Latest Incident Response Analyst Jobs

SOC Shift Lead

Leads a team of SOC analysts during assigned shifts, ensuring high-quality incident triage, investigation, and documentation. Oversees shift operations, conducts quality assurance, mentors junior staff, and drives process improvements in line with SLAs. Works closely with engineering and customer teams to enhance threat detection and response through rule tuning, reporting, and service refinement.

Claranet Leeds, United Kingdom
CrowdStrike logo

Automation Engineer II, Falcon Complete

This role focuses on building and maintaining security automation workflows, SOAR playbooks, and AI-powered response systems to enhance detection and triage efficiency within a managed detection and response (MDR) environment. The engineer develops Python and PowerShell scripts, integrates REST APIs, and incorporates LLMs and AI services into automated pipelines while ensuring reliability through testing and optimization. Work emphasizes collaboration with SOC teams, version control, and innovation in AI-driven cybersecurity operations.

Remote
CrowdStrike logo

Incident Response Consultant - Weekend Shift , GBR)

Lead and conduct incident response engagements for high-profile cybersecurity breaches, performing forensic analysis across Windows, Mac, and Linux systems. Hunt for advanced threats using AI-native tools, analyze network and host data, and produce detailed reports for legal and executive stakeholders. Work weekends in a collaborative, mission-driven environment focused on stopping breaches at scale.

CrowdStrike United Kingdom
Remote Permanent Shift-work

Principal Consultant, Incident Response (Unit 42)

Leads high-stakes incident response engagements for clients, conducting forensic investigations across Windows, Linux, and macOS systems to identify breaches and attack vectors. Uses advanced tools like EnCase, FTK, and Splunk to analyze logs and memory artifacts, delivering actionable remediation strategies. Mentors junior consultants and collaborates with internal teams to strengthen client security postures.

Palo Alto Networks London, United Kingdom
Hybrid Permanent

Principal Consultant, Incident Response (Weekend Schedule)

Lead incident response engagements for clients, conducting forensic investigations and providing expert guidance on containment and remediation. Perform host-based analysis and log examination across Windows, Linux, and macOS systems to identify threats and attack vectors. Mentor junior consultants and collaborate with internal and external stakeholders to strengthen client security postures using tools like EnCase, FTK, Splunk, and SIFT.

Palo Alto Networks United Kingdom

Cyber Security Analyst

Security Analyst | Cardiff | Hybrid Working | Excellent BenefitsAre you looking for a role where you'll play a key part in protecting a leading professional services organisation from evolving cyber threats?We're looking for a proactive Security Analyst to join...

Yolk Recruitment Cardiff, Cymru / Wales, CF10 2AF, United Kingdom
Experis logo

Splunk SIEM Engineer

Role Title: Splunk SIEM EngineerDuration: contract to run until 30/11/2026Location: Knutsford. Hybrid, 3 days per week onsiteRate: up to £587.33 p/d Umbrella inside IR35Role purpose / summaryJoin us as Splunk SIEM Engineer where you must design, develop and improve software,...

Experis Knutsford, Cheshire, United Kingdom

SC Cleared Splunk SIEM Engineer

Design, develop, and enhance SIEM solutions using Splunk and Microsoft Sentinel within a secure enterprise environment. Manage data pipelines, develop correlation rules, and support security operations with strong focus on automation, incident response, and cross-platform integration. Work in a hybrid model with regular on-site presence in Cheshire.

Hays Technology Knutsford, Cheshire, United Kingdom £500 – £638 pd
HAYS Specialist Recruitment logo

Cyber Security Manager

The Cyber Security Manager will lead the development and implementation of a comprehensive cyber security strategy, manage a team, and ensure compliance with regulations. Key responsibilities include conducting risk assessments, managing incident response, and fostering a culture of continuous learning and development.

HAYS Specialist Recruitment Stoke-on-Trent, United Kingdom
Hybrid Permanent

Security Operations Centre Manager

Leads the Cyber Security Operations Centre (CSOC) in detecting, responding to, and remediating cyber threats in real time. Develops and refines incident response plans, security monitoring strategies, and cyber resilience capabilities in alignment with government and regulatory standards. Works closely with senior stakeholders and external agencies to ensure robust cyber readiness and strategic investment in security tooling, governance, and staffing.

First Military Recruitment United Kingdom
Remote Contract Clearance Required

Interim Cyber Security Officer

This role involves providing senior-level technical leadership for a Security Operations Centre, with a focus on enhancing capabilities in endpoint detection and response using CrowdStrike Falcon and Splunk Enterprise Security. The candidate will lead configuration, incident response, threat hunting, and SOAR automation, while mentoring internal teams and improving security monitoring. The position requires deep expertise in EDR, SIEM, and security orchestration within a hybrid working environment in London.

Alois Technologies Limited London, United Kingdom £400 – £500 pd

Senior Security Engineer

This role involves leading security operations, incident response, and vulnerability management while designing and automating security controls across the technology estate. The engineer will work with SIEM, EDR (including CrowdStrike), IAM, and cloud security technologies, supporting secure adoption of AI and other emerging platforms. Responsibilities include policy development, threat monitoring, and embedding security best practices across teams.

STELLAR360 Bracknell, Berkshire, United Kingdom £80,000 – £100,000 pa

Cyber Security Officer

The Cyber Security Officer will lead the organisation's security posture by identifying and mitigating cyber risks across systems and data. This role involves driving security monitoring, incident response, vulnerability management, and policy development, while ensuring compliance with regulatory and data protection standards. The officer will collaborate with internal teams and third parties to embed security best practices and support resilience planning.

Pinpoint Resourcing Ltd Sw1P1Jp, SW1P 1JP, United Kingdom £65,000 pa

Cyber Security Engineer

This role involves delivering end-to-end cyber security work packages, including risk assessments, security architecture design, and vulnerability management. The engineer will develop security controls, produce security cases, and contribute to organisational security policies. Work spans both client and internal projects within a defence and national security context, with a strong focus on engineering and technical implementation.

Forward Role Cheltenham, United Kingdom £35,000 – £55,000 pa

Crisis Management & Scenario Testing Specialist

This role involves coordinating WTW's global crisis management and scenario testing programmes, supporting major incident response, and driving continuous improvement in operational resilience. The specialist will work across business, technology, and risk functions to ensure effective governance, communication, and recovery during disruptions. Key responsibilities include managing testing exercises, supporting regulatory compliance, and enhancing crisis response frameworks across a complex, global organisation.

WTW Ec3M7Dq, EC3M 7DQ, United Kingdom