1 to 25 of 323 Incident Response Jobs in the UK excluding London

Director, Digital Forensics & Incident Response (Global)

Hiring Organisation
Jobleads-UK
Location
Manchester, England, United Kingdom
Director, Digital Forensics & Incident Response (Global) Department: Cyber Services and Capabilities Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Reporting To: Matt Hull (Open to Associate Director with progression path to Director) Description The purpose of this role is to lead NCC Group’s global Digital Forensics … Incident Response (DFIR) capability, ensuring effective preparedness, response, recovery, and continuous improvement across cyber incident management and forensic investigations. The global DFIR team will consist of regionally distributed colleagues, delivering a consistent, scalable, and market-leading service that protects client assets, reputation, and business operations. ...

Security Incident Response Engineer (ServiceNow)

Hiring Organisation
INTEC SELECT LIMITED
Location
Warrington, Cheshire, England, United Kingdom
Employment Type
Contractor
Contract Rate
£100.00 per hour
Security Incident Response Engineer (ServiceNow) Contract: 6 Months (Likely Extension)Location: HybridIR35: Outside/LTD – £700PDSC Cleared/BPSSA highly reputable corporation is hiring an experienced ServiceNow Security Incident Response (SIR) Consultant to support the design, implementation and optimisation of a Security Incident Response capability for a Cyber Security Operations Centre (CSOC).This is an excellent opportunity to play a key role in enhancing cyber incident management processes, automating security workflows and integrating ServiceNow Security Operations with wider security tooling. Key Responsibilities ServiceNow SIR Workflow Design & Development Design and configure ...

Incident Response (CSIRT) / SOC Level 3 Analyst

Hiring Organisation
Morson Edge
Location
Hampshire, South East, United Kingdom
Employment Type
Contract
Incident Response (CSIRT)/SOC Level 3 Analyst - Outside IR35 Location: Crawley (2-3 days onsite) Contract: 6 Months Outside IR35 We are looking for an experienced Incident Response (CSIRT)/SOC Level 3 Analyst to join a high-performing cyber security operations team … initial 6-month contract. This is an excellent opportunity for a senior cyber security professional with strong incident response, threat hunting, and SOC expertise to play a critical role in protecting enterprise IT and operational environments from advanced cyber threats. You will work closely with cyber security operations ...

Cyber Incident Response Manager

Hiring Organisation
Hays
Location
Liverpool, Merseyside, North West, United Kingdom
Employment Type
Contract
Contract Rate
£750.0 - £800 per day
IR35 Status: Outside IR35 Contract Length: 6 months initially Location: Hybrid - Liverpool Overview I'm supporting an organisation seeking an experienced Incident Response Manager to lead and mature its Incident Response capability across a complex enterprise environment. Responsibilities Own and manage cyber incidents from detection through … resolution. Review, enhance, and develop Incident Response frameworks, runbooks, and playbooks. Ensure alerts from SIEM, EDR, CTI, and SOC services are effectively integrated into Incident Response processes. Lead tabletop exercises and testing activities. Work closely with SOC, Threat Intelligence, Technology, and Business teams. Drive continual improvement ...

Security Incident Response Engineer

Hiring Organisation
NonStop Consulting
Location
Warrington, Cheshire, United Kingdom
Employment Type
Contract
Contract Rate
£100/hour
Details at a Glance Role: Security Incident Response Engineer Location: Warrington - hybrid, typically 2 days per week on site Contract length: 6 months (with strong potential for extension based on performance and project needs) IR35 status: Out of Scope Rate: 100/hour Clearance: Existing SC preferred … Would Be Doing This role sits at the intersection of cyber operations and ServiceNow engineering. You would be responsible for designing and embedding robust incident response capabilities in the ServiceNow Security Incident Response (SIR) module, closely aligned to NCSC and best-practice frameworks. ServiceNow SIR workflow ...

Head of Cyber, Band 8b

Hiring Organisation
Gloucestershire Hospitals NHS Foundation Trust
Location
Gloucester, GL1 2EL, United Kingdom
Salary
£66582.00 to £77368.00
participation in the regional "Defend as One" model. The role combines governance, assurance and hands-on leadership of proactive and preventative tactics, threat intelligence, incident response, vulnerability management, strategy and cultural change to build cyber resilience across the Integrated Care System (ICS). Main duties … within large, complex or multi-organisation environments. They will possess deep technical and governance expertise across areas such as threat detection, vulnerability management and incident response, with the ability to translate complex technical risk into clear, articulate, actionable information for senior executives and boards with assurance and confidence. ...

