Cyber Incident Response Lead

Reference: 4znjcx92rkpdf25pxu68

We are seeking an experienced Cyber Incident Response Lead to direct the identification, investigation, containment and recovery of complex cybersecurity incidents. You will provide senior technical leadership throughout the incident lifecycle, coordinating rapid and effective responses to threats affecting systems, networks, applications, cloud environments and sensitive data. The role will involve assessing alerts, validating incidents, determining scope and impact, developing containment strategies, and ensuring that recovery actions are completed safely and efficiently.

You will lead incident response activities across multidisciplinary teams, including security operations, infrastructure, engineering, risk, legal, communications and business stakeholders. Responsibilities will include establishing response priorities, allocating resources, maintaining accurate incident records, overseeing forensic investigations, preserving evidence and producing clear executive updates. You will also facilitate post-incident reviews, identify root causes, track remediation actions and use lessons learned to improve playbooks, detection capabilities, crisis processes and organisational resilience. Where required, you will support regulatory, customer and law-enforcement notifications in line with established procedures.

The successful candidate will have substantial experience in cyber incident response, digital forensics, threat investigation or a closely related security discipline, together with a proven record of leading high-severity incidents. You will be confident working under pressure, making sound risk-based decisions and communicating technical issues clearly to both specialist and non-technical audiences. Strong knowledge of incident response frameworks, threat intelligence, endpoint detection and response, SIEM platforms, network security, identity compromise and cloud technologies is expected. Experience developing response plans, conducting exercises and managing third-party responders would be advantageous. Relevant professional certifications, such as CISSP, GIAC, CISM or equivalent practical expertise, are desirable.

£66,000.00
Per annum
Added 09/09/2026
Reference: 4znjcx92rkpdf25pxu68

Other similar jobs

Identity and Access Management Lead

Added 11/09/2026

We are seeking an experienced Identity and Access Management Lead to define and deliver a secure, scalable IAM strategy across a complex technology environment. This role will provide technical leadership for identity governance, access management, authentication, privileged access, and directory services, ensuring that users have appropriate access at the right time while maintaining strong security and regulatory controls. You will lead the design, implementation, and continuous improvement of IAM solutions, including joiner, mover, and leaver processes, role-based access control, single sign-on, multi-factor authentication, privileged access management, and access certification. Working closely with information security, infrastructure, applications, compliance, and business stakeholders,...

Learn more

Cyber Operations Manager

Added 09/09/2026

We are seeking an experienced Cyber Operations Manager to lead and develop a high-performing security operations function. The successful candidate will oversee the monitoring, detection, investigation and response to cyber threats across the organisation’s technology environment. You will provide strategic direction while remaining engaged with operational priorities, ensuring that security controls, processes and services are effective, resilient and aligned with business objectives. This role will involve managing internal teams and third-party providers, setting service standards, and promoting a culture of continuous improvement. Key responsibilities will include overseeing security monitoring and incident response activities; coordinating the triage, containment and remediation of...

Learn more

Senior Manager, Global Cyber Security Incident Response (Global CSIRT)

Added 18/09/2026

We are seeking a Senior Manager, Global Cyber Security Incident Response to lead and evolve a global incident response capability. This role will be responsible for directing the identification, containment, investigation and recovery of significant cyber security incidents across a complex, international environment. You will provide calm, decisive leadership during high-impact events, coordinate technical and business stakeholders, and ensure that response activities protect critical services, data and customer trust. The role will also contribute to the development of a mature, intelligence-led and continuously improving Global CSIRT function. Key responsibilities include leading incident response teams and third-party partners through suspected and...

Learn more

Senior Associate, Cyber Security Analyst – Incident Response

Added 02/09/2026

We are seeking a Senior Associate, Cyber Security Analyst – Incident Response to join a dedicated security operations function. In this role, you will help protect critical systems, data and services by leading the investigation and response to cyber security incidents. You will work closely with technology, risk, infrastructure and business teams to identify threats, contain activity, recover affected environments and strengthen the organisation’s overall security posture. Key responsibilities include monitoring and analysing security alerts, endpoint activity, network traffic, identity events and other indicators of compromise. You will triage incidents, determine scope and severity, coordinate containment and eradication activities, and...

Learn more

Graduate Consultant, Cyber Incident Response: One Year Fixed Term Contract

Added 01/09/2026

Graduate Consultant, Cyber Incident Response: One Year Fixed Term Contract. An exciting opportunity is available for a recent graduate or early-career professional to begin a career in cyber incident response. Working as part of a specialist security team, you will support the investigation, management and resolution of cyber incidents affecting a range of systems, networks and users. This is a practical, learning-focused role suited to someone with a genuine interest in cybersecurity, strong analytical ability and a willingness to develop technical expertise. Your responsibilities will include assisting with the triage and investigation of suspected security incidents, reviewing alerts and log...

Learn more

Cyber Incident Response Manager

Added 25/08/2026

We are seeking an experienced Cyber Incident Response Manager to lead the identification, investigation and resolution of cyber security incidents across a complex technology environment. This role will manage the full incident response lifecycle, from preparation and detection through containment, eradication, recovery and post-incident review. You will provide calm, decisive leadership during high-impact events and help strengthen the organisation’s resilience against evolving cyber threats. Key responsibilities will include managing and developing incident response processes, playbooks and escalation procedures; coordinating technical response activities across security, infrastructure, applications, legal, compliance and communications teams; and ensuring incidents are accurately assessed, documented and reported....

