Cyber Incident Operations Lead

Reference: 8edj0r475wh1bb6eamjp

We are seeking a Cyber Incident Operations Lead to oversee the detection, response and resolution of cyber security incidents across a complex technology environment. This role will provide operational leadership during high-impact events, coordinate technical and business stakeholders, and ensure incidents are managed efficiently from initial triage through to recovery and closure. You will act as a senior point of escalation, helping to protect critical services, sensitive information and organisational resilience.

Key responsibilities include leading the incident response process, assessing severity and business impact, assigning appropriate response teams, and maintaining clear communication with technical specialists, senior leaders and relevant third parties. You will coordinate investigations into security alerts, suspected breaches, malware, unauthorised access, data loss and other cyber events. The role will also oversee the development and testing of incident response playbooks, improve escalation procedures, track incident metrics, and ensure accurate, timely documentation. Following major incidents, you will lead post-incident reviews, identify root causes, and drive corrective actions to reduce the likelihood and impact of future events.

The successful candidate will have substantial experience in cyber security operations, incident response or a closely related discipline, including hands-on experience managing complex or high-severity incidents. You will be confident working with security monitoring, endpoint detection, identity, network and vulnerability management technologies, and have a strong understanding of threat intelligence and attack techniques. Experience with recognised security frameworks and standards, such as NIST or ISO 27001, is desirable. Strong analytical, communication and decision-making skills are essential, along with the ability to remain calm under pressure, manage competing priorities and influence stakeholders at all levels. Relevant professional certifications in cyber security, incident handling or service management would be advantageous.

£59,000.00 - £74,000.00
Per annum
Added 17/09/2026
Reference: 8edj0r475wh1bb6eamjp

Other similar jobs

Cyber Security Vulnerability Lead

Added 03/09/2026

We are seeking an experienced Cyber Security Vulnerability Lead to strengthen and coordinate vulnerability management across a complex technology environment. You will lead the identification, assessment, prioritisation and remediation of security vulnerabilities affecting infrastructure, applications, cloud services, endpoints and third-party platforms. Working closely with security operations, technology, architecture, engineering and risk teams, you will help reduce cyber risk and ensure vulnerabilities are managed consistently, transparently and within agreed timescales. Your responsibilities will include owning the vulnerability management framework, policies, standards and operating procedures; overseeing regular vulnerability scanning and validation activities; analysing findings from automated tools, penetration tests, threat intelligence and...

Learn more

Op Cyber Threat Intelligence Analyst

Added 31/07/2026

We are seeking a skilled Op Cyber Threat Intelligence Analyst to join our dynamic team. In this role, you will be responsible for monitoring, analyzing, and interpreting cyber threat data to identify vulnerabilities and develop proactive strategies to mitigate risks. Your primary duties will include gathering intelligence on emerging threats, assessing the potential impact on our systems, and providing actionable insights to enhance our security posture. You will collaborate closely with cross-functional teams to ensure the implementation of effective security measures and contribute to the overall cyber defense strategy. The ideal candidate will possess a strong understanding of threat intelligence...

Learn more

Cyber Incident Operations Lead

Added 29/07/2026

We are seeking a highly skilled Cyber Incident Operations Lead to join our dynamic team. The successful candidate will be responsible for leading the incident response team in the identification, containment, eradication, and recovery from cybersecurity incidents. This role involves developing and maintaining incident response plans, conducting post-incident reviews, and ensuring the organization is prepared for potential threats through regular training and simulations. The Cyber Incident Operations Lead will collaborate with cross-functional teams to enhance the overall security posture and facilitate effective communication during incidents. The ideal candidate will have a deep understanding of cybersecurity frameworks and best practices, along...

