Team Leader - Information Security Incident Response

Reference: 7tj44k04x4n3q29r9wu3

We are seeking an experienced Team Leader – Information Security Incident Response to lead the coordination and delivery of effective responses to cyber security incidents. This role will provide operational leadership to an incident response team, ensuring threats are identified, contained, investigated and resolved promptly. You will oversee the end-to-end incident management lifecycle, from initial triage and assessment through to recovery, post-incident review and the implementation of preventative improvements.

Key responsibilities will include leading the investigation of complex security incidents, coordinating technical and business stakeholders, and ensuring timely, accurate communication during major events. You will develop and maintain incident response procedures, playbooks and escalation processes, while supporting the continual improvement of security operations and organisational resilience. The role will also involve monitoring incident trends, producing management reports, contributing to risk assessments, and ensuring lessons learned are translated into practical security controls. You will help manage exercises and simulations, provide guidance during high-severity incidents, and maintain effective relationships with internal teams, specialist suppliers and relevant external parties.

The successful candidate will have substantial experience in cyber security incident response, security operations or a closely related discipline, together with proven experience leading or mentoring technical teams. You will have a strong understanding of incident management frameworks, threat intelligence, vulnerability management, digital forensics and common attack techniques. Experience using security information and event management, endpoint detection and response, case management and other security tooling is essential. Strong analytical, decision-making and communication skills are required, along with the ability to remain calm and provide clear direction in high-pressure situations. Relevant professional certifications or demonstrable equivalent experience would be advantageous. This is an opportunity to play a key role in strengthening security capability, improving response maturity and protecting critical information and services.

COMPETITIVE SALARY
Added 26/08/2026
Reference: 7tj44k04x4n3q29r9wu3

Team Leader - Information Security Incident Response

Leicester, England, United Kingdom Permanent Incident Response

Other similar jobs

Security Pen Tester - InfoSec

Added 05/08/2026

We are seeking a skilled Security Pen Tester to join our dynamic Information Security team. The successful candidate will be responsible for identifying vulnerabilities within our systems and applications through comprehensive penetration testing. You will conduct security assessments, develop testing methodologies, and provide actionable recommendations to enhance the security posture of our organization. Your expertise will be crucial in simulating real-world attacks to uncover potential weaknesses and improve our defenses against cyber threats. Key responsibilities include executing penetration tests on networks, web applications, and mobile platforms, as well as documenting findings in detailed reports. You will collaborate closely with development...

Learn more

Vulnerability Research Team Leader

Added 18/09/2026

We are seeking an experienced Vulnerability Research Team Leader to guide a specialist team responsible for identifying, analysing, and responsibly disclosing security vulnerabilities across operating systems, applications, embedded devices, and emerging technologies. You will provide technical direction, set research priorities, and help translate complex findings into practical recommendations for engineering, product, and security stakeholders. This role combines hands-on technical leadership with people management and strategic planning. Key responsibilities include defining and maintaining the team’s research roadmap; overseeing vulnerability discovery, exploit development, reverse engineering, fuzzing, and proof-of-concept creation; reviewing technical reports and ensuring findings are accurately assessed and documented; and coordinating...

Learn more

Advisory Engineer, Enterprise Product Security Incident Response Team (E-PSIRT)

Added 11/09/2026

We are seeking an Advisory Engineer to join an Enterprise Product Security Incident Response Team (E-PSIRT). In this role, you will help identify, assess, coordinate, and resolve security vulnerabilities affecting enterprise products, platforms, and services. You will act as a trusted technical adviser to engineering, product, infrastructure, and customer-facing teams, helping to ensure that security issues are managed consistently, efficiently, and in line with established response processes. Your responsibilities will include investigating reported vulnerabilities and security incidents, validating technical findings, assessing severity and potential business impact, and coordinating remediation activities across multiple stakeholders. You will contribute to vulnerability response plans,...

