1 to 25 of 132 Remote/Hybrid Incident Response Jobs in the UK excluding London

Security Incident Response Engineer (ServiceNow)

Hiring Organisation
INTEC SELECT LIMITED
Location
Warrington, Cheshire, England, United Kingdom
Employment Type
Contractor
Contract Rate
£100.00 per hour
Security Incident Response Engineer (ServiceNow) Contract: 6 Months (Likely Extension)Location: HybridIR35: Outside/LTD – £700PDSC Cleared/BPSSA highly reputable corporation is hiring an experienced ServiceNow Security Incident Response (SIR) Consultant to support the design, implementation and optimisation of a Security Incident Response capability for a Cyber Security Operations Centre (CSOC).This is an excellent opportunity to play a key role in enhancing cyber incident management processes, automating security workflows and integrating ServiceNow Security Operations with wider security tooling. Key Responsibilities ServiceNow SIR Workflow Design & Development Design and configure ...

Cyber Incident Response Manager

Hiring Organisation
Hays
Location
Liverpool, Merseyside, North West, United Kingdom
Employment Type
Contract
Contract Rate
£750.0 - £800 per day
IR35 Status: Outside IR35 Contract Length: 6 months initially Location: Hybrid - Liverpool Overview I'm supporting an organisation seeking an experienced Incident Response Manager to lead and mature its Incident Response capability across a complex enterprise environment. Responsibilities Own and manage cyber incidents from detection through … resolution. Review, enhance, and develop Incident Response frameworks, runbooks, and playbooks. Ensure alerts from SIEM, EDR, CTI, and SOC services are effectively integrated into Incident Response processes. Lead tabletop exercises and testing activities. Work closely with SOC, Threat Intelligence, Technology, and Business teams. Drive continual improvement ...

Security Incident Response Engineer

Hiring Organisation
NonStop Consulting
Location
Warrington, Cheshire, United Kingdom
Employment Type
Contract
Contract Rate
£100/hour
Details at a Glance Role: Security Incident Response Engineer Location: Warrington - hybrid, typically 2 days per week on site Contract length: 6 months (with strong potential for extension based on performance and project needs) IR35 status: Out of Scope Rate: 100/hour Clearance: Existing SC preferred … Would Be Doing This role sits at the intersection of cyber operations and ServiceNow engineering. You would be responsible for designing and embedding robust incident response capabilities in the ServiceNow Security Incident Response (SIR) module, closely aligned to NCSC and best-practice frameworks. ServiceNow SIR workflow ...

Head of Cyber, Band 8b

Hiring Organisation
Gloucestershire Hospitals NHS Foundation Trust
Location
Gloucester, GL1 2EL, United Kingdom
Salary
£66582.00 to £77368.00
participation in the regional "Defend as One" model. The role combines governance, assurance and hands-on leadership of proactive and preventative tactics, threat intelligence, incident response, vulnerability management, strategy and cultural change to build cyber resilience across the Integrated Care System (ICS). Main duties … within large, complex or multi-organisation environments. They will possess deep technical and governance expertise across areas such as threat detection, vulnerability management and incident response, with the ability to translate complex technical risk into clear, articulate, actionable information for senior executives and boards with assurance and confidence. ...

SPLUNK SOAR Engineer - FTC 12m £110k UK REMOTE

Hiring Organisation
Circle Group
Location
Birmingham, West Midlands, United Kingdom
Employment Type
Temporary
optimising security automation across a large-scale enterprise environment. This is a hands-on engineering position focused on delivering scalable Security Orchestration, Automation and Response (SOAR) capabilities using the Splunk Security platform . Working alongside Incident Response and Threat Management teams, you will develop advanced automation, improve … detection and response processes, and build new use cases that strengthen cyber resilience. This is a 12-month fixed term contract with a strong likelihood of renewal , offering a salary of up to £110,000 , an excellent benefits package and fully expensed travel and accommodation for occasional business travel ...

Cyber Security Engineer/Specialist

Hiring Organisation
Exalto Consulting
Location
Surrey, United Kingdom
Employment Type
Permanent
Salary
£70000 - £80000/annum Up to 80k (+ benefits)
risk reduction rather than purely operational support. You'll be responsible for strengthening the organisation's security posture through threat assessment, vulnerability management, incident response and continuous security improvement initiatives. Key responsibilities include: Enterprise Threat Management Identify, assess and mitigate cyber threats across enterprise infrastructure and business systems … vulnerability analysis Develop and implement security controls and remediation strategies Monitor emerging threats and recommend appropriate defensive measures Enhance threat detection, monitoring and incident response capabilities Develop and maintain incident response playbooks and operational procedures Work closely with third-party security providers during incidents and security ...

