Latest Incident Response Jobs

CrowdStrike logo

Incident Response Consultant - Weekend Shift , GBR)

Lead and conduct incident response engagements for high-profile cybersecurity breaches, performing forensic analysis across Windows, Mac, and Linux systems. Hunt for advanced threats using AI-native tools, analyze network and host data, and produce detailed reports for legal and executive stakeholders. Work weekends in a collaborative, mission-driven environment focused on stopping breaches at scale.

CrowdStrike United Kingdom
Remote Permanent Shift-work

Senior Incident Response Consultant, Rapid Response

Leads high-pressure incident response engagements for organizations affected by cyberattacks, directing forensic investigations and coordinating with customer teams. Produces detailed reports mapped to MITRE ATT&CK, focusing on ransomware and business email compromise (BEC) incidents. Operates in a rapid-response environment with a rotating weekend-heavy schedule to support global customers.

Sophos United Kingdom
Remote Permanent

Principal Consultant, Incident Response (Unit 42)

Leads high-stakes incident response engagements for clients, conducting forensic investigations across Windows, Linux, and macOS systems to identify breaches and attack vectors. Uses advanced tools like EnCase, FTK, and Splunk to analyze logs and memory artifacts, delivering actionable remediation strategies. Mentors junior consultants and collaborates with internal teams to strengthen client security postures.

Palo Alto Networks London, United Kingdom
Hybrid Permanent

SOC Manager

Lead and develop a Security Operations Centre within a public sector environment, defining strategy and operational roadmap while overseeing incident management, threat intelligence, and security monitoring. Manage cyber security tools, vendor relationships, and MSSP partnerships to strengthen national-level security operations. This role requires active SC clearance and experience in strategic SOC leadership.

NonStop Consulting Exeter, Devon, United Kingdom £800 – £850 pd

Operational Security Lead and Vulnerability Manager

This role involves leading day-to-day operational cybersecurity, managing cyber incidents, and overseeing vulnerability management across infrastructure and cloud environments. The individual will coordinate incident response, drive remediation of security risks, and lead threat monitoring and phishing simulations. They will work closely with senior stakeholders to strengthen cyber resilience and ensure robust security governance within a regulated financial services environment.

Kensington Mortgage Company Marlow, United Kingdom
Hybrid Permanent

SOC Analyst - Active SC required

Monitor and respond to security incidents using IBM QRadar SIEM, conducting threat detection, log analysis, and incident investigation across enterprise systems. Support a defence/aerospace client with robust security controls and detailed post-incident reporting. Engage in proactive threat hunting and handle diverse cyber threats including phishing and malware.

Matchtech Harlow, Essex, United Kingdom
Hybrid Contract Clearance Required

IT Cyber Security Analyst

This role involves managing patching, vulnerability remediation, and incident response within a large enterprise environment, supporting both IT and OT systems. The analyst will work closely with internal teams and external SOC/MDR providers to enhance threat detection and security maturity. Key responsibilities include coordinating security controls, supporting audits, and improving detection capabilities across networks, endpoints, identity, and cloud platforms.

Rise Technical Recruitment Scunthorpe, DN15 6SS, United Kingdom £45,000 – £50,000 pa
On-site Permanent Clearance Required

IT Cyber Security Analyst

This role involves managing patching, vulnerability remediation, and incident response within a large enterprise environment that includes both IT and OT systems. The analyst will work alongside SOC/MDR providers to monitor threats, improve detection capabilities, and support compliance and security control initiatives. It's a key position in an ongoing cyber transformation, focusing on strengthening overall security maturity across critical infrastructure.

Rise Technical Recruitment Scunthorpe, Lincolnshire, DN17 1AF, United Kingdom £45,000 – £50,000 pa
On-site Permanent Clearance Required

Cyber Resilience Specialist

This role involves assessing cyber threats and vulnerabilities in the context of operational resilience, translating technical security risks into business service impacts, and supporting scenario testing and governance. The specialist will work across technology, security, and risk teams to strengthen resilience capabilities within a regulated environment. Key focus areas include service mapping, impact tolerance assessments, and providing actionable recommendations to enhance organisational resilience.

Hays Technology London, United Kingdom £600 pd
Remote Contract

SOC Manager

Lead and oversee the strategic direction of a Cyber Security Operations Centre, managing incident response, threat intelligence, and security operations. This role involves high-level governance, coordination with external vendors and MSSPs, and leading teams during major security incidents. The position requires a strategic leader rather than a hands-on analyst, with a focus on crisis management and security operations leadership.

Randstad Technologies Recruitment London, City And County Of the City Of London, United Kingdom £600 – £700 pd
Remote Contract Clearance Required

Senior Security Engineering Consultant

Our client, a leader in the cyber security sector, is currently seeking a Senior Security Engineering Consultant to join their team. This permanent role is a hands-on technical position within the Security Operations domain, focused on helping customers improve and...

Infosec Basingstoke, Hampshire, United Kingdom £70,000 – £80,000 pa

Infrastructure Engineer / Security

This role involves maintaining and securing IT infrastructure across on-premise and cloud environments, with a focus on system hardening, vulnerability management, and incident response. The engineer will work with security technologies like SIEM, EDR, and IAM, support compliance and disaster recovery, and contribute to infrastructure projects using automation and Infrastructure-as-Code tools. A strong background in Linux, networking, and cloud security is essential.

IT Talent Solutions Guildford, Surrey, United Kingdom £55,000 – £65,000 pa

Cloud Security Engineer

This role involves operating and optimising cloud security across AWS and cloud-native environments using Palo Alto's Cortex and Prisma platforms. You'll develop threat detection rules, support incident response, and enhance Zero Trust and container security controls. The position is fully remote, working within a collaborative security team on a 12-month contract.

Hays Technology London, United Kingdom £450 – £550 pd

SOC Analyst (Tier 1)

Monitor and triage security alerts using Microsoft Defender and Sentinel in a 24/7 Security Operations Centre. Conduct incident investigation and support response activities within a collaborative team environment. Contribute to improving detection capabilities and SOC processes in a hybrid-working setup with rotating 12-hour shifts.

VIQU IT New Edlington, South Yorkshire, DN12 1DZ, United Kingdom £25,000 – £30,000 pa

Senior Security Engineer

This role involves leading security operations, incident response, and vulnerability management while designing and automating security controls across the technology estate. The engineer will work with SIEM, EDR (including CrowdStrike), IAM, and cloud security technologies, supporting secure adoption of AI and other emerging platforms. Responsibilities include policy development, threat monitoring, and embedding security best practices across teams.

STELLAR360 Bracknell, Berkshire, United Kingdom £80,000 – £100,000 pa