Learn more

Cyber Incident Operations Lead

Added 29/07/2026

We are seeking a highly skilled Cyber Incident Operations Lead to enhance our proactive defense strategies and coordinate incident response efforts. In this critical role, you will oversee the detection, analysis, and response to cyber incidents, ensuring timely resolution and minimal impact on operations. You will lead a team of cybersecurity professionals, driving incident management processes and facilitating collaboration across departments. Your expertise will be essential in developing and implementing incident response plans, conducting post-incident reviews, and refining threat intelligence practices to bolster organizational resilience. The ideal candidate will possess in-depth knowledge of cyber threats, vulnerabilities, and mitigation techniques, along...

Learn more

Incident Response Engineer, UK Security Operations, Hampshire

Added 26/08/2026

We are seeking an Incident Response Engineer to join a UK-based Security Operations function in Hampshire. This role will help protect critical systems, services and information by identifying, investigating and responding to cyber security incidents. You will work as part of a collaborative team responsible for monitoring threats, assessing their impact and coordinating effective containment and recovery activities across a complex technical environment. Your responsibilities will include triaging alerts and reported security events, conducting investigations using security information and event management, endpoint detection and response, network monitoring and vulnerability management tools, and analysing logs, malware and other forensic evidence. You...

Learn more

Managed Security Operations Centre (SOC) and Incident Response Services Agreement

Added 29/07/2026

An exciting opportunity has arisen for a skilled professional to lead the delivery and management of Security Operations Centre (SOC) and Incident Response services. The successful candidate will be responsible for overseeing a team of security analysts, ensuring proactive monitoring, detection, and response to security incidents across various client environments. This role requires maintaining high standards of service delivery, ensuring compliance with relevant frameworks, and continuous improvement of security operations processes. Key responsibilities include managing and developing SOC processes, collaborating with stakeholders to assess risk and implement mitigation strategies, and coordinating effective incident response and recovery actions. You will be...

Learn more

Cyber Incident Lead

Added 14/09/2026

We are seeking an experienced Cyber Incident Lead to oversee the effective identification, management and resolution of cyber security incidents across a complex technology environment. You will lead the incident response function, coordinating activity from initial detection through containment, eradication, recovery and post-incident review. Working closely with security operations, infrastructure, technology, risk, legal and business stakeholders, you will ensure incidents are handled promptly, consistently and with clear communication throughout. Key responsibilities will include assessing and prioritising alerts and incidents, directing investigations, maintaining accurate incident records and providing timely updates to senior stakeholders. You will coordinate technical and business response teams...

Learn more

Cyber Incident Response Lead

Added 09/09/2026

We are seeking an experienced Cyber Incident Response Lead to direct the identification, investigation, containment and recovery of complex cybersecurity incidents. You will provide senior technical leadership throughout the incident lifecycle, coordinating rapid and effective responses to threats affecting systems, networks, applications, cloud environments and sensitive data. The role will involve assessing alerts, validating incidents, determining scope and impact, developing containment strategies, and ensuring that recovery actions are completed safely and efficiently. You will lead incident response activities across multidisciplinary teams, including security operations, infrastructure, engineering, risk, legal, communications and business stakeholders. Responsibilities will include establishing response priorities, allocating resources,...

Learn more

Embedded Senior Operations Officer - Global Security Operations Centre

Added 09/09/2026

We are seeking an experienced Embedded Senior Operations Officer to support the effective delivery of a Global Security Operations Centre (GSOC). This role will provide security monitoring, intelligence analysis and operational coordination in a fast-paced, international environment. You will act as a trusted point of contact for security-related matters, helping to protect people, assets, information and business operations across multiple locations. Key responsibilities will include monitoring global security, safety and threat information; assessing incidents and emerging risks; and producing clear, timely notifications, briefings and situation reports. You will manage and escalate incidents in accordance with established procedures, coordinate responses with...