Cyber Security Analyst

Hiring Organisation
Hays Technology
Location
Newport, Gwent, United Kingdom
Employment Type
Permanent
Salary
£43000 - £47000/annum Up to £47k + good benefits
will require knowledge and understanding of attack and exploitation techniques and adversarial TTP's. Help to provide resilience to our threat monitoring and response capabilities. Handle security incident response with internal teams and other third parties to ensure that the incident response life cycle … Good knowledge and understanding of SOC processes and procedures. Basic experience using SIEM systems such as MS Sentinel, LogRhythm, AlienVault, Splunk Good understanding of incident response stages and handling. Basic knowledge and experience using leading endpoint detection and threat management products and managing their operation. Good knowledge ...

Cyber Security Engineer

Hiring Organisation
DCV Technologies Limited
Location
Tring, Hertfordshire, South East, United Kingdom
Employment Type
Contract
Contract Rate
£65,000
network estate (including Cisco Meraki). The role is hands-on and operational, partnering with IT teams to implement security controls, supportmonitoringand incident response through Sophos MDR, and improve cyber resilience by supporting Disaster Recovery (DR) testing and Business Continuity (BC) readiness. Key Responsibilities Cloud Security (Azure) Implement … whererequiredand ensure changes follow change control. Enable and review network security logging/alerting (e.g., syslog/SIEM integrations where applicable). Monitoring, Detection & Incident Response (Sophos MDR) Act as the internal technical point of contact for Sophos MDR and ensure smooth collaboration with MDR analysts. Maintain coverage ...

Mid-Level Cyber Security Analyst

Hiring Organisation
Nextech
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
£45,000 - £55,000 per annum
excellent opportunity for someone with 2-4 years' hands-on security experience to take the next step in their career, working across threat detection, incident response, and security operations in a collaborative, fast-paced environment. Key Responsibilities Monitor security alerts and investigate potential threats using SIEM tooling Support … incident response activities, from initial triage through to resolution and reporting Conduct vulnerability assessments and coordinate remediation with technical teams Assist with security control reviews and audits against frameworks such as ISO 27001, NIST CSF, and Cyber Essentials Contribute to the development and improvement of security policies ...

Lead Security Analyst

Hiring Organisation
Hackajob Ltd
Location
Bristol, Avon, South West, United Kingdom
Employment Type
Permanent, Part Time, Work From Home
Salary
£80,000
engagement, setting the technical direction for the SOC and owning the quality of what the team produces - from detection engineering to threat-hunting to incident response. This isn't a role where you disappear into a ticket queue. You'll shape the threat-landscape narrative for your engagement, drive … collection plan, produce timely and rigorous intelligence products, and build feedback loops that keep the cycle honest and improving. Establish and lead security incident response practice - build playbooks, define the severity model, run exercises, and lead the team's response to significant incidents; run blameless post-mortems ...

Cyber Incident Response Manager

Hiring Organisation
Hays
Location
Liverpool, Merseyside, United Kingdom
Employment Type
Contract
Contract Rate
GBP 750 - 800 Daily
IR35 Status: Outside IR35 Contract Length: 6 months initially Location: Hybrid - Liverpool Overview I'm supporting an organisation seeking an experienced Incident Response Manager to lead and mature its Incident Response capability across a complex enterprise environment click apply for full job details ...

CIRT Analyst

Hiring Organisation
IMT Resourcing Solutions
Location
Cheltenham, Gloucestershire, United Kingdom
Employment Type
Contract
Contract Rate
GBP 300 Annual
major project by reviewing a large volume of applications and ensuring they meet security standards before deployment. Whilst there is some exposure to Cyber Incident Response activities, this is very much a hands-on security assessment role where you'll be expected to work independently and manage … management tools such as Qualys (or similar) to assess security risks. Support ongoing cybersecurity project delivery within a high-profile programme. Assist with Cyber Incident Response activities where required, including security monitoring and investigation. What we're looking for We're looking for someone ...

Senior Security Analyst

Hiring Organisation
Surrey County Council
Location
Reigate, Surrey, United Kingdom
Employment Type
Permanent
Salary
£55486 - £60898/annum
work will include proactive security monitoring across our hybrid cloud and on premises environment, triaging and investigating alerts, and supporting coordinated incident response activities. You will operate our vulnerability management processes, translate threat intelligence into actionable defences, and contribute to the improvement of detection content and security controls. … contribute to several high impact initiatives including: Establishing a more mature, risk based vulnerability management lifecycle and reducing exposure windows across critical systems Enhancing incident response readiness through improved playbooks, scenario testing, and lessons learned processes Uplifting monitoring coverage and the effectiveness of SIEM/EDR/ ...