Network Security Manager

Hiring Organisation
Pearson Whiffin IT & Digital
Location
Dartford, Kent, South East, United Kingdom
Employment Type
Permanent
Salary
£95,000
Cyber & Network Security Manager We are seeking an experienced Cyber & Network Security Manager to lead the delivery of all security operations, drive cyber incident response, and provide enterprise-wide oversight of network security. This is an operational leadership role at the centre of the cyber defence function. … Security Operations Centre (SOC) services. Act as the senior operational escalation point for cyber security incidents and major security events. Own and coordinate cyber incident response activities, ensuring effective containment, eradication, recovery, and lessons learned. Develop, maintain, and test cyber incident response plans, procedures, and playbooks. ...

Cyber Incident Response Team Lead (CSIRT)

Hiring Organisation
Robert Walters
Location
Merseyside, England, United Kingdom
Employment Type
Contractor
Contract Rate
£500 - £600 per day
Blends hands-on incident command and digital forensics with programmatic capability building. Establishes the CSIRT operating model, creates scenario playbooks (ransomware, exfiltration) from scratch, and leads technical containment/recovery during active security events. About the Role My client is a well established business, looking for a hands … CSIRT Lead to establish and run the cyber incident response capability across a complex, multi-site industrial and corporate estate. The role blends hands-on incident command and digital forensics coordination with the programmatic build-out of incident playbooks and operational runbooks from scratch. Key Responsibilities ...

Head of Security Operations

Hiring Organisation
Jobleads-UK
Location
Wolverhampton, England, United Kingdom
will be accountable for the effective operation, continuous improvement and resilience of the Bank's security operations capability, covering Security Operations Centre monitoring and response, Identity and Access Management services, security analysis, operational security controls and supplier-delivered security services. The Head of Security Operations is a senior leadership … India offices, supported where appropriate by third-party managed security service providers. The team provides 24x7 or extended-hours security monitoring and response, identity and access management operations, vulnerability and threat analysis, security tooling administration, control assurance support, reporting, and operational support. Your responsibilities will include... Security Operations Leadership ...

IT Security & Compliance Lead

Hiring Organisation
Jobleads-UK
Location
City of Edinburgh, Scotland, United Kingdom
company grows. You'll build our IT security function from the ground up — covering device management, identity and access, infrastructure controls, and incident response — while also owning the compliance and AI governance work that keeps enterprise customers confident in how we operate. It's a hands‐on, build … tools like Okta. Own infrastructure and cloud security controls across our environment (e.g. AWS), working closely with Engineering to keep systems hardened. Security Operations & Incident Response Lead security incident response — full lifecycle investigations, coordinating with internal teams and external partners (e.g. SOCaaS providers), and running post ...

SPLUNK SOAR Engineer - FTC 12m £110k UK REMOTE

Hiring Organisation
Circle Group
Location
Birmingham, West Midlands, United Kingdom
Employment Type
Temporary
optimising security automation across a large-scale enterprise environment. This is a hands-on engineering position focused on delivering scalable Security Orchestration, Automation and Response (SOAR) capabilities using the Splunk Security platform . Working alongside Incident Response and Threat Management teams, you will develop advanced automation, improve … detection and response processes, and build new use cases that strengthen cyber resilience. This is a 12-month fixed term contract with a strong likelihood of renewal , offering a salary of up to £110,000 , an excellent benefits package and fully expensed travel and accommodation for occasional business travel ...

Cyber Security Engineer/Specialist

Hiring Organisation
Exalto Consulting
Location
Surrey, United Kingdom
Employment Type
Permanent
Salary
£70000 - £80000/annum Up to 80k (+ benefits)
risk reduction rather than purely operational support. You'll be responsible for strengthening the organisation's security posture through threat assessment, vulnerability management, incident response and continuous security improvement initiatives. Key responsibilities include: Enterprise Threat Management Identify, assess and mitigate cyber threats across enterprise infrastructure and business systems … vulnerability analysis Develop and implement security controls and remediation strategies Monitor emerging threats and recommend appropriate defensive measures Enhance threat detection, monitoring and incident response capabilities Develop and maintain incident response playbooks and operational procedures Work closely with third-party security providers during incidents and security ...

