Latest Incident Response Jobs

CrowdStrike logo

Incident Response Consultant - Weekend Shift , GBR)

Lead and conduct incident response engagements for high-profile cybersecurity breaches, performing forensic analysis across Windows, Mac, and Linux systems. Hunt for advanced threats using AI-native tools, analyze network and host data, and produce detailed reports for legal and executive stakeholders. Work weekends in a collaborative, mission-driven environment focused on stopping breaches at scale.

CrowdStrike United Kingdom
Remote Permanent Shift-work

Incident Response Engineer 2

As an Incident Response Engineer 2, you will perform advanced investigative, forensic, and containment activities during active cyber incidents. You will work with moderate autonomy, support Incident Advisors, and mentor junior analysts to ensure consistent execution and documentation quality.

Sophos United Kingdom
Remote

Senior Incident Response Consultant, Rapid Response

Leads high-pressure incident response engagements for organizations affected by cyberattacks, directing forensic investigations and coordinating with customer teams. Produces detailed reports mapped to MITRE ATT&CK, focusing on ransomware and business email compromise (BEC) incidents. Operates in a rapid-response environment with a rotating weekend-heavy schedule to support global customers.

Sophos United Kingdom
Remote Permanent

Principal Consultant, Incident Response (Unit 42)

Leads high-stakes incident response engagements for clients, conducting forensic investigations across Windows, Linux, and macOS systems to identify breaches and attack vectors. Uses advanced tools like EnCase, FTK, and Splunk to analyze logs and memory artifacts, delivering actionable remediation strategies. Mentors junior consultants and collaborates with internal teams to strengthen client security postures.

Palo Alto Networks London, United Kingdom
Hybrid Permanent

SOC Lead

This role involves overseeing SOC activities, leading incident response, and mentoring a team of analysts. The focus is on cyber threat detection, incident investigation, and using the Splunk Enterprise Security platform.

NCC Group Remote, United Kingdom
Hybrid

SOAR Engineer (SPLUNK)

The role involves designing, building, and maintaining security automations using Splunk to detect, investigate, and respond to cyber threats. Responsibilities include advanced analytics, scripting, creating new use cases, validating automation, and mentoring junior engineers.

NCC Group Remote, United Kingdom
Remote Permanent

SOC Analyst - Active SC required

Monitor and respond to security incidents using IBM QRadar SIEM, conducting threat detection, log analysis, and incident investigation across enterprise systems. Support a defence/aerospace client with robust security controls and detailed post-incident reporting. Engage in proactive threat hunting and handle diverse cyber threats including phishing and malware.

Matchtech Harlow, Essex, United Kingdom
Hybrid Contract Clearance Required

Enterprise Security Risk Manager

This role involves assessing cyber risks, leading security investigations, and ensuring effective security controls across various domains. You'll work closely with senior stakeholders to shape the organization's security posture and advise on strategic actions.

Head Resourcing Edinburgh, Alba / Scotland, United Kingdom £70,000 pa

Senior Security Engineering Consultant

Our client, a leader in the cyber security sector, is currently seeking a Senior Security Engineering Consultant to join their team. This permanent role is a hands-on technical position within the Security Operations domain, focused on helping customers improve and...

Infosec Basingstoke, Hampshire, United Kingdom £70,000 – £80,000 pa

Infrastructure Engineer / Security

This role involves maintaining and securing IT infrastructure across on-premise and cloud environments, with a focus on system hardening, vulnerability management, and incident response. The engineer will work with security technologies like SIEM, EDR, and IAM, support compliance and disaster recovery, and contribute to infrastructure projects using automation and Infrastructure-as-Code tools. A strong background in Linux, networking, and cloud security is essential.

IT Talent Solutions Guildford, Surrey, United Kingdom £55,000 – £65,000 pa

Cloud Security Engineer

This role involves operating and optimising cloud security across AWS and cloud-native environments using Palo Alto's Cortex and Prisma platforms. You'll develop threat detection rules, support incident response, and enhance Zero Trust and container security controls. The position is fully remote, working within a collaborative security team on a 12-month contract.

Hays Technology London, United Kingdom £450 – £550 pd

Senior SOC Analyst

This role involves independently monitoring and investigating cybersecurity events in a 24/7 SOC environment. Responsibilities include analysing security alerts, correlating information from multiple sources, and providing technical guidance to junior analysts.

Hays Technology Milton Keynes, Buckinghamshire, United Kingdom £73 ph
On-site Permanent Shift-work Clearance Required

Senior SOC Analyst

This role involves leading complex security incident investigations, designing and tuning detection rules in SIEM/EDR platforms, proactive threat hunting in cloud and CI/CD environments, and building automation through SOAR. The analyst will drive improvements in SOC maturity, collaborate with engineering teams to strengthen security posture, and mentor junior staff, all within a modern cloud-first environment.

Ballantyne Technology Associates Ltd Reading, Berkshire, United Kingdom £75,000 – £90,000 pa
Hybrid Permanent

Lead SOC Analyst - DV Cleared

The Lead SOC Analyst will lead the operational delivery of security monitoring, supervise Senior SOC Analysts, and provide technical leadership during live cyber security events. Responsibilities include complex investigations, shift handovers, and continuous process improvement.

Network IT Milton Keynes, Buckinghamshire, United Kingdom £80 ph

Cyber Security & Infrastructure Engineer

This role involves protecting systems, networks, and data by monitoring security alerts, leading incident response, and improving security posture across on-premises and cloud environments. The engineer will implement and maintain Azure, Microsoft 365, and Intune security, conduct vulnerability management, and ensure compliance with standards like ISO 27001 and NCSC. A key focus is threat detection, forensic investigation, and enhancing infrastructure resilience within a small, technical IT team.

Adria Solutions East Howdon, Tyne & Wear, United Kingdom £40,000 – £50,000 pa