Senior SOC Analyst - Hybrid / Bristol

Hiring Organisation
Interface Recruitment
Location
Bristol, City of Bristol, United Kingdom
Employment Type
Permanent
Salary
£58600/annum 26 days hols / Pen / Health / DISx4
team within a leading international technology and cyber security provider. This is far more than a traditional SOC role. You'll be involved in incident response, threat hunting, vulnerability management, detection engineering and proactive cyber defence activities across a modern Microsoft security environment. What You'll Be Doing … Identity Defender for Cloud Apps Microsoft Intune Qualys AttackIQ XM Cyber We're Interested In Candidates with experience in: SOC Operations Security Monitoring Incident Response Threat Hunting Cyber Defence Vulnerability Management Security Operations Engineering You may currently be working as a: Senior SOC Analyst SOC Analyst Cyber Security ...

Senior SOC Analyst - Hybrid / Leeds

Hiring Organisation
Interface Recruitment
Location
Leeds, West Yorkshire, United Kingdom
Employment Type
Permanent
Salary
£58600/annum 26 days hols / Pen / Health / DISx2
team within a leading international technology and cyber security provider. This is far more than a traditional SOC role. You'll be involved in incident response, threat hunting, vulnerability management, detection engineering and proactive cyber defence activities across a modern Microsoft security environment. What You'll Be Doing … Identity Defender for Cloud Apps Microsoft Intune Qualys AttackIQ XM Cyber We're Interested In Candidates with experience in: SOC Operations Security Monitoring Incident Response Threat Hunting Cyber Defence Vulnerability Management Security Operations Engineering You may currently be working as a: Senior SOC Analyst SOC Analyst Cyber Security ...

Site Reliability Engineer

Hiring Organisation
Connells Limited
Location
Milton Keynes, Buckinghamshire, South East, United Kingdom
Employment Type
Permanent, Work From Home
hands-on role in ensuring it is reliable, scalable, and observable. You will help establish and mature SRE practices, focusing on: Monitoring and observability Incident response Post-incident review Reliability testing and capacity planning Toil reduction Enabling development velocity We offer a hybrid working arrangement with … Milton Keynes office. Key Responsibilities: Support teams using ConnellsX and respond to incidents in a structured, blameless way Investigate root causes and drive post-incident actions to completion Define SLIs, contribute to SLOs, and monitor error budgets Build dashboards, alerts, and runbooks to improve visibility Automate repetitive tasks ...

Splunk SIEM Engineer

Hiring Organisation
Experis
Location
Knutsford, Cheshire, United Kingdom
Employment Type
Contract
Splunk Enterprise Security, Microsoft Sentinel, and SIEM architecture including data models, correlation rules, and administrative functions. Security Operations: Strong analytical skills in threat detection, incident response, and security event analysis with experience in large enterprise environments (10,000+ endpoints). Data Pipeline Management: Hands-on experience with … tools like Cribl, plus understanding of data normalisation and parsing in Splunk Enterprise. SOAR & Automation: Experience with Security Orchestration platforms, playbook development, and automated response workflows for incident management. Network Security Fundamentals: Working knowledge of network architectures, firewalls, proxies, and common attack vectors with troubleshooting expertise. Communication & Documentation ...

Splunk SIEM Engineer

Hiring Organisation
Hays
Location
Knutsford, Cheshire, North West, United Kingdom
Employment Type
Contract, Work From Home
Contract Rate
£500.0 - £638 per day + Up to £638 per day Inside IR35
Splunk Enterprise Security, Microsoft Sentinel, and SIEM architecture including data models, correlation rules, and administrative functions. Security Operations: Strong analytical skills in threat detection, incident response, and security event analysis with experience in large enterprise environments (10,000+ endpoints). Data Pipeline Management: Hands-on experience with … tools like Cribl, plus understanding of data normalisation and parsing in Splunk Enterprise. SOAR & Automation: Experience with Security Orchestration platforms, playbook development, and automated response workflows for incident management. Network Security Fundamentals: Working knowledge of network architectures, firewalls, proxies, and common attack vectors with troubleshooting expertise. Communication & Documentation ...

