Lead Threat Response Operations Analyst

Reference: sxbm5soplrbnp2ln2ynn

We are seeking a Lead Threat Response Operations Analyst to provide senior-level expertise in the identification, investigation, and containment of cyber threats. The role will lead day-to-day threat response activities, coordinate the analysis of security events, and ensure incidents are managed efficiently from initial detection through to remediation and post-incident review. You will work closely with security operations, infrastructure, application, risk, and business teams to assess potential impact, prioritise action, and reduce the likelihood of recurrence.

Key responsibilities include directing the investigation of complex and high-severity incidents; validating alerts and correlating intelligence from endpoint, network, identity, cloud, and application sources; developing and refining detection and response procedures; and providing clear updates to technical and senior stakeholders. You will contribute to threat hunting, forensic analysis, vulnerability-driven response, and the continuous improvement of playbooks, monitoring rules, automation, and operational metrics. The role will also involve mentoring analysts, supporting capability development, participating in an on-call or escalation rota where required, and ensuring that incident records, lessons learned, and control improvements are documented to a high standard.

Applicants should have substantial experience in security operations, incident response, threat hunting, or a related discipline, with proven experience leading investigations in a complex technology environment. Strong knowledge of security information and event management, endpoint detection and response, network analysis, identity security, cloud platforms, and common attack techniques is expected. Experience with scripting or automation, threat intelligence frameworks, digital forensics, and recognised incident response methodologies would be advantageous. You will need excellent analytical and communication skills, sound judgement under pressure, and the ability to translate technical findings into practical business risks and recommendations. Relevant professional certifications or equivalent practical experience are desirable.

COMPETITIVE SALARY
Added 14/09/2026
Reference: sxbm5soplrbnp2ln2ynn

Lead Threat Response Operations Analyst

Sandwich, England, United Kingdom Permanent Incident Response

Other similar jobs

Senior Cyber Threat Detection and Response Analyst

Added 14/09/2026

We are seeking a Senior Cyber Threat Detection and Response Analyst to lead the identification, investigation and containment of sophisticated cyber threats across a complex technology environment. You will monitor security events, analyse alerts and intelligence, and coordinate effective responses to incidents affecting networks, endpoints, cloud services, applications and critical data. The role will involve working closely with security engineering, infrastructure, risk and operational teams to strengthen defensive capabilities and reduce organisational exposure. Key responsibilities include developing and tuning detection rules, use cases and correlation logic; conducting advanced threat hunting across security telemetry; investigating indicators of compromise and suspicious activity;...

Learn more

Threat Intelligence Analyst, Threat Disruption

Added 25/08/2026

As a Threat Intelligence Analyst, Threat Disruption, you will help identify, assess and disrupt online threats that may affect individuals, organisations, communities or critical services. You will monitor a wide range of open, closed and technical information sources to uncover emerging threats, malicious activity, criminal networks and patterns of abuse. Using structured analytical techniques, you will turn complex data into clear, timely and actionable intelligence for operational, investigative and strategic audiences. Your responsibilities will include researching threat actors, infrastructure, tactics, techniques and procedures; assessing the credibility, intent, capability and potential impact of threats; and producing concise intelligence reports, alerts, briefings...

Learn more

Threat Intelligence Analyst, Threat Disruption

Added 20/08/2026

We are seeking a skilled Threat Intelligence Analyst specializing in Threat Disruption to join our dynamic team. In this role, you will be responsible for identifying, analyzing, and mitigating emerging threats to safeguard our organization’s information assets. You will leverage advanced analytical techniques to gather intelligence from various sources, including open-source data, dark web monitoring, and internal threat data. You will collaborate closely with cybersecurity teams to develop proactive strategies for disrupting threats before they can impact our operations. Your key responsibilities will include conducting in-depth threat assessments, producing actionable intelligence reports, and developing threat profiles that inform our defensive...