Learn more

Defence Security Virtual Practice Leader

Added 08/09/2026

We are seeking an experienced Defence Security Virtual Practice Leader to shape and lead a specialist security practice supporting complex defence and national security programmes. This senior role will provide strategic direction, technical leadership and operational oversight across virtualised environments, cloud platforms, secure networks and mission-critical systems. You will work with senior stakeholders, delivery teams and technical specialists to ensure security practices align with regulatory obligations, organisational priorities and the evolving threat landscape. Key responsibilities will include defining and maintaining the practice strategy, governance framework, standards and delivery roadmap; leading the design and assurance of secure virtualisation and cloud solutions;...

Learn more

SOC Manager (MSSP Leader) - Hybrid

Added 15/09/2026

An experienced SOC Manager is sought to lead and develop a high-performing Security Operations Centre within a managed security services environment. This hybrid role will oversee the delivery of 24/7 security monitoring, detection, investigation and response services for multiple customers, ensuring consistently high standards of operational performance, service quality and client satisfaction. The successful candidate will provide clear direction to SOC analysts, incident responders and technical specialists, while fostering a culture of collaboration, accountability and continuous improvement. Responsibilities will include managing day-to-day SOC operations, workforce planning, shift coverage, escalation procedures and incident response coordination. You will establish and monitor service-level...

Learn more

Embedded Cyber Detection and Response Deputy Team Lead

Added 18/08/2026

We are seeking a highly skilled and motivated individual to join our team as an Embedded Cyber Detection and Response Deputy Team Lead. In this role, you will be responsible for supporting the development and implementation of cyber detection and response strategies within embedded systems. Your primary duties will include leading a team of cybersecurity professionals, coordinating incident response efforts, and ensuring that our embedded systems are resilient against cyber threats. You will work closely with cross-functional teams to identify vulnerabilities, develop remediation strategies, and enhance our overall security posture. The ideal candidate will have a strong background in cybersecurity,...

Learn more

Security Engineer I, AWS Security Incident Response

Added 02/09/2026

We are seeking a Security Engineer I, AWS Security Incident Response to help protect cloud environments, investigate security events, and strengthen incident response capabilities. In this role, you will work with security operations, engineering, and infrastructure teams to identify, contain, and remediate threats affecting AWS accounts, services, and workloads. You will contribute to the development of repeatable processes that improve detection, response times, and overall cloud security resilience. Key responsibilities include monitoring and triaging security alerts, investigating suspicious activity across AWS services, and supporting incident response from initial analysis through containment, recovery, and post-incident review. You will assist with log...

Learn more

Security Engineer I, AWS Security Incident Response

Added 02/09/2026

We are seeking a Security Engineer I to support cloud security incident response and help protect critical systems, applications, and data. In this entry-level role, you will monitor, investigate, and respond to suspected security events across cloud environments, working closely with experienced security professionals and technical teams. You will contribute to the full incident lifecycle, including alert triage, evidence collection, containment, eradication, recovery, and post-incident review. Key responsibilities include analysing logs, alerts, and network or endpoint telemetry; investigating potential unauthorised access, malware, data exposure, and account compromise; documenting findings and maintaining accurate case records; and escalating incidents according to established...

Learn more

Senior Manager, Global Cyber Security Incident Response (Global CSIRT)

Added 18/09/2026

We are seeking a Senior Manager, Global Cyber Security Incident Response to lead and evolve a global incident response capability. This role will be responsible for directing the identification, containment, investigation and recovery of significant cyber security incidents across a complex, international environment. You will provide calm, decisive leadership during high-impact events, coordinate technical and business stakeholders, and ensure that response activities protect critical services, data and customer trust. The role will also contribute to the development of a mature, intelligence-led and continuously improving Global CSIRT function. Key responsibilities include leading incident response teams and third-party partners through suspected and...

