Cybersecurity Incident Response Lead

Reference: wsllicp252v9mw8c9p9g

We are seeking a Cybersecurity Incident Response Lead to coordinate the identification, containment, investigation and resolution of security incidents across a complex technology environment. You will provide technical leadership during high-impact events, ensuring that response activities are structured, timely and aligned with established security and business continuity objectives. The role will work closely with security operations, infrastructure, application, legal, risk, compliance and communications teams to reduce operational impact and protect sensitive information.

Responsibilities will include leading incident response investigations from initial triage through recovery and post-incident review; assessing alerts, indicators of compromise and reported threats; directing containment, eradication and remediation activities; and maintaining clear, accurate incident records. You will develop and improve incident response plans, playbooks, escalation procedures and tabletop exercises, while identifying opportunities to strengthen detection and response capabilities. The role will also support threat hunting, forensic analysis, vulnerability remediation and security monitoring, as well as contribute to regulatory, executive and stakeholder reporting. You will help define meaningful response metrics and ensure lessons learned are translated into practical improvements.

The successful candidate will have substantial experience in cybersecurity incident response, security operations or digital forensics, with a proven record of leading investigations and coordinating technical teams during critical incidents. Strong knowledge of incident response methodologies, network and endpoint security, identity systems, cloud environments, malware analysis and forensic evidence handling is required. Experience with SIEM, SOAR, EDR and threat intelligence platforms is highly desirable, along with familiarity with recognised security frameworks and data protection requirements. You should be an effective communicator who can explain complex risks clearly, remain calm under pressure and make sound decisions in rapidly changing situations. Relevant professional certifications and experience in developing response processes, mentoring analysts and engaging senior stakeholders would be advantageous.

COMPETITIVE SALARY
Added 22/09/2026
Reference: wsllicp252v9mw8c9p9g

Cybersecurity Incident Response Lead

London, England, United Kingdom Permanent Incident Response

Other similar jobs

Cybersecurity Risk Analyst

Added 01/09/2026

We are seeking a Cybersecurity Risk Analyst to help identify, assess and manage information security risks across technology, business and third-party environments. In this role, you will support the development and maintenance of risk management practices that protect sensitive information, systems and services. You will work with stakeholders across the organisation to understand evolving threats, evaluate control effectiveness and promote practical, risk-based security improvements. Your responsibilities will include conducting cybersecurity risk assessments, documenting findings and recommending appropriate remediation actions. You will monitor risk registers, track mitigation activities and prepare clear reports for senior stakeholders and governance forums. You will also...

Learn more

Senior Manager, Cybersecurity Incident Response

Added 25/08/2026

We are seeking a Senior Manager, Cybersecurity Incident Response to lead the development and execution of a mature, enterprise-wide capability for detecting, investigating and responding to cyber threats. This role will provide strategic direction and operational leadership across incident response, digital forensics, threat intelligence, crisis management and post-incident improvement. The successful candidate will help protect critical systems, data and services while ensuring a coordinated, timely and effective response to security events. Key responsibilities include leading and developing a team of incident response professionals; establishing and maintaining response policies, procedures, playbooks and escalation processes; and overseeing the investigation and containment of...

Learn more

Cyber Incident Response Lead

Added 09/09/2026

We are seeking an experienced Cyber Incident Response Lead to direct the identification, investigation, containment and recovery of complex cybersecurity incidents. You will provide senior technical leadership throughout the incident lifecycle, coordinating rapid and effective responses to threats affecting systems, networks, applications, cloud environments and sensitive data. The role will involve assessing alerts, validating incidents, determining scope and impact, developing containment strategies, and ensuring that recovery actions are completed safely and efficiently. You will lead incident response activities across multidisciplinary teams, including security operations, infrastructure, engineering, risk, legal, communications and business stakeholders. Responsibilities will include establishing response priorities, allocating resources,...