Support Engineer L3

Hiring Organisation
Opus Recruitment Solutions
Location
Newcastle upon Tyne, Tyne & Wear, United Kingdom
Employment Type
Contract
Contract Rate
£37000 - £55000/annum
point for complex issues impacting business-critical services. Execute technical recovery actions during incidents to restore service as quickly as possible. Participate in Major Incident and High-Priority Incident response activities. Technical Troubleshooting Diagnose and resolve application, infrastructure, integration, database, and data-related issues across supported products … architecture, business processes, and operational dependencies. Problem Management & Continuous Improvement Conduct root cause analysis (RCA) and contribute to Problem Management processes. Participate in post-incident reviews and recommend long-term preventative solutions. Drive continuous service improvement through automation, process optimisation, tooling enhancements, and reduction of recurring incidents. Monitor service ...

Security Analyst | Cyber Security | Hybrid

Hiring Organisation
Cyber Talent Limited
Location
Lutterworth, Leicestershire, East Midlands, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£55,000
Cyber Essentials , and Cyber Essentials Plus certifications. Produce security metrics , dashboards , and security reports to inform security strategy . Lead and coordinate security incident response and post-incident improvements . Conduct third-party security assessments and manage vendor security assurance . Requirements 4+ years' experience … skills across complex IT environments. Proactive approach to security , with a focus on continuous improvement and best practice . Experience leading or supporting security incident response and remediation . Strong reporting , analysis , and security metrics capabilities. Excellent communication , stakeholder engagement , and documentation skills. Benefits Excellent salary Pension Private ...

Cyber Security Specialist (SecOps / Liverpool)

Hiring Organisation
Michael Page
Location
Liverpool, Merseyside, United Kingdom
Employment Type
Permanent
Salary
£60000 - £65000/annum healthcare
This position focuses on security monitoring, incident investigation, threat analysis, and operational security improvement. The successful candidate will act as a subject matter expert for cyber security operations, supporting both proactive and reactive security activities while helping to enhance the organisation's overall security maturity. Client Details Our client … analysis and identifying potential threats or areas requiring further investigation. Working closely with external security service providers to ensure effective monitoring, alert management, and incident handling. Supporting cyber incident response activities as a technical security specialist. Analysing security metrics and trends, providing recommendations to improve security controls ...

Lead Security Assurance Engineer

Hiring Organisation
Jobleads-UK
Location
Bristol, England, United Kingdom
audience, showing trends over time, and structuring reports around the decisions the reader needs to make, not just the findings. Set the standard for incident response and detection readiness. Drive adoption of incident response practices across engagements, own the IR-to-vulnerability-management feedback loop ...

Lead Security Assurance Engineer

Hiring Organisation
Hackajob Ltd
Location
Bristol, Avon, South West, United Kingdom
Employment Type
Permanent, Part Time, Work From Home
Salary
£90,000
audience, showing trends over time, and structuring reports around the decisions the reader needs to make, not just the findings. Set the standard for incident response and detection readiness. Drive adoption of incident response practices across engagements, own the IR-to-vulnerability-management feedback loop ...

Head of Cyber Defence Centre

Hiring Organisation
Jobleads-UK
Location
Manchester, England, United Kingdom
scale security capabilities that protect the UK's largest digital bank. You'll provide strategic direction for cyber defence, detection engineering, threat hunting and incident response, while driving continuous improvement across security operations platforms, tooling and processes. Leading a high‐performing team, you'll strengthen operational resilience, coordinate … effective response to cyber threats and incidents, champion a threat‐led approach to defence, and help shape a world‐class security operation that enables the Group to go faster, safely. Why Join us? If you think all banks are the same, you're wrong. We're a pioneering, fast ...

SOC Manager

Hiring Organisation
RESILLION UK LIMITED
Location
Glasgow, Lanarkshire, Scotland, United Kingdom
Employment Type
Permanent
Salary
£80,000
organisations strengthen their security posture, protect critical assets, and deliver high-quality digital solutions. Our teams operate across multiple specialist disciplines, including Digital Forensics, Incident Response, SOC Operations, Quality & Compliance, and Technical Consultancy. We are committed to excellence, continuous improvement, and delivering trusted, customer-focused services that meet … complex transition projects (e.g., insourcing, offshore in-shore). Operational familiarity with CREST, NIS2, DORA, and the EU AI Act. Hands-on experience leading incident response, threat hunting, and investigations. Broad technical knowledge across Windows, Linux, cloud, hybrid environments, firewalls, EDR/XDR, IDS/IPS, VPNs ...