Job Search and Career Advice Platform

Enable job alerts via email!

Lead Cybersecurity Incident Responder - IR, Cyber, - London

Adecco

City Of London

Hybrid

GBP 80,000 - 100,000

Full time

Yesterday
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading staffing agency is seeking a skilled Lead Cybersecurity Incident Responder in London with strong incident response and security operations expertise. This hybrid role requires leadership in managing security incidents, conducting investigations, and providing client support. Ideal candidates will have extensive knowledge of technologies like Microsoft security stack, incident response procedures, and scripting abilities. Mentorship of junior team members and experience in a SOC environment are key aspects of the position.

Qualifications

  • Extensive hands-on experience in Incident Response or SOC environments.
  • Ability to automate tasks using programming languages.
  • Strong analytical skills with compliance understanding.

Responsibilities

  • Manage high-impact security incidents as the Lead Cybersecurity Incident Responder.
  • Conduct forensic investigations and present findings to clients.
  • Provide on-call emergency support and lead response actions.

Skills

Incident Response (IR)
SOC operations
Microsoft security stack
Scripting (Bash, Perl, Python, PowerShell)
MITRE ATT&CK framework

Tools

Microsoft Defender/Sentinel
DFIR tooling
SIEM
Job description

Lead Cybersecurity Incident Responder - IR, Cyber, - London / Hybrid (some travel European travel)

Salary: Competitive,

We are seeking a highly experienced cybersecurity professional with a strong background in incident response and advanced security operations.

  • Extensive hands-on experience in Incident Response (IR), SOC, MSSP, CSIRT, or DFIR, with a proven ability to handle urgent and complex client incidents under pressure.
  • European language is beneficial but not required.
  • Experience working in a 24/7 SOC environment, with a deep understanding of how SOC operations integrate with IR.
  • Expert knowledge of technologies such as Microsoft security stack, DFIR tooling, SIEM, Microsoft Defender/Sentinel, EDR platforms, timeline analysis, and cloud environments (Azure, AWS, or GCP).
  • Exposure to penetration testing, including red team or purple team exercises, is advantageous.
  • Ability to script or automate using Bash, Perl, Python, or PowerShell.
  • Strong analytical mindset and familiarity with hypothesis-driven investigation methods.
  • Confident understanding of compliance, legal requirements, and managing third-party vendor relationships.
  • Solid working knowledge of the MITRE ATT&CK framework.
  • Willingness to take part in on-call rotations.

As the Lead Cybersecurity Incident Responder, you will play a critical role in guiding clients through high-impact, time-sensitive security incidents.

  • Conducting network, host, and forensic investigations, presenting clear and actionable findings to clients.
  • Providing on-call emergency support and leading swift, effective response actions.
  • Handling complex and sensitive IR engagements across a wide range of industries and technical environments.
  • Acting as a trusted advisor, consulting directly with clients and collaborating with senior leadership.
  • Producing detailed technical reports and executive-level summaries.
  • Mentoring and supporting junior members of the team.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.