Learn more

Incident Response Engineer, UK Security Operations, Hampshire

Added 26/08/2026

We are seeking an Incident Response Engineer to join a UK-based Security Operations function in Hampshire. This role will help protect critical systems, services and information by identifying, investigating and responding to cyber security incidents. You will work as part of a collaborative team responsible for monitoring threats, assessing their impact and coordinating effective containment and recovery activities across a complex technical environment. Your responsibilities will include triaging alerts and reported security events, conducting investigations using security information and event management, endpoint detection and response, network monitoring and vulnerability management tools, and analysing logs, malware and other forensic evidence. You...

Learn more

Managed Security Operations Centre (SOC) and Incident Response Services Agreement

Added 29/07/2026

An exciting opportunity has arisen for a skilled professional to lead the delivery and management of Security Operations Centre (SOC) and Incident Response services. The successful candidate will be responsible for overseeing a team of security analysts, ensuring proactive monitoring, detection, and response to security incidents across various client environments. This role requires maintaining high standards of service delivery, ensuring compliance with relevant frameworks, and continuous improvement of security operations processes. Key responsibilities include managing and developing SOC processes, collaborating with stakeholders to assess risk and implement mitigation strategies, and coordinating effective incident response and recovery actions. You will be...

Learn more

Cyber Incident Response Lead

Added 09/09/2026

We are seeking an experienced Cyber Incident Response Lead to direct the identification, investigation, containment and recovery of complex cybersecurity incidents. You will provide senior technical leadership throughout the incident lifecycle, coordinating rapid and effective responses to threats affecting systems, networks, applications, cloud environments and sensitive data. The role will involve assessing alerts, validating incidents, determining scope and impact, developing containment strategies, and ensuring that recovery actions are completed safely and efficiently. You will lead incident response activities across multidisciplinary teams, including security operations, infrastructure, engineering, risk, legal, communications and business stakeholders. Responsibilities will include establishing response priorities, allocating resources,...

Learn more

Embedded Cyber Detection and Response Deputy Team Lead

Added 18/08/2026

We are seeking a highly skilled and motivated individual to join our team as an Embedded Cyber Detection and Response Deputy Team Lead. In this role, you will be responsible for supporting the development and implementation of cyber detection and response strategies within embedded systems. Your primary duties will include leading a team of cybersecurity professionals, coordinating incident response efforts, and ensuring that our embedded systems are resilient against cyber threats. You will work closely with cross-functional teams to identify vulnerabilities, develop remediation strategies, and enhance our overall security posture. The ideal candidate will have a strong background in cybersecurity,...

Learn more

Lead Threat Intelligence Analyst

Added 11/09/2026

We are seeking a Lead Threat Intelligence Analyst to drive the development and delivery of actionable intelligence that strengthens security decision-making and improves organisational resilience. In this role, you will lead the collection, analysis, and dissemination of strategic, operational, and tactical threat intelligence, helping security teams understand emerging risks, adversary behaviours, and potential impacts to critical systems and business operations. You will manage intelligence requirements, establish effective collection strategies, and analyse information from open-source, commercial, internal, and technical sources. Responsibilities include monitoring threat actors, campaigns, vulnerabilities, and geopolitical developments; producing high-quality reports, briefings, and alerts for technical and senior audiences;...

Learn more

Embedded Senior Operations Officer - Global Security Operations Centre

Added 09/09/2026

We are seeking an experienced Embedded Senior Operations Officer to support the effective delivery of a Global Security Operations Centre (GSOC). This role will provide security monitoring, intelligence analysis and operational coordination in a fast-paced, international environment. You will act as a trusted point of contact for security-related matters, helping to protect people, assets, information and business operations across multiple locations. Key responsibilities will include monitoring global security, safety and threat information; assessing incidents and emerging risks; and producing clear, timely notifications, briefings and situation reports. You will manage and escalate incidents in accordance with established procedures, coordinate responses with...

