Lead Security Incident Response Engineer: Cloud & Forensics

Checkout.com

Greater London

On-site

GBP 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Checkout.com in London is seeking a senior security incident response lead to own the technical direction of incident response across the company. You will guide investigations, containment, eradication, and recovery, and lead from the front during serious incidents with calm authority.

In this role you will operate across endpoint, identity, cloud, and SaaS environments, partnering with Security Operations, IT, and Engineering to reduce real risk.

Qualifications

  • Proven, hands-on experience leading response to real security incidents.
  • Strong investigation capability across endpoint, identity, and cloud environments.
  • Experience prioritising vulnerability or patching risk in large, complex estates.
  • Ability to remain decisive and effective during incidents, and analytical between them.
  • Clear communicator who can influence outcomes without needing direct ownership of every fix.
  • Pragmatic mindset: reduce risk first, optimise later.
  • DFIR, forensics, or malware analysis experience.
  • Proven ability to correlate vulnerability data with runtime telemetry and attacker behaviour.
  • Cloud-first incident response or exposure management experience.
  • Exposure to compliance-driven security requirements.
  • Experience working alongside vulnerability scanning platforms without being constrained by them.

Responsibilities

  • Leading the end-to-end technical response to high‑severity security incidents
  • Owning investigation, containment, eradication, and recovery activities
  • Acting as the senior technical authority during live incidents
  • Providing clear, decisive guidance to Security Operations under pressure
  • Coordinating response across endpoint, identity, cloud, and SaaS platforms
  • Supplying executives, legal, and risk stakeholders with accurate technical context and impact assessments
  • Ensuring incidents are driven to resolution, not just stabilised
  • Designing, maintaining, and continuously improving incident response playbooks and runbooks
  • Identifying systemic weaknesses that increase incident likelihood or blast radius
  • Using SIEM and security tooling to prioritise patching and vulnerability risk based on real exposure
  • Partnering with IT, Cloud, and Engineering teams to drive remediation based on business risk
  • Tracking remediation through to completion and validating effectiveness post‑fix
  • Turning incidents, near‑misses, and exposure findings into: improved detections, stronger preventative controls, faster and less disruptive response
  • Driving readiness through simulations, tabletop exercises, and scenario testing
  • Raising the overall maturity of the Cyber Security function by pushing advanced response into BAU operations

Skills

Incident response leadership
Investigation capability
Vulnerability management
Communication
Risk-based thinking
DFIR / forensics
Vulnerability correlation
Cloud incident response
Compliance awareness
Vulnerability scanning tools

Job description

Checkout.com in London is seeking a senior security incident response lead to own the technical direction of incident response across the company. You will guide investigations, containment, eradication, and recovery, and lead from the front during serious incidents with calm authority.

In this role you will operate across endpoint, identity, cloud, and SaaS environments, partnering with Security Operations, IT, and Engineering to reduce real risk.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Incident Response Engineer (Hybrid)
Lead Incident Response Engineer (Hybrid)

Checkout Ltd • Greater London

Hybrid
GBP 70,000 - 90,000
Flexible hybrid working model
Opportunities for growth and recognition
Incident Response Engineer Information security London
Incident Response Engineer Information security London

Checkout Ltd • Greater London

Hybrid
GBP 70,000 - 90,000
Flexible hybrid working model
Opportunities for growth and recognition
Senior Security Incident Response Engineer
Senior Security Incident Response Engineer

Checkout.com • Greater London

On-site
GBP 120,000 - 180,000
Senior SecOps Engineer: Cloud Security & Incident Response
Senior SecOps Engineer: Cloud Security & Incident Response

Risk Ledger • Greater London

Hybrid
GBP 90,000 - 100,000
Competitive salary
Equity package
Private pension
+5
Incident Response Engineer - UK Security Operations
Incident Response Engineer - UK Security Operations

Google Inc. • City of Westminster

On-site
GBP 70,000 - 110,000
AI-Driven Security Detection & Response Engineer
AI-Driven Security Detection & Response Engineer

AI Startups UK • Greater London

Hybrid
GBP 90,000 - 130,000
Cybersecurity Incident Response Lead
Cybersecurity Incident Response Lead

Creative Artists Agency • Greater London

On-site
GBP 90,000 - 120,000
Senior DFIR Investigator: Incident Response Lead
Senior DFIR Investigator: Incident Response Lead

CFC • City Of London

On-site
GBP 90,000 - 120,000
London Cyber Security Lead – Incident Response
London Cyber Security Lead – Incident Response

Cyber UK • Greater London

Hybrid
GBP 140,000 - 190,000
Hybrid working
Personal pension plan
Private medical and dental insurance
+7
Incident Response Lead & Digital Forensics Expert
Incident Response Lead & Digital Forensics Expert

Alto • Greater London

On-site
GBP 90,000 - 120,000