Security Incident Response Engineer

Cyber UK

Warrington

On-site

GBP 117,096 - 158,424

Part time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Cyber UK is seeking a Security Incident Response Engineer to design and embed robust incident response capabilities in the ServiceNow SIR module, aligned to NCSC and best‑practice frameworks.

You will work at the intersection of cyber operations and ServiceNow engineering, integrating with SIEM/SOC tools, building dashboards, playbooks and documenting configurations.

The role is hybrid in Warrington, 6‑month contract with potential extension, SC clearance preferred.

Qualifications

  • Proven ServiceNow experience, ideally with SecOps/SIR.
  • Strong background in cyber security and incident response.
  • Experience engaging with stakeholders across Cyber Operations, IT and senior management.
  • Public sector experience is beneficial but not essential if SIR credentials are strong.

Responsibilities

  • ServiceNow SIR workflow design & development.
  • Review and translate incident processes into ServiceNow SIR workflows.
  • Platform configuration & enhancement.
  • Systems integration & automation with SIEM/SOC tools, ITSM, and SOAR.
  • Data dashboards and reporting for CSOC analysts and senior management.
  • Documentation & playbooks for maintainability.
  • Training & BAU handover to embed SIR into operations.

Skills

ServiceNow
SecOps/SIR
Stakeholder mgmt
SOC/CSOC
SIEM integration

Tools

CSOC tooling

Job description

Key Details at a Glance
  • Role: Security Incident Response Engineer
  • Location: Warrington – hybrid, typically 2 days per week on site
  • Contract length: 6 months (with strong potential for extension based on performance and project needs)
  • IR35 status: Out of Scope
  • Rate: 100/hour
  • Clearance: Existing SC preferred or strong eligible candidates
  • Day‑to‑day environment: Digital / Cyber, working closely with Cyber Operations / CSOC
What You Would Be Doing

This role sits at the intersection of cyber operations and ServiceNow engineering. You would be responsible for designing and embedding robust incident response capabilities in the ServiceNow Security Incident Response (SIR) module, closely aligned to NCSC and best‑practice frameworks.

  • ServiceNow SIR workflow design & development
  • Review existing incident processes and translate them into effective ServiceNow SIR workflows, covering triage, escalation paths, case lifecycle, evidence management, and integration with CSOC tooling.
  • Platform configuration & enhancement
  • Configure and customise SIR forms, fields, templates, routing rules, severity models, and guided response actions. You will also identify gaps in capability and define enhancements in line with platform governance and architecture standards.
  • Systems integration & automation
  • Support integration of SIR with SIEM/SOC tools, threat intelligence feeds, SOAR modules, email ingestion, and ITSM processes (Change, Problem, Incident). A key focus is on building automations that reduce manual effort and improve response times.
  • Data, reporting & dashboards
  • Define and implement operational dashboards for CSOC analysts, KPIs for senior management, and compliance/audit‑ready reporting. You will help ensure clear visibility of incident trends, response performance, and workflow bottlenecks.
  • Documentation & playbooks
  • Translate existing cyber response processes into guided SIR workflows and create user guides, SOPs, technical configuration documentation, data flow diagrams, and integration maps to support long‑term maintainability.
  • Training & BAU handover
  • Deliver hands‑on training for Cyber Operations and process owners, and provide detailed handover materials to embed SIR into BAU operations.
What Our Client Is Looking For
  • Proven ServiceNow experience, ideally with a strong focus on SecOps / SIR.
  • Solid background in cyber security and incident response, ideally within SOC/CSOC or similar environments.
  • Comfortable engaging with stakeholders across Cyber Operations, IT, and senior management, with the ability to explain both technical detail and business impact.
  • Experience working in or with public sector / regulated environments is beneficial but not essential if you bring strong SIR and IR credentials.
Why This Contract Might Appeal to You
  • Opportunity to shape and build a critical incident response capability on ServiceNow rather than simply maintaining an existing setup.
  • Direct impact on how a major organisation responds to cyber incidents, with visibility to senior stakeholders.
  • Hybrid working model, combining meaningful on‑site collaboration with flexibility.
  • Work within the Cyber / Public Sector space, contributing to the protection of nationally important services.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

ServiceNow SIR Engineer | Hybrid Cyber Incident Specialist
ServiceNow SIR Engineer | Hybrid Cyber Incident Specialist

Cyber UK • Warrington

Hybrid
Incident Response Consultant - Systems Integrator
Incident Response Consultant - Systems Integrator

Hamilton Barnes Associates Limited • England

Hybrid
GBP 40,000 - 50,000
Mentorship
Exposure to advanced tools
Flexible working arrangement
ServiceNow Security Architect
ServiceNow Security Architect

Hamilton Barnes ? • United Kingdom

Remote
Digital & Technical Consultancy
Digital & Technical Consultancy

your Jared • Greater London

Hybrid
GBP 90,000 - 130,000
26 days annual leave
Pension contribution up to 8%
Private Medical Insurance
+5
Cyber Security Operations Specialist
Cyber Security Operations Specialist

Tank Recruitment • Bath

On-site
GBP 55,000 - 85,000
ServiceNow Engineer
ServiceNow Engineer

Magnit Global • Greater London

On-site
GBP 119,925 - 147,600
Senior Security Engineer
Senior Security Engineer

TRIA • Greater London

Hybrid
GBP 90,000 - 120,000
SOC Analyst - SC Cleared
SOC Analyst - SC Cleared

Sanderson Government & Defence • Greater London

Hybrid
GBP 146,000 - 151,000
Senior / Lead Incident Response Engineer
Senior / Lead Incident Response Engineer

Arcus Search • Greater London

Hybrid
GBP 90,000 - 150,000
SOC – Cyber Threat Operations Specialist
SOC – Cyber Threat Operations Specialist

Advantage Resourcing UK Ltd • Stevenage

On-site
GBP 97,000 - 138,000