Learn more

Cyber Defense Incident Responder - Assistant Director

Added 18/09/2026

We are seeking a Cyber Defense Incident Responder – Assistant Director to lead the identification, investigation, containment, and recovery of cybersecurity incidents across a complex technology environment. This senior role will provide operational leadership to incident response activities, helping protect critical systems, data, and services from evolving cyber threats. You will oversee the coordination of high-severity incidents, ensure timely escalation, and support clear communication with technical teams, senior stakeholders, and relevant external parties. Key responsibilities include developing and maintaining incident response procedures, playbooks, and escalation frameworks; directing investigations into suspected security breaches, malware infections, unauthorized access, and other cyber events;...

Learn more

Cyber Defense Incident Responder - Associate Director

Added 18/09/2026

We are seeking a Cyber Defense Incident Responder – Associate Director to lead the detection, investigation, containment, and resolution of complex cybersecurity incidents. This senior role will provide technical direction during high-impact events, coordinate response activities across security, technology, risk, legal, and business teams, and help strengthen the organisation’s overall cyber resilience. The successful candidate will act as a trusted escalation point for sophisticated threats, ensuring incidents are managed efficiently, documented accurately, and resolved in line with established procedures and regulatory expectations. Key responsibilities include leading investigations involving malware, ransomware, phishing, insider threats, account compromise, data exposure, and advanced persistent...

Learn more

Cyber Defense Incident Responder - Associate Director

Added 18/09/2026

We are seeking a Cyber Defense Incident Responder – Associate Director to lead the identification, investigation, containment, and remediation of complex cybersecurity incidents. This role will provide senior technical direction during high-impact events, helping to protect critical systems, sensitive information, and business operations. You will work closely with security operations, threat intelligence, digital forensics, infrastructure, application, and risk teams to coordinate effective incident response across the organisation. Key responsibilities include directing the end-to-end response to suspected and confirmed security incidents; assessing alerts and evidence to determine scope, severity, and business impact; developing containment, eradication, and recovery strategies; and ensuring that...

Learn more

Cyber Defense Incident Responder - Associate Director

Added 18/09/2026

We are seeking a Cyber Defense Incident Responder – Associate Director to lead the identification, investigation, containment, and resolution of sophisticated cybersecurity incidents. This role will provide senior-level technical direction during high-impact events, coordinate response activities across security, technology, risk, legal, and business teams, and help strengthen the organisation’s overall cyber resilience. The successful candidate will be comfortable operating in a fast-paced environment where sound judgment, clear communication, and decisive action are essential. Responsibilities include managing the end-to-end incident response lifecycle, including detection triage, scoping, forensic investigation, threat containment, eradication, recovery, and post-incident review. You will analyse security alerts and...

Learn more

Senior Manager, Global Cyber Security Incident Response (Global CSIRT)

Added 18/09/2026

We are seeking a Senior Manager, Global Cyber Security Incident Response to lead and evolve a global incident response capability. This role will be responsible for directing the identification, containment, investigation and recovery of significant cyber security incidents across a complex, international environment. You will provide calm, decisive leadership during high-impact events, coordinate technical and business stakeholders, and ensure that response activities protect critical services, data and customer trust. The role will also contribute to the development of a mature, intelligence-led and continuously improving Global CSIRT function. Key responsibilities include leading incident response teams and third-party partners through suspected and...

Learn more

Cyber Defense Incident Responder - Associate Director

Added 18/09/2026

We are seeking a Cyber Defense Incident Responder – Associate Director to lead the identification, investigation, containment, and resolution of complex cybersecurity incidents. This role will provide senior-level direction during high-impact events, helping protect critical systems, data, and business operations from evolving cyber threats. The successful candidate will combine strong technical expertise with sound judgment, clear communication, and the ability to coordinate effectively across security, technology, risk, legal, and business teams. Key responsibilities include overseeing the end-to-end incident response lifecycle, from triage and forensic investigation through containment, eradication, recovery, and post-incident review. You will lead investigations into malware, ransomware, phishing,...

Learn more
At least 8 characters, 1 uppercase, 1 lowercase and 1 special character or number
Your file must be a doc, docx or pdf. No larger than 5MB.