Learn more

Head of Cyber Defence & Incident Response

Added 25/08/2026

We are seeking an experienced Head of Cyber Defence & Incident Response to lead the development and delivery of a resilient, intelligence-led cyber security capability. This senior role will provide strategic direction across security operations, threat detection, incident response, vulnerability management and cyber resilience, ensuring the organisation is prepared to prevent, identify, contain and recover from increasingly sophisticated threats. You will advise senior stakeholders on cyber risk, translate technical issues into clear business impacts, and promote a strong culture of security and continuous improvement. Key responsibilities will include leading and developing cyber defence and incident response teams; establishing and refining...

Learn more

Head of Cyber Defence & Incident Response

Added 20/08/2026

We are seeking a dynamic and experienced Head of Cyber Defence & Incident Response to lead our cyber security initiatives. This pivotal role involves developing and implementing robust incident response strategies to safeguard our organization against potential threats. The successful candidate will oversee the cyber defence team, ensuring the identification, containment, and remediation of security incidents. You will be responsible for establishing and maintaining incident response protocols, conducting threat assessments, and coordinating with cross-functional teams to enhance overall security posture. A key part of your role will involve staying abreast of emerging threats and trends in cyber security to proactively...

Learn more

Cyber Incident Response Manager

Added 18/08/2026

We are seeking a highly skilled Cyber Incident Response Manager to lead our organization's efforts in identifying, responding to, and mitigating cybersecurity incidents. In this pivotal role, you will be responsible for developing and implementing incident response plans and protocols to ensure effective management of security breaches. You will work closely with cross-functional teams to enhance overall security posture, conduct risk assessments, and coordinate incident response exercises. Your expertise in threat intelligence and forensic analysis will be crucial in investigating security incidents and providing actionable recommendations to prevent future occurrences. The ideal candidate will possess a strong background in cybersecurity,...

Learn more

Associate Manager - Cyber Security Incident Response

Added 18/08/2026

We are seeking a proactive and skilled Associate Manager - Cyber Security Incident Response to join our dynamic team. In this role, you will be responsible for leading incident response efforts, managing the investigation and resolution of security incidents, and ensuring that timely and effective responses are executed. Your expertise will be crucial in identifying vulnerabilities, assessing risks, and implementing strategies to mitigate potential threats. You will work closely with cross-functional teams to develop and refine incident response plans, ensuring alignment with industry best practices and compliance requirements. Your duties will include monitoring security alerts, performing in-depth analysis of incidents,...

Learn more

Cyber Digital Forensics & Incident Response Manager

Added 05/08/2026

We are seeking a highly skilled Cyber Digital Forensics & Incident Response Manager to lead digital investigations, manage incident response processes, and enhance our overall cyber resilience. In this role, you will oversee the identification, analysis, and remediation of security incidents, ensuring that all investigative activities are conducted thoroughly and in compliance with legal and regulatory requirements. You will work closely with technology teams and business stakeholders to develop and implement incident response plans, coordinate forensic investigations, and provide expert guidance during critical situations. The successful candidate will be responsible for ensuring the timely detection and response to potential threats,...

Learn more

Cyber Digital Forensics & Incident Response Manager

Added 28/07/2026

We are seeking a highly skilled Cyber Digital Forensics & Incident Response Manager to lead our cybersecurity team in investigating and responding to cyber incidents. In this pivotal role, you will be responsible for overseeing digital forensics investigations, managing incident response protocols, and ensuring the organization is prepared to handle cyber threats effectively. You will collaborate with cross-functional teams to develop and implement security policies, conduct risk assessments, and provide guidance on best practices to mitigate potential vulnerabilities. Your expertise will be crucial in analyzing data breaches, identifying the root causes of incidents, and developing strategies to prevent future occurrences....

Learn more

Advisory Engineer, Enterprise Product Security Incident Response Team (E-PSIRT)

Added 11/09/2026

We are seeking an Advisory Engineer to join an Enterprise Product Security Incident Response Team (E-PSIRT). In this role, you will help identify, assess, coordinate, and resolve security vulnerabilities affecting enterprise products, platforms, and services. You will act as a trusted technical adviser to engineering, product, infrastructure, and customer-facing teams, helping to ensure that security issues are managed consistently, efficiently, and in line with established response processes. Your responsibilities will include investigating reported vulnerabilities and security incidents, validating technical findings, assessing severity and potential business impact, and coordinating remediation activities across multiple stakeholders. You will contribute to vulnerability response plans,...

Learn more

Security Engineer – SecOps / Incident Response & Automation (GBP 350 per day outside IR35)

Added 03/09/2026

We are seeking an experienced Security Engineer to support Security Operations, Incident Response and security automation within a fast-paced technology environment. This contract opportunity offers a rate of GBP 350 per day, outside IR35, and is suited to a hands-on practitioner who can investigate security events, coordinate effective responses and improve the efficiency of operational security processes. The successful candidate will monitor, triage and investigate alerts from SIEM, endpoint detection and response, identity, cloud and network security platforms. You will lead or support the response to security incidents, including scoping impact, analysing logs and indicators of compromise, containing threats, coordinating...

Learn more

Senior SOC Analyst - Incident Response

Added 02/09/2026

We are seeking a Senior SOC Analyst – Incident Response to lead the investigation, containment, and resolution of complex cybersecurity incidents. You will operate as a senior member of a security operations team, providing expert guidance during active incidents and helping protect critical systems, applications, and data. The role requires strong analytical thinking, sound technical judgement, and the ability to remain calm and decisive in a fast-moving environment. Responsibilities include monitoring and triaging security alerts, investigating suspected compromises, conducting threat hunting, and coordinating end-to-end incident response activities. You will analyse events from SIEM, EDR, network, identity, cloud, and other security...

Learn more
At least 8 characters, 1 uppercase, 1 lowercase and 1 special character or number
Your file must be a doc, docx or pdf. No larger than 5MB.