Security Operations Technical Lead

Hiring Organisation
Jobleads-UK
Location
Manchester, England, United Kingdom
that security operations activities are executed efficiently, consistently and in line with defined SLAs and operational standards, through hands‐on technical leadership across SOC, Incident Response, Threat Intelligence, Insider Risk and Vulnerability Management. This role acts as a senior technical escalation point, supporting complex investigations and driving improvements … detection, response, automation and operational processes. The role holder is expected to lead through expertise, supporting analysts and ensuring Security Operations operates with discipline, quality and continuous improvement. Key Responsibilities Act as the primary technical escalation point for security events and incidents identified by the Security Operations team. Support ...

MDR Team Lead

Hiring Organisation
Jobleads-UK
Location
Oxford, England, United Kingdom
Role Summary Sophos is seeking an experienced MDR Manager to support its Managed Detection and Response customers. The successful candidate will lead MDR analysts and day-to-day operations, ensuring operational quality, timely incident handling, effective customer communication, consistent reporting, and continuous service improvement. As part … Managed Detection and Response team, you will help deliver best-in-class monitoring, detection, and response services that proactively defend customer environments. You will guide investigations, review quality, coach analysts, manage escalations, and use operational insights to improve team performance, investigation consistency, and customer outcomes. What you will ...

SOC Operations Technical Lead

Hiring Organisation
Jobleads-UK
Location
Birmingham, England, United Kingdom
reports to Head of SOC Operations. This hands‐on position serves as the senior technical authority for SOC operations, driving excellence in threat detection, incident response, and security operations across a diverse multi-client portfolio. You will combine deep technical proficiency with strong consulting skills to mentor analysts … manage shift rotations, optimise SOC processes and tools, lead complex incident escalations, and act as a trusted advisor. Although you will manage a team of SOC analysts, this is not a purely managerial role; you will remain deeply involved in technical work while elevating team capabilities and delivering strategic ...

Cyber Security Analyst

Hiring Organisation
Hays Technology
Location
Newport, Gwent, United Kingdom
Employment Type
Permanent
Salary
£43000 - £47000/annum Up to £47k + good benefits
will require knowledge and understanding of attack and exploitation techniques and adversarial TTP's. Help to provide resilience to our threat monitoring and response capabilities. Handle security incident response with internal teams and other third parties to ensure that the incident response life cycle … Good knowledge and understanding of SOC processes and procedures. Basic experience using SIEM systems such as MS Sentinel, LogRhythm, AlienVault, Splunk Good understanding of incident response stages and handling. Basic knowledge and experience using leading endpoint detection and threat management products and managing their operation. Good knowledge ...

Cyber Security Engineer

Hiring Organisation
DCV Technologies Limited
Location
Tring, Hertfordshire, South East, United Kingdom
Employment Type
Contract
Contract Rate
£65,000
network estate (including Cisco Meraki). The role is hands-on and operational, partnering with IT teams to implement security controls, supportmonitoringand incident response through Sophos MDR, and improve cyber resilience by supporting Disaster Recovery (DR) testing and Business Continuity (BC) readiness. Key Responsibilities Cloud Security (Azure) Implement … whererequiredand ensure changes follow change control. Enable and review network security logging/alerting (e.g., syslog/SIEM integrations where applicable). Monitoring, Detection & Incident Response (Sophos MDR) Act as the internal technical point of contact for Sophos MDR and ensure smooth collaboration with MDR analysts. Maintain coverage ...

Incident Response (CSIRT) / SOC Level 3 Analyst

Hiring Organisation
Morson Edge
Location
Hampshire, United Kingdom
Employment Type
Contract
Contract Rate
GBP Annual
Incident Response (CSIRT)/SOC Level 3 Analyst - Outside IR35 Location: Crawley (2-3 days onsite) Contract: 6 Months Outside IR35 We are looking for an experienced Incident Response (CSIRT)/SOC Level 3 Analyst to join a high-performing cyber security operations team ...

Mid-Level Cyber Security Analyst

Hiring Organisation
Nextech
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
£45,000 - £55,000 per annum
excellent opportunity for someone with 2-4 years' hands-on security experience to take the next step in their career, working across threat detection, incident response, and security operations in a collaborative, fast-paced environment. Key Responsibilities Monitor security alerts and investigate potential threats using SIEM tooling Support … incident response activities, from initial triage through to resolution and reporting Conduct vulnerability assessments and coordinate remediation with technical teams Assist with security control reviews and audits against frameworks such as ISO 27001, NIST CSF, and Cyber Essentials Contribute to the development and improvement of security policies ...

