We are seeking a Cybersecurity Incident Response Lead to coordinate the identification, containment, investigation and resolution of security... Read more
We are seeking a Cybersecurity Incident Response Lead to coordinate the identification, containment, investigation and resolution of security incidents across a complex technology environment. You will provide technical leadership during high-impact events, ensuring that response activities are structured, timely and aligned with established security and business continuity objectives. The role will work closely with security operations, infrastructure, application, legal, risk, compliance and communications teams to reduce operational impact and protect sensitive information.
Responsibilities will include leading incident response investigations from initial triage through recovery and post-incident review; assessing alerts, indicators of compromise and reported threats; directing containment, eradication and remediation activities; and maintaining clear, accurate incident records. You will develop and improve incident response plans, playbooks, escalation procedures and tabletop exercises, while identifying opportunities to strengthen detection and response capabilities. The role will also support threat hunting, forensic analysis, vulnerability remediation and security monitoring, as well as contribute to regulatory, executive and stakeholder reporting. You will help define meaningful response metrics and ensure lessons learned are translated into practical improvements.
The successful candidate will have substantial experience in cybersecurity incident response, security operations or digital forensics, with a proven record of leading investigations and coordinating technical teams during critical incidents. Strong knowledge of incident response methodologies, network and endpoint security, identity systems, cloud environments, malware analysis and forensic evidence handling is required. Experience with SIEM, SOAR, EDR and threat intelligence platforms is highly desirable, along with familiarity with recognised security frameworks and data protection requirements. You should be an effective communicator who can explain complex risks clearly, remain calm under pressure and make sound decisions in rapidly changing situations. Relevant professional certifications and experience in developing response processes, mentoring analysts and engaging senior stakeholders would be advantageous.
Read lessLondon, England, United KingdomPermanent
All your saved jobs are no longer available or you've already applied.
for the following search criteria