Learn more

Senior Manager, Global Cyber Security Incident Response (Global CSIRT)

Added 18/09/2026

We are seeking a Senior Manager, Global Cyber Security Incident Response to lead and evolve a global incident response capability. This role will be responsible for directing the identification, containment, investigation and recovery of significant cyber security incidents across a complex, international environment. You will provide calm, decisive leadership during high-impact events, coordinate technical and business stakeholders, and ensure that response activities protect critical services, data and customer trust. The role will also contribute to the development of a mature, intelligence-led and continuously improving Global CSIRT function. Key responsibilities include leading incident response teams and third-party partners through suspected and...

Learn more

Advisory Engineer, Enterprise Product Security Incident Response Team (E-PSIRT)

Added 11/09/2026

We are seeking an Advisory Engineer to join an Enterprise Product Security Incident Response Team (E-PSIRT). In this role, you will help identify, assess, coordinate, and resolve security vulnerabilities affecting enterprise products, platforms, and services. You will act as a trusted technical adviser to engineering, product, infrastructure, and customer-facing teams, helping to ensure that security issues are managed consistently, efficiently, and in line with established response processes. Your responsibilities will include investigating reported vulnerabilities and security incidents, validating technical findings, assessing severity and potential business impact, and coordinating remediation activities across multiple stakeholders. You will contribute to vulnerability response plans,...

Learn more

Security Engineer – SecOps / Incident Response & Automation (GBP 350 per day outside IR35)

Added 03/09/2026

We are seeking an experienced Security Engineer to support Security Operations, Incident Response and security automation within a fast-paced technology environment. This contract opportunity offers a rate of GBP 350 per day, outside IR35, and is suited to a hands-on practitioner who can investigate security events, coordinate effective responses and improve the efficiency of operational security processes. The successful candidate will monitor, triage and investigate alerts from SIEM, endpoint detection and response, identity, cloud and network security platforms. You will lead or support the response to security incidents, including scoping impact, analysing logs and indicators of compromise, containing threats, coordinating...

Learn more

Security Engineer I, AWS Security Incident Response

Added 02/09/2026

We are seeking a Security Engineer I to support cloud security incident response and help protect critical systems, applications, and data. In this entry-level role, you will monitor, investigate, and respond to suspected security events across cloud environments, working closely with experienced security professionals and technical teams. You will contribute to the full incident lifecycle, including alert triage, evidence collection, containment, eradication, recovery, and post-incident review. Key responsibilities include analysing logs, alerts, and network or endpoint telemetry; investigating potential unauthorised access, malware, data exposure, and account compromise; documenting findings and maintaining accurate case records; and escalating incidents according to established...

Learn more

Security Engineer I, AWS Security Incident Response

Added 02/09/2026

We are seeking a Security Engineer I, AWS Security Incident Response to help protect cloud environments, investigate security events, and strengthen incident response capabilities. In this role, you will work with security operations, engineering, and infrastructure teams to identify, contain, and remediate threats affecting AWS accounts, services, and workloads. You will contribute to the development of repeatable processes that improve detection, response times, and overall cloud security resilience. Key responsibilities include monitoring and triaging security alerts, investigating suspicious activity across AWS services, and supporting incident response from initial analysis through containment, recovery, and post-incident review. You will assist with log...

Learn more

Senior Associate, Cyber Security Analyst – Incident Response

Added 02/09/2026

We are seeking a Senior Associate, Cyber Security Analyst – Incident Response to join a dedicated security operations function. In this role, you will help protect critical systems, data and services by leading the investigation and response to cyber security incidents. You will work closely with technology, risk, infrastructure and business teams to identify threats, contain activity, recover affected environments and strengthen the organisation’s overall security posture. Key responsibilities include monitoring and analysing security alerts, endpoint activity, network traffic, identity events and other indicators of compromise. You will triage incidents, determine scope and severity, coordinate containment and eradication activities, and...

