Latest Incident Response Analyst Jobs

CrowdStrike logo

Platform Professional Services, Sr. Analyst

This role involves hands-on technical work in incident detection, analysis, and response using CrowdStrike's Falcon platform. You will develop and improve processes, produce high-quality reports, and provide consulting support to clients.

CrowdStrike United Kingdom
Remote
CrowdStrike logo

Platform Professional Services, Sr. Analyst

This role involves hands-on incident handling, malware analysis, and remediation across various platforms. You will develop and improve detection processes, produce high-quality reports, and provide consulting support to clients using CrowdStrike's Falcon platform.

Remote

SOC Engineer

This role involves operating and tuning security monitoring platforms, managing log and telemetry pipelines, and supporting incident response within a 24/7 SOC environment. The engineer will develop detection rules and playbooks, automate security operations, and onboard new systems into monitoring frameworks. The position emphasizes hands-on technical work across hybrid on-premises and cloud infrastructures, with a focus on improving visibility and response capabilities.

Spectrum IT Recruitment Milton Keynes, United Kingdom £40,000 – £45,000 pa
Adecco logo

Security Automation and AI SOC Engineer (Torq, Tines, Swimlane)

This role involves designing and implementing security automation workflows and AI-assisted security operations within a SOC. The focus is on reducing manual effort, improving consistency, and ensuring safe and effective AI adoption. The candidate will work closely with the SOC team to identify automation opportunities and establish best practices.

Adecco London, United Kingdom £750 pd

Sr. AI Threat Researcher

A senior individual contributor role focused on researching how threat actors exploit AI across the attack lifecycle, including LLM-powered social engineering, AI-generated malware, and attacks on agentic AI systems. The role involves analyzing telemetry and OSINT to detect adversarial AI use, developing detection strategies, automating research workflows using AI, and producing actionable intelligence for internal and external dissemination. Works cross-functionally with threat researchers, malware analysts, and engineers to integrate findings into protections and operational systems.

Sophos United Kingdom
Remote Permanent
Darktrace logo

Technical Success Manager - Enterprise Accounts

Act as a trusted technical advisor for enterprise customers, driving adoption and operational value of AI-driven cybersecurity solutions. Bridge technical and business needs by identifying risks, guiding integration, and accelerating time-to-value. Collaborate across teams to ensure platform health, customer success, and renewal readiness.

Darktrace Germany
Darktrace logo

Technical Success Manager - Enterprise Accounts

The Technical Success Manager (TSM) role involves building trusted relationships with customer security and IT teams, creating technical success plans, and guiding customers through the transition from deployment to active use. The role focuses on driving adoption, reducing risk, and ensuring customer satisfaction and renewal readiness.

Darktrace

Cyber Security SOC Analyst

As a Cyber Security SOC Analyst, you will monitor systems, respond to alerts, and manage incident reporting. You will work closely with the Escalations Management Team to mitigate threats and provide operational support to the wider Cyber Security Team.

Gold Group London, United Kingdom £30,000 – £36,000 pa
Hybrid Permanent Clearance Required
Experis logo

Senior SOC Engineer

This role involves designing, implementing, and optimising Microsoft Sentinel and Defender solutions within enterprise environments. The engineer will develop KQL queries, detection rules, and automation playbooks while conducting security assessments and tenant health checks. It focuses on technical depth in Microsoft security engineering, with direct customer engagement and mentorship of junior team members.

Experis United Kingdom

Principal Microsoft Defender XDR, IRM & Deception Engineer

The Principal Microsoft Defender XDR, IRM & Deception Engineer, working within the Global Information and Cyber Security Defence (ICSD) function, is the technical leader for enterprise cyber deception and unified detection and response across the Microsoft security ecosystem. The role...

WTW London, United Kingdom

Principal Consultant, Incident Response (Unit 42)

Leads high-stakes incident response engagements for clients, conducting forensic investigations across Windows, Linux, and macOS systems to identify breaches and attack vectors. Uses advanced tools like EnCase, FTK, and Splunk to analyze logs and memory artifacts, delivering actionable remediation strategies. Mentors junior consultants and collaborates with internal teams to strengthen client security postures.

Palo Alto Networks London, United Kingdom
Hybrid Permanent

Secure by Design lead for Defence

This senior role involves owning cybersecurity and information assurance across products, programmes, and spacecraft lifecycle in the defence sector. Responsibilities include certification, ITHCs, Secure by Design reviews, supplier security, and space licensing assurance, with a focus on hands-on delivery and real outcomes.

Standard 8 Guildford, United Kingdom £85,000 pa
Hybrid Permanent Clearance Required

Cyber Resilience Specialist

This role involves assessing cyber threats and vulnerabilities in the context of operational resilience, translating technical security risks into business service impacts, and supporting scenario testing and governance. The specialist will work across technology, security, and risk teams to strengthen resilience capabilities within a regulated environment. Key focus areas include service mapping, impact tolerance assessments, and providing actionable recommendations to enhance organisational resilience.

Hays Technology London, United Kingdom £600 pd
Remote Contract

Data Privacy Senior Manager

Lead the design and implementation of privacy controls across data platforms, products, and engineering workflows, embedding privacy-by-design into SDLC and CI/CD pipelines. Drive automation of data discovery, classification, and lineage, and manage compliance with UK GDPR, international transfers, and AI/ML model governance. Operate end-to-end data subject rights and incident response with engineered runbooks and tooling integration.

Barclays London, E14 5RB, United Kingdom
Hybrid Permanent

Cyber Security & Infrastructure Engineer

This role involves protecting systems, networks, and data by monitoring security alerts, leading incident response, and improving security posture across on-premises and cloud environments. The engineer will implement and maintain Azure, Microsoft 365, and Intune security, conduct vulnerability management, and ensure compliance with standards like ISO 27001 and NCSC. A key focus is threat detection, forensic investigation, and enhancing infrastructure resilience within a small, technical IT team.

Adria Solutions East Howdon, Tyne & Wear, United Kingdom £40,000 – £50,000 pa