Learn more

Security Engineer – SecOps / Incident Response & Automation (GBP 350 per day outside IR35)

Added 03/09/2026

We are seeking an experienced Security Engineer to support Security Operations, Incident Response and security automation within a fast-paced technology environment. This contract opportunity offers a rate of GBP 350 per day, outside IR35, and is suited to a hands-on practitioner who can investigate security events, coordinate effective responses and improve the efficiency of operational security processes. The successful candidate will monitor, triage and investigate alerts from SIEM, endpoint detection and response, identity, cloud and network security platforms. You will lead or support the response to security incidents, including scoping impact, analysing logs and indicators of compromise, containing threats, coordinating...

Learn more

Senior Associate, Cyber Security Analyst – Incident Response

Added 02/09/2026

We are seeking a Senior Associate, Cyber Security Analyst – Incident Response to join a dedicated security operations function. In this role, you will help protect critical systems, data and services by leading the investigation and response to cyber security incidents. You will work closely with technology, risk, infrastructure and business teams to identify threats, contain activity, recover affected environments and strengthen the organisation’s overall security posture. Key responsibilities include monitoring and analysing security alerts, endpoint activity, network traffic, identity events and other indicators of compromise. You will triage incidents, determine scope and severity, coordinate containment and eradication activities, and...

Learn more

Incident Response Engineer, UK Security Operations, Hampshire

Added 26/08/2026

We are seeking an Incident Response Engineer to join a UK-based Security Operations function in Hampshire. This role will help protect critical systems, services and information by identifying, investigating and responding to cyber security incidents. You will work as part of a collaborative team responsible for monitoring threats, assessing their impact and coordinating effective containment and recovery activities across a complex technical environment. Your responsibilities will include triaging alerts and reported security events, conducting investigations using security information and event management, endpoint detection and response, network monitoring and vulnerability management tools, and analysing logs, malware and other forensic evidence. You...

Learn more

Senior Security Consultant (Incident Response)

Added 26/08/2026

We are seeking a Senior Security Consultant (Incident Response) to lead and support the investigation, containment and recovery of complex cybersecurity incidents. This role will work closely with clients and internal stakeholders to provide expert guidance throughout the incident lifecycle, from initial triage and scoping through to remediation, lessons learned and strategic improvement. You will be expected to operate confidently in high-pressure situations, communicate clearly with both technical and non-technical audiences, and help organisations strengthen their resilience against future threats. Key responsibilities include leading or contributing to digital forensics and incident response engagements; analysing endpoint, network, identity, cloud and application...

Learn more

Product Security Incident Response Manager (m/f/d)

Added 25/08/2026

We are seeking a Product Security Incident Response Manager (m/f/d) to lead the coordination and continuous improvement of security incident response for products, platforms, and supporting services. In this role, you will manage the response to vulnerabilities, suspected compromises, and product security incidents from initial assessment through containment, remediation, recovery, and post-incident review. You will work closely with engineering, product management, cloud operations, legal, privacy, communications, and customer-facing teams to ensure that incidents are handled efficiently, consistently, and with clear ownership. Your responsibilities will include establishing and maintaining incident response processes, playbooks, severity models, escalation paths, and communication procedures. You...

Learn more

Senior Security Incident Response Engineer

Added 20/08/2026

We are seeking a highly skilled Senior Security Incident Response Engineer to join our dynamic cybersecurity team. In this role, you will be at the forefront of our incident response efforts, tasked with identifying, managing, and mitigating security incidents across our organization. You will collaborate closely with cross-functional teams to develop and implement incident response plans, ensuring rapid recovery and minimal impact on business operations. Your expertise will be critical in conducting thorough investigations, analyzing security breaches, and producing detailed reports that outline the findings, recommendations, and lessons learned. The ideal candidate will have a strong background in cybersecurity, with...

Learn more
At least 8 characters, 1 uppercase, 1 lowercase and 1 special character or number
Your file must be a doc, docx or pdf. No larger than 5MB.