Learn more

Senior SOC Analyst - Incident Response

Added 02/09/2026

We are seeking a Senior SOC Analyst – Incident Response to lead the investigation, containment and resolution of complex cybersecurity incidents across a diverse technology environment. You will act as a senior escalation point within the Security Operations Centre, providing expert analysis during high-impact events and helping to protect critical systems, data and services. The role will involve working closely with infrastructure, cloud, engineering, risk and business teams to coordinate effective responses and minimise operational disruption. Your responsibilities will include monitoring and triaging alerts from SIEM, EDR, network, identity and cloud security platforms; conducting in-depth analysis of logs, endpoint activity,...

Learn more

Senior SOC Analyst - Incident Response

Added 02/09/2026

We are seeking a Senior SOC Analyst – Incident Response to lead the investigation, containment, and resolution of complex cybersecurity incidents. You will operate as a senior member of a security operations team, providing expert guidance during active incidents and helping protect critical systems, applications, and data. The role requires strong analytical thinking, sound technical judgement, and the ability to remain calm and decisive in a fast-moving environment. Responsibilities include monitoring and triaging security alerts, investigating suspected compromises, conducting threat hunting, and coordinating end-to-end incident response activities. You will analyse events from SIEM, EDR, network, identity, cloud, and other security...

Learn more

Senior SOC Analyst - Incident Response

Added 02/09/2026

We are seeking a Senior SOC Analyst – Incident Response to lead the investigation, containment and resolution of complex cybersecurity incidents. In this role, you will act as a senior escalation point within the security operations function, coordinating response activities across technical teams and providing clear, timely updates to relevant stakeholders. You will analyse alerts and events from SIEM, EDR, network security and cloud platforms, identify indicators of compromise, determine root cause and assess the scope and impact of incidents. Your responsibilities will include developing and executing incident response procedures, conducting forensic investigations, performing threat hunting and supporting malware and...

Learn more

Senior SOC Analyst - Incident Response

Added 02/09/2026

We are seeking a Senior SOC Analyst – Incident Response to lead the investigation, containment, and resolution of complex cybersecurity incidents. You will act as a senior point of escalation within the Security Operations Centre, providing expert guidance during high-impact events and helping strengthen the organisation’s overall incident response capability. The role involves working closely with security engineering, infrastructure, application, risk, and compliance teams to protect critical systems, data, and services. Your responsibilities will include monitoring and analysing alerts from SIEM, EDR, network, cloud, identity, and threat intelligence platforms; validating suspected incidents; performing detailed investigation and forensic analysis; and coordinating...

Learn more

Senior SOC Analyst - Incident Response

Added 02/09/2026

We are seeking a Senior SOC Analyst – Incident Response to lead the investigation, containment, and resolution of complex cybersecurity incidents. In this role, you will act as a senior point of escalation within the Security Operations Centre, providing expert analysis and guidance during high-impact events. You will monitor and investigate alerts across endpoint, network, cloud, identity, and application environments, using SIEM, EDR, threat intelligence, and other security technologies to identify malicious activity and assess business risk. You will coordinate incident response activities from initial triage through eradication, recovery, and post-incident review. Responsibilities include developing and refining detection rules, conducting...

Learn more

Graduate Consultant, Cyber Incident Response: One Year Fixed Term Contract

Added 01/09/2026

Graduate Consultant, Cyber Incident Response: One Year Fixed Term Contract. An exciting opportunity is available for a recent graduate or early-career professional to begin a career in cyber incident response. Working as part of a specialist security team, you will support the investigation, management and resolution of cyber incidents affecting a range of systems, networks and users. This is a practical, learning-focused role suited to someone with a genuine interest in cybersecurity, strong analytical ability and a willingness to develop technical expertise. Your responsibilities will include assisting with the triage and investigation of suspected security incidents, reviewing alerts and log...

Learn more
Required for two factor authentication
At least 8 characters, 1 uppercase, 1 lowercase and 1 special character or number
Your file must be a doc, docx or pdf. No larger than 5MB.