond day-to-day operational responsibilities, the role carries explicit accountability for network architecture, strategic design, and cross-functional incident response.This role also attracts a market pay supplement of 6650 per annum (to be reviewed in February 2027).Main duties of the jobOwn … teams.Manage routing, switching, wireless, WAN, load balancing, IPAM, DNS and DHCP services, alongside Extreme Networks Fabric Engine, Site Engine and wireless platforms.Network Security, Resilience & Incident ManagementProvide technical leadership for network security and operational resilience across the UKHSA estate.Administer Palo Alto NGFW, Panorama, VPN, micro-segmentation, DMZ and Zero Trust ...

Senior Specialist Engineer - Networks

Hiring Organisation
National Health Service
Location
Liverpool, Merseyside, United Kingdom
Salary
£ 60 K
configured, resilient, secure, and performant. Beyond day-to-day operational responsibilities, the role carries explicit accountability for network architecture, strategic design, and cross-functional incident response.This role also attracts a market pay supplement of 6650 per annum (to be reviewed in February 2027).Main duties of the jobOwn … teams.Manage routing, switching, wireless, WAN, load balancing, IPAM, DNS and DHCP services, alongside Extreme Networks Fabric Engine, Site Engine and wireless platforms.Network Security, Resilience & Incident ManagementProvide technical leadership for network security and operational resilience across the UKHSA estate.Administer Palo Alto NGFW, Panorama, VPN, micro-segmentation, DMZ and Zero Trust ...