Learn more

Senior SOC Analyst - Incident Response

Added 02/09/2026

We are seeking a Senior SOC Analyst – Incident Response to lead the investigation, containment and resolution of complex cybersecurity incidents across a diverse technology environment. You will act as a senior escalation point within the Security Operations Centre, providing expert analysis during high-impact events and helping to protect critical systems, data and services. The role will involve working closely with infrastructure, cloud, engineering, risk and business teams to coordinate effective responses and minimise operational disruption. Your responsibilities will include monitoring and triaging alerts from SIEM, EDR, network, identity and cloud security platforms; conducting in-depth analysis of logs, endpoint activity,...

Learn more

Senior SOC Analyst - Incident Response

Added 02/09/2026

We are seeking a Senior SOC Analyst – Incident Response to lead the investigation, containment, and resolution of complex cybersecurity incidents. You will operate as a senior member of a security operations team, providing expert guidance during active incidents and helping protect critical systems, applications, and data. The role requires strong analytical thinking, sound technical judgement, and the ability to remain calm and decisive in a fast-moving environment. Responsibilities include monitoring and triaging security alerts, investigating suspected compromises, conducting threat hunting, and coordinating end-to-end incident response activities. You will analyse events from SIEM, EDR, network, identity, cloud, and other security...

Learn more

Senior SOC Analyst - Incident Response

Added 02/09/2026

We are seeking a Senior SOC Analyst – Incident Response to lead the investigation, containment and resolution of complex cybersecurity incidents. In this role, you will act as a senior escalation point within the security operations function, coordinating response activities across technical teams and providing clear, timely updates to relevant stakeholders. You will analyse alerts and events from SIEM, EDR, network security and cloud platforms, identify indicators of compromise, determine root cause and assess the scope and impact of incidents. Your responsibilities will include developing and executing incident response procedures, conducting forensic investigations, performing threat hunting and supporting malware and...

Learn more

Senior Associate, Cyber Security Analyst – Incident Response

Added 02/09/2026

We are seeking a Senior Associate, Cyber Security Analyst – Incident Response to join a dedicated security operations function. In this role, you will help protect critical systems, data and services by leading the investigation and response to cyber security incidents. You will work closely with technology, risk, infrastructure and business teams to identify threats, contain activity, recover affected environments and strengthen the organisation’s overall security posture. Key responsibilities include monitoring and analysing security alerts, endpoint activity, network traffic, identity events and other indicators of compromise. You will triage incidents, determine scope and severity, coordinate containment and eradication activities, and...

Learn more

Senior SOC Analyst - Incident Response

Added 02/09/2026

We are seeking a Senior SOC Analyst – Incident Response to lead the investigation, containment, and resolution of complex cybersecurity incidents. In this role, you will act as a senior point of escalation within the Security Operations Centre, providing expert analysis and guidance during high-impact events. You will monitor and investigate alerts across endpoint, network, cloud, identity, and application environments, using SIEM, EDR, threat intelligence, and other security technologies to identify malicious activity and assess business risk. You will coordinate incident response activities from initial triage through eradication, recovery, and post-incident review. Responsibilities include developing and refining detection rules, conducting...

Learn more

Senior SOC Analyst - Incident Response

Added 02/09/2026

We are seeking a Senior SOC Analyst – Incident Response to lead the investigation, containment, and resolution of complex cybersecurity incidents. You will act as a senior point of escalation within the Security Operations Centre, providing expert guidance during high-impact events and helping strengthen the organisation’s overall incident response capability. The role involves working closely with security engineering, infrastructure, application, risk, and compliance teams to protect critical systems, data, and services. Your responsibilities will include monitoring and analysing alerts from SIEM, EDR, network, cloud, identity, and threat intelligence platforms; validating suspected incidents; performing detailed investigation and forensic analysis; and coordinating...

Learn more
At least 8 characters, 1 uppercase, 1 lowercase and 1 special character or number
Your file must be a doc, docx or pdf. No larger than 5MB.