Latest Incident Response Jobs

CrowdStrike logo

Incident Response Consultant - Weekend Shift , GBR)

Lead and conduct incident response engagements for high-profile cybersecurity breaches, performing forensic analysis across Windows, Mac, and Linux systems. Hunt for advanced threats using AI-native tools, analyze network and host data, and produce detailed reports for legal and executive stakeholders. Work weekends in a collaborative, mission-driven environment focused on stopping breaches at scale.

CrowdStrike United Kingdom
Remote Permanent Shift-work

Senior Incident Response Consultant, Rapid Response

Leads high-pressure incident response engagements for organizations affected by cyberattacks, directing forensic investigations and coordinating with customer teams. Produces detailed reports mapped to MITRE ATT&CK, focusing on ransomware and business email compromise (BEC) incidents. Operates in a rapid-response environment with a rotating weekend-heavy schedule to support global customers.

Sophos United Kingdom
Remote Permanent

Senior Manager - Cyber Incident & Response - Consulting

Leads cyber incident response advisory and live incident management engagements for major organisations, focusing on improving resilience through preparedness planning, simulation exercises, and crisis management. Acts as a trusted adviser to senior stakeholders during high-impact security events and leads multidisciplinary teams in both proactive and reactive scenarios. Involves shaping client strategies, developing response playbooks, and contributing to business development and market growth of the cyber practice.

Oliver James London, United Kingdom £100,000 – £110,000 pa

Principal Consultant, Incident Response (Unit 42)

Leads high-stakes incident response engagements for clients, conducting forensic investigations across Windows, Linux, and macOS systems to identify breaches and attack vectors. Uses advanced tools like EnCase, FTK, and Splunk to analyze logs and memory artifacts, delivering actionable remediation strategies. Mentors junior consultants and collaborates with internal teams to strengthen client security postures.

Palo Alto Networks London, United Kingdom
Hybrid Permanent

Principal Consultant, Incident Response (Weekend Schedule)

Lead incident response engagements for clients, conducting forensic investigations and providing expert guidance on containment and remediation. Perform host-based analysis and log examination across Windows, Linux, and macOS systems to identify threats and attack vectors. Mentor junior consultants and collaborate with internal and external stakeholders to strengthen client security postures using tools like EnCase, FTK, Splunk, and SIFT.

Palo Alto Networks United Kingdom

SOC Manager

Lead and develop a Security Operations Centre within a public sector environment, defining strategy and operational roadmap while overseeing incident management, threat intelligence, and security monitoring. Manage cyber security tools, vendor relationships, and MSSP partnerships to strengthen national-level security operations. This role requires active SC clearance and experience in strategic SOC leadership.

NonStop Consulting Exeter, Devon, United Kingdom £800 – £850 pd

Level 3 SOC Analyst

This role involves leading complex cybersecurity incident investigations across endpoint, network, cloud, and identity environments, with a focus on proactive threat hunting and improving detection capabilities. The analyst will act as a technical escalation point during major incidents, mentor junior team members, and contribute to developing detection rules and automated workflows. The position supports a customer-facing SOC delivering managed security services.

Redline Group Aylesbury, Buckinghamshire, United Kingdom £60,000 – £70,000 pa
Hybrid Permanent Clearance Required

Cyber Security Engineer - MS Sentinel, Defender, SSO, PKI, SC-100/200, CISSP

This role involves strengthening cybersecurity across a global IT environment through hands-on engineering, incident response, and vulnerability management. You'll work with tools like MS Sentinel and MS Defender to monitor threats, remediate risks in Windows Server and Azure environments, and support major incidents. The position also includes designing secure infrastructure solutions and improving security posture through proactive risk assessment and technical leadership.

Comtecs London, United Kingdom £90,000 – £100,000 pa

Cyber Security Engineer

This role involves leading incident response, threat monitoring, and root-cause analysis while optimising SIEM and EDR systems like CrowdStrike Falcon and Microsoft Defender. The engineer will drive vulnerability management, implement Zero Trust principles, and secure cloud infrastructure using tools such as Intune, Entra ID, Palo Alto, and Mimecast. Collaboration with internal teams and penetration testers is key to strengthening the organisation's security posture within a global professional services environment.

Picture More Ec4M5Sb, United Kingdom £70,000 – £77,000 pa
Hybrid Permanent Clearance Required
Experis logo

Splunk SIEM Engineer

Role Title: Splunk SIEM EngineerDuration: contract to run until 30/11/2026Location: Knutsford. Hybrid, 3 days per week onsiteRate: up to £587.33 p/d Umbrella inside IR35Role purpose / summaryJoin us as Splunk SIEM Engineer where you must design, develop and improve software,...

Experis Knutsford, Cheshire, United Kingdom

Senior IT Security Analyst / Engineer

This role involves leading and operationalising key cybersecurity domains such as endpoint, network, and identity security, with a strong focus on hands-on management of tools like CrowdStrike and Zscaler. The analyst will conduct vulnerability assessments, threat-informed remediation, and incident response, using attacker behaviour and MITRE ATT&CK to prioritise actions. Collaboration with infrastructure, cloud, and identity teams ensures continuous improvement of the organisation's cyber defence posture through automation, detection tuning, and security investigations.

Prime Personnel UK Victoria, Greater London, London, SW1P 1BX, United Kingdom £75,000 – £90,000 pa
Hybrid Permanent Clearance Required

Interim Cyber Security Officer

This role involves providing senior-level technical leadership for a Security Operations Centre, with a focus on enhancing capabilities in endpoint detection and response using CrowdStrike Falcon and Splunk Enterprise Security. The candidate will lead configuration, incident response, threat hunting, and SOAR automation, while mentoring internal teams and improving security monitoring. The position requires deep expertise in EDR, SIEM, and security orchestration within a hybrid working environment in London.

Alois Technologies Limited London, United Kingdom £400 – £500 pd

Cyber Resilience Specialist

This role involves assessing cyber threats and vulnerabilities in the context of operational resilience, translating technical security risks into business service impacts, and supporting scenario testing and governance. The specialist will work across technology, security, and risk teams to strengthen resilience capabilities within a regulated environment. Key focus areas include service mapping, impact tolerance assessments, and providing actionable recommendations to enhance organisational resilience.

Hays Technology London, United Kingdom £600 pd
Remote Contract

SOC Manager

Lead and oversee the strategic direction of a Cyber Security Operations Centre, managing incident response, threat intelligence, and security operations. This role involves high-level governance, coordination with external vendors and MSSPs, and leading teams during major security incidents. The position requires a strategic leader rather than a hands-on analyst, with a focus on crisis management and security operations leadership.

Randstad Technologies Recruitment London, City And County Of the City Of London, United Kingdom £600 – £700 pd
Remote Contract Clearance Required

IT Security and Compliance Specialist

This role involves leading cybersecurity, risk, and compliance initiatives within a software services company. The specialist will manage security governance, conduct audits, perform risk assessments, and support incident response. They will act as a security advisor across both technical and business teams, ensuring alignment with regulatory standards and maintaining a strong security posture.

Head Resourcing Edinburgh, Alba / Scotland, United Kingdom £55,000 – £65,000 pa
Hybrid Permanent Clearance Required