Latest Incident Response Jobs

Spotlight
Lab 1 logo

Senior Data Engineer

This role involves designing, building, and operating scalable batch and streaming data pipelines that transform vast, unstructured exposed data into reliable, queryable intelligence. The Senior Data Engineer will own end-to-end data workflows, ensure data quality and model readiness, and collaborate closely with ML teams on feature engineering. The position is central to enabling analytics and AI capabilities on a platform that detects corporate data exposure across supply chains.

Lab 1 London, Greater London, United Kingdom £85,000 – £125,000 pa
Hybrid Permanent
CrowdStrike logo

Incident Response Consultant - Weekend Shift , GBR)

Lead and conduct incident response engagements for high-profile cybersecurity breaches, performing forensic analysis across Windows, Mac, and Linux systems. Hunt for advanced threats using AI-native tools, analyze network and host data, and produce detailed reports for legal and executive stakeholders. Work weekends in a collaborative, mission-driven environment focused on stopping breaches at scale.

CrowdStrike United Kingdom
Remote Permanent Shift-work

Senior Incident Response Consultant, Rapid Response

This role involves leading high-pressure incident response engagements for organizations affected by cyberattacks, primarily focusing on ransomware and business email compromise (BEC) incidents. The Senior Incident Response Consultant will direct forensic investigations, manage customer communications, and produce detailed reports mapped to the MITRE ATT&CK framework. The position emphasizes leadership, technical analysis, and mentoring junior team members during rapid response scenarios.

Sophos United Kingdom
Remote Permanent

Cyber Security Engineer - Incident Response & Crisis Simulation within UK

Design and build realistic cyber incident response and crisis simulation labs within a gamified learning platform. Research emerging threats and translate technical concepts into engaging, accessible content for both technical and non-technical audiences. Collaborate with product and cyber teams to expand defensive security training offerings.

Immersive United Kingdom
Remote Permanent

Principal Consultant, Incident Response (Unit 42)

Leads high-stakes incident response engagements for clients, conducting forensic investigations across Windows, Linux, and macOS systems to identify breaches and attack vectors. Uses advanced tools like EnCase, FTK, and Splunk to analyze logs and memory artifacts, delivering actionable remediation strategies. Mentors junior consultants and collaborates with internal teams to strengthen client security postures.

Palo Alto Networks London, United Kingdom
Hybrid Permanent

Principal Consultant, Incident Response (Weekend Schedule)

Our MissionAt Palo Alto Networks®, we’re united by a shared mission—to protect our digital way of life. We thrive at the intersection of innovation and impact, solving real-world problems with cutting-edge technology and bold thinking. Here, everyone has a voice,...

Palo Alto Networks United Kingdom

Level 3 SOC Analyst

This role involves leading complex cybersecurity incident investigations across endpoint, network, cloud, and identity environments, with a focus on proactive threat hunting and improving detection capabilities. The analyst will act as a technical escalation point during major incidents, mentor junior team members, and contribute to developing detection rules and automated workflows. The position supports a customer-facing SOC delivering managed security services.

Redline Group Aylesbury, Buckinghamshire, United Kingdom £60,000 – £70,000 pa
Hybrid Permanent Clearance Required

Operational Resilience Analyst

The role involves developing and maintaining Barclays' operational resilience strategy, focusing on recovery planning, incident management, and compliance with regulatory standards. You'll enhance crisis response capabilities, conduct testing, and provide governance reporting to ensure critical services can withstand disruptions. Collaboration with stakeholders across technology, operations, and control functions is key to identifying risks, driving improvements, and strengthening resilience across the organisation.

Barclays United Kingdom
Hybrid Permanent
Experis logo

SOC Analyst

This SOC Analyst role involves real-time monitoring, triage, and incident response within a modern enterprise security environment. The candidate will investigate security events, fine-tune detection rules, and collaborate with internal teams to strengthen security operations. Focus is on proactive threat detection, incident documentation, and continuous improvement of SOC processes using tools like Microsoft Sentinel and Microsoft Defender.

Experis London, City And County Of the City Of London, United Kingdom £400 – £500 pd
Hybrid Contract Clearance Required
Bridewell logo

OT Lead

This role involves leading the development and growth of Bridewell's OT Cyber Security practice, shaping the strategic vision and service offerings across OT consulting, managed security, incident response, and engineering. The OT Lead will act as a senior figurehead, building client relationships and guiding cross-functional teams to deliver high-impact security outcomes in critical sectors.

Bridewell London, United Kingdom
Hybrid Permanent Clearance Required
Experis logo

Splunk SIEM Engineer

Role Title: Splunk SIEM EngineerDuration: contract to run until 30/11/2026Location: Knutsford. Hybrid, 3 days per week onsiteRate: up to £587.33 p/d Umbrella inside IR35Role purpose / summaryJoin us as Splunk SIEM Engineer where you must design, develop and improve software,...

Experis Knutsford, Cheshire, United Kingdom

Senior SOC Analyst / Leeds

This role involves end-to-end investigation of security incidents, proactive threat hunting, and detection engineering within a modern Microsoft security environment. The analyst will monitor cloud, endpoint, identity, and network security events using tools like Microsoft Sentinel and Defender XDR. Responsibilities also include vulnerability management, alert tuning, and contributing to cyber defence strategies across a 24/7 shift pattern with remote night shifts.

Interface Recruitment Leeds, West Yorkshire, United Kingdom £58,600 pa
Hybrid Permanent

Senior SOC Analyst / Bristol

This role involves end-to-end investigation and management of security incidents within a modern Microsoft security environment. The analyst will conduct proactive threat hunting, perform detection engineering, and optimise security tooling using platforms like Microsoft Sentinel and Defender XDR. The position supports vulnerability management, compliance, and cyber defence across cloud, endpoint, identity, and network domains.

Interface Recruitment Bristol, Bristol (county), United Kingdom £58,600 pa
Hybrid Permanent
HAYS Specialist Recruitment logo

Senior Security Analyst

This role involves proactive security monitoring, incident response, and vulnerability management across a hybrid on-premises and cloud environment. The analyst will investigate security events, improve security controls, and communicate findings to technical and non-technical stakeholders. The position reports directly to the CISO and supports the organisation's broader cyber resilience strategy.

HAYS Specialist Recruitment Rh12Nl, RH1 2NL, United Kingdom £55,000 – £61,000 pa
Hybrid Permanent

Senior IT Security Analyst / Engineer

This role involves leading and operationalising key cybersecurity domains such as endpoint, network, and identity security, with a strong focus on hands-on management of tools like CrowdStrike and Zscaler. The analyst will conduct vulnerability assessments, threat-informed remediation, and incident response, using attacker behaviour and MITRE ATT&CK to prioritise actions. Collaboration with infrastructure, cloud, and identity teams ensures continuous improvement of the organisation's cyber defence posture through automation, detection tuning, and security investigations.

Prime Personnel UK Victoria, Greater London, London, SW1P 1BX, United Kingdom £75,000 – £90,000 pa
Hybrid Permanent Clearance Required

Interim Cyber Security Officer

This role involves providing senior-level technical leadership for a Security Operations Centre, with a focus on enhancing capabilities in endpoint detection and response using CrowdStrike Falcon and Splunk Enterprise Security. The candidate will lead configuration, incident response, threat hunting, and SOAR automation, while mentoring internal teams and improving security monitoring. The position requires deep expertise in EDR, SIEM, and security orchestration within a hybrid working environment in London.

Alois Technologies Limited London, United Kingdom £400 – £500 pd