Latest Incident Response Jobs

Incident Response Engineer 2

As an Incident Response Engineer 2, you will perform advanced investigative, forensic, and containment activities during active cyber incidents. You will work with moderate autonomy, support Incident Advisors, and mentor junior analysts to ensure consistent execution and documentation quality.

Sophos United Kingdom
Remote

Senior Incident Response Consultant, Rapid Response

Leads high-pressure incident response engagements for organizations affected by cyberattacks, directing forensic investigations and coordinating with customer teams. Produces detailed reports mapped to MITRE ATT&CK, focusing on ransomware and business email compromise (BEC) incidents. Operates in a rapid-response environment with a rotating weekend-heavy schedule to support global customers.

Sophos United Kingdom
Remote Permanent

Principal Consultant, Incident Response (Unit 42)

Leads high-stakes incident response engagements for clients, conducting forensic investigations across Windows, Linux, and macOS systems to identify breaches and attack vectors. Uses advanced tools like EnCase, FTK, and Splunk to analyze logs and memory artifacts, delivering actionable remediation strategies. Mentors junior consultants and collaborates with internal teams to strengthen client security postures.

Palo Alto Networks London, United Kingdom
Hybrid Permanent

SOC Lead

This role involves overseeing SOC activities, leading incident response, and mentoring a team of analysts. The focus is on cyber threat detection, incident investigation, and using the Splunk Enterprise Security platform.

NCC Group Remote, United Kingdom
Hybrid

Cyber Security Engineer

This role involves developing and implementing information security policies, monitoring security events, and designing and troubleshooting security solutions. The engineer will act as a senior point of contact for security issues, manage vulnerability testing, and provide technical expertise across network environments.

Oscar Technology Surrey, United Kingdom £50,000 pa

SOAR Engineer (SPLUNK)

The role involves designing, building, and maintaining security automations using Splunk to detect, investigate, and respond to cyber threats. Responsibilities include advanced analytics, scripting, creating new use cases, validating automation, and mentoring junior engineers.

NCC Group Remote, United Kingdom
Remote Permanent

3rd Line Security Analyst - Reading Sentinel Defender XDR CrowdStrike

This role involves leading serious security incidents, conducting forensic investigations, and developing detections and automation using tools like Sentinel, Defender XDR, and CrowdStrike. The analyst will also support the wider team by mentoring colleagues and maintaining documentation.

Global Technology Solutions Ltd Rg15Bs, United Kingdom £50,000 – £60,000 pa
Hybrid

Junior SOC Analyst

As a Junior SOC Analyst, you will support the monitoring and protection of business systems, helping to identify and escalate security threats. You will gain hands-on experience with security monitoring tools, threat detection, and incident management processes, contributing to the overall security posture of a growing financial services organization.

Back TO Work Nottingham, Nottinghamshire, United Kingdom £26,100 pa

Enterprise Security Risk Manager

This role involves assessing cyber risks, leading security investigations, and ensuring effective security controls across various domains. You'll work closely with senior stakeholders to shape the organization's security posture and advise on strategic actions.

Head Resourcing Edinburgh, Alba / Scotland, United Kingdom £70,000 pa

Junior SOC Analyst

As a Junior SOC Analyst, you will support the monitoring and protection of business systems, identify security threats, and assist with incident management. You will gain hands-on experience with security monitoring tools, threat detection, and compliance activities, while working in a growing financial services organization.

Back TO Work Derby, Derbyshire, DE1 3AE, United Kingdom £26,100 pa

Cyber Design Lead

The Cyber Design Lead will own end-to-end solution design for cybersecurity initiatives, producing architecture documents, risk assessments, and governance artefacts. They will present solutions to senior stakeholders and provide technical leadership in large-scale transformation programmes, with a focus on IAM and HashiCorp Vault.

Hays Technology Sheffield, South Yorkshire, United Kingdom £450 – £500 pd

Cyber Security Engineer

This role involves strengthening the organization's security posture by delivering key initiatives across the Cyber Security Roadmap. Responsibilities include managing and enhancing Microsoft Defender, Intune, Entra ID, and Microsoft 365 security controls, supporting vulnerability management, and maintaining security compliance.

Erin Associates Manchester, United Kingdom £45,000 – £50,000 pa

Senior Security Engineering Consultant

Our client, a leader in the cyber security sector, is currently seeking a Senior Security Engineering Consultant to join their team. This permanent role is a hands-on technical position within the Security Operations domain, focused on helping customers improve and...

Infosec Basingstoke, Hampshire, United Kingdom £70,000 – £80,000 pa

Infrastructure Engineer / Security

This role involves maintaining and securing IT infrastructure across on-premise and cloud environments, with a focus on system hardening, vulnerability management, and incident response. The engineer will work with security technologies like SIEM, EDR, and IAM, support compliance and disaster recovery, and contribute to infrastructure projects using automation and Infrastructure-as-Code tools. A strong background in Linux, networking, and cloud security is essential.

IT Talent Solutions Guildford, Surrey, United Kingdom £55,000 – £65,000 pa

Cloud Security Engineer

This role involves operating and optimising cloud security across AWS and cloud-native environments using Palo Alto's Cortex and Prisma platforms. You'll develop threat detection rules, support incident response, and enhance Zero Trust and container security controls. The position is fully remote, working within a collaborative security team on a 12-month contract.

Hays Technology London, United Kingdom £450 – £550 pd