Splunk SIEM Engineer

Hiring Organisation
Square One Resources
Location
Manchester, Lancashire, United Kingdom
Employment Type
Contract
Contract Rate
GBP 500 - 550 Daily
Cribl Stream. This is an exciting opportunity to work within a large-scale enterprise environment, helping improve threat detection, security monitoring, automation, and incident response capabilities. Essential Experience Bachelor's degree (minimum qualification). Strong experience administering and developing Splunk Enterprise . Extensive experience with Splunk Enterprise Security … Experience with Cribl Stream , including log ingestion, data routing, transformation, parsing, and data normalisation. Experience working in enterprise Security Operations environments, including threat detection, incident response, and security event analysis. Experience with SOAR platforms, playbook development, and security automation. Good understanding of network security, including Firewalls, proxies, network ...

Lead Security Analyst

Hiring Organisation
Hackajob Ltd
Location
Bristol, Avon, South West, United Kingdom
Employment Type
Permanent, Part Time, Work From Home
Salary
£80,000
engagement, setting the technical direction for the SOC and owning the quality of what the team produces - from detection engineering to threat-hunting to incident response. This isn't a role where you disappear into a ticket queue. You'll shape the threat-landscape narrative for your engagement, drive … collection plan, produce timely and rigorous intelligence products, and build feedback loops that keep the cycle honest and improving. Establish and lead security incident response practice - build playbooks, define the severity model, run exercises, and lead the team's response to significant incidents; run blameless post-mortems ...

Cyber Incident Response Manager

Hiring Organisation
Hays
Location
Liverpool, Merseyside, United Kingdom
Employment Type
Contract
Contract Rate
GBP 750 - 800 Daily
IR35 Status: Outside IR35 Contract Length: 6 months initially Location: Hybrid - Liverpool Overview I'm supporting an organisation seeking an experienced Incident Response Manager to lead and mature its Incident Response capability across a complex enterprise environment click apply for full job details ...

Senior Security Operations Engineer

Hiring Organisation
Vitality Corporate Services Limited
Location
Bournemouth, Dorset, South West, United Kingdom
Employment Type
Permanent
Salary
£60,000
week. We are happy to discuss flexible working! Top 3 skills needed for this role: Highly experienced Cyber Security Operations expertise Advanced security incident response capability Proven security tooling and threat management knowledge What this role is all about: We're looking for a Senior Security Operations Engineer … strong relationships with internal stakeholders, vendors and technology partners to support effective security operations You'll develop and maintain security documentation, operational procedures and incident response playbooks Support penetration testing activities and coordinate the remediation of identified findings Contribute to the ongoing enhancement of monitoring, detection and response ...

CIRT Analyst

Hiring Organisation
IMT Resourcing Solutions
Location
Cheltenham, Gloucestershire, United Kingdom
Employment Type
Contract
Contract Rate
GBP 300 Annual
major project by reviewing a large volume of applications and ensuring they meet security standards before deployment. Whilst there is some exposure to Cyber Incident Response activities, this is very much a hands-on security assessment role where you'll be expected to work independently and manage … management tools such as Qualys (or similar) to assess security risks. Support ongoing cybersecurity project delivery within a high-profile programme. Assist with Cyber Incident Response activities where required, including security monitoring and investigation. What we're looking for We're looking for someone ...

Senior Security Analyst

Hiring Organisation
Surrey County Council
Location
Reigate, Surrey, United Kingdom
Employment Type
Permanent
Salary
£55486 - £60898/annum
work will include proactive security monitoring across our hybrid cloud and on premises environment, triaging and investigating alerts, and supporting coordinated incident response activities. You will operate our vulnerability management processes, translate threat intelligence into actionable defences, and contribute to the improvement of detection content and security controls. … contribute to several high impact initiatives including: Establishing a more mature, risk based vulnerability management lifecycle and reducing exposure windows across critical systems Enhancing incident response readiness through improved playbooks, scenario testing, and lessons learned processes Uplifting monitoring coverage and the effectiveness of SIEM/EDR/ ...