Latest Incident Response Analyst Jobs

SOC Automation Engineer

As a SOC Automation Engineer, you will design, build, and maintain automation workflows to enhance the efficiency and scalability of SOC services. You will work across SIEM, EDR, and SOAR platforms, focusing on reducing analyst workload and improving incident response times. Collaboration with SOC and engineering teams to identify automation opportunities and support pre-sales activities is also a key part of the role.

Claranet Leeds, West Yorkshire, United Kingdom
On-site Permanent Clearance Required

SOC Automation Engineer

This role involves designing, building, and maintaining automation workflows across SIEM, EDR, and SOAR platforms—primarily Palo Alto XSOAR—to enhance SOC efficiency and incident response. The engineer will integrate security tools, optimise automation lifecycle management, and collaborate with SOC analysts and engineering teams to reduce manual effort. Responsibilities also include contributing to threat modelling, pre-sales support, and ensuring secure, scalable automation in multi-tenant environments.

Claranet Ls11Az, United Kingdom

Cyber Security Engineer

This role involves securing a hybrid IT environment spanning Microsoft Azure, VMware, and Cisco Meraki systems. The engineer will focus on cloud security, infrastructure hardening, incident response, and disaster recovery testing while collaborating with infrastructure and service teams. Key responsibilities include vulnerability remediation, security automation, and strengthening cyber resilience across the estate.

DCV Technologies Lincoln, Lincolnshire, United Kingdom £60,000 – £65,000 pa
Hybrid Permanent Clearance Required

Threat Detection Engineer

This role involves designing and developing threat-led detections using threat intelligence and hunting outputs, collaborating with an MSP SOC, and building automated reporting dashboards. The focus is on protecting sensitive genomic and AI-driven data, with high autonomy and a mission to advance precision healthcare.

Additional Resources London, United Kingdom £60,000 – £80,000 pa
Hybrid Permanent Flexible

Threat Detection Engineer

Design and develop threat-led detection capabilities using Microsoft Sentinel, KQL, and threat intelligence to protect sensitive genomic and AI-driven healthcare data. Build automated reporting dashboards, collaborate with an outsourced SOC, and ensure monitoring coverage across cloud, SaaS, and Kubernetes environments. Contribute to security initiatives including ISO 27001 compliance and detection logic documentation.

Additional Resources Wc1A2Sl, United Kingdom £60,000 – £80,000 pa
Hybrid

Sr. AI Threat Researcher

A senior individual contributor role focused on researching how threat actors exploit AI across the attack lifecycle, including LLM-powered social engineering, AI-generated malware, and attacks on agentic AI systems. The role involves analyzing telemetry and OSINT to detect adversarial AI use, developing detection strategies, automating research workflows using AI, and producing actionable intelligence for internal and external dissemination. Works cross-functionally with threat researchers, malware analysts, and engineers to integrate findings into protections and operational systems.

Sophos United Kingdom
Remote Permanent
CrowdStrike logo

Sr. Software Engineer, Backend/Cloud , London)

Design and build scalable backend systems for a next-generation AI-native SIEM platform, enabling security teams to detect, investigate, and respond to threats at petabyte scale. Develop intelligent case management and investigation workflows using Go, Kubernetes, and cloud-native technologies. Collaborate across engineering, product, and design to deliver low-latency, high-throughput services that power real-time threat detection and automated response.

CrowdStrike London, United Kingdom
Hybrid Permanent
Darktrace logo

Technical Success Manager - Enterprise Accounts

The role involves building trusted relationships with enterprise security and IT teams to drive technical adoption of Darktrace’s AI-driven cybersecurity platform. You'll create success plans, identify high-value use cases, and guide customers from deployment to active use, ensuring measurable risk reduction and operational integration. The position acts as a technical advisor, bridging customer needs with internal teams to improve health, retention, and expansion opportunities.

Darktrace London, UB8 1LQ, United Kingdom
Hybrid Permanent

SOC Analyst

Monitor and triage security alerts in a 24/7 Security Operations Centre, investigating suspicious activity and escalating incidents. Conduct log reviews and support incident response using tools like Sentinel, Defender, or Splunk. Operate on a 4 days on / 4 days off shift pattern with mostly remote work and periodic on-site attendance in Doncaster.

VIQU IT Recruitment London, United Kingdom £25,000 – £30,000 pa
CrowdStrike logo

Automation Engineer II, Falcon Complete

Develop and maintain security automation workflows and SOAR playbooks to enhance detection, triage, and response within a managed detection and response (MDR) environment. Integrate AI-powered solutions and scripting (PowerShell, Python) to streamline SOC operations, working closely with analysts to identify automation opportunities. Use Git for version control and contribute to improving analyst efficiency through scalable, AI-augmented workflows.

CrowdStrike United Kingdom
Remote Permanent

Cyber Security SOC Analyst

As a Cyber Security SOC Analyst, you will monitor systems, respond to alerts, and manage incident reporting. You will work closely with the Escalations Management Team to mitigate threats and provide operational support to the wider Cyber Security Team.

Gold Group London, United Kingdom £30,000 – £36,000 pa
Hybrid Permanent Clearance Required

Cyber Security Analyst - Watford

Job specification for the position of: Cyber Security AnalystReporting to: IT Governance and Security Manager***OFFICE BASED IN WATFORD - FIVE DAYS PER WEEK - NON-NEGOTIABLE***Must have a British passport or ILR (Indefinite leave to remain) - ***no sponsorship available***Purpose of...

Morgan Philips Group Watford, Hertfordshire, United Kingdom £55,000 – £60,000 pa

SOC Engineer

This role involves engineering and optimising security tools, telemetry, detections, and automation within a Cyber Security Operations Centre. The SOC Engineer will administer Microsoft Sentinel, develop SOAR workflows, tune detection rules, conduct threat hunting, and support incident response. The position requires strong scripting skills and experience with SIEM, SOAR, and security monitoring across hybrid environments.

Proactive Appointments Milton Keynes, United Kingdom £55,000 pa

Senior Threat Researcher (UK)

Develops high-fidelity threat detections by analyzing malware and web attacks using multi-source telemetry and threat intelligence. Translates research into actionable alerts across Sophos' security platform with a focus on reducing noise. Works closely with threat intelligence and product teams to enhance detection accuracy for endpoint, cloud, and network environments.

Sophos United Kingdom
Remote Permanent

Incident Response Consultant - Mid to Principal - UK Wide

This role involves conducting digital forensics and incident response (DFIR) for organisations during cyber incidents, from initial triage to recovery. The consultant will perform forensic analysis across endpoints, networks, and cloud environments, identify attacker techniques, and support proactive readiness planning. Work includes producing technical reports, threat hunting, and improving detection capabilities within a remote UK-wide team.

Circle Recruitment London, United Kingdom £55,000 – £95,000 pa