Security Incident Response Manager

KPMG LLP

Greater London

Hybrid

GBP 90,000 - 120,000

Full time

32 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

KPMG LLP is seeking a Security Incident Response Manager to lead Tier 2 Incident Response within the Security Operations framework. You will blend people leadership with hands-on technical direction, coordinating investigations and driving improvements across a diverse technology environment.

The role requires on-call participation for high-priority incidents, with hybrid UK work arrangements and eligibility for clearance.

Qualifications

  • Proven experience leading complex cyber security incidents in an SOC or defence environment.
  • Ability to coach and develop security analysts with clear guidance.
  • Experience coordinating incidents across endpoint, identity, email, cloud and network.
  • Strong communication with technical and non-technical stakeholders, including senior decision-makers.
  • Familiarity with incident response playbooks, post-incident reviews and root-cause analysis.

Responsibilities

  • Lead and develop Tier 2 Incident Response Analysts, setting standards and guidance.
  • Direct investigations across endpoint, identity, email, cloud and network, from escalation to recovery.
  • Provide technical and operational leadership during major incidents and on-call events.
  • Collaborate with SOC to improve triage, escalation, and response effectiveness.
  • Work with Threat Intelligence, Detection Engineering and Security Engineering teams to improve visibility and tooling.
  • Lead post-incident reviews and drive practical resilience improvements.
  • Develop incident response playbooks and run simulations and readiness exercises.
  • Engage stakeholders across technology, risk, legal and privacy for strategy alignment.

Skills

Incident response leadership
Cyber security investigations
Stakeholder communication
Team coaching

Tools

Microsoft Sentinel
Microsoft Defender
Purview
Forensics tools

Job description

Select how often (in days) to receive an alert:

This Grade C role sits within Operational Security in Group Corporate Services, the internal specialist capability that helps KPMG's people and business operate effectively and securely. KPMG is evolving Security Operations across the UK and Switzerland to create a more integrated, intelligence-led approach to cyber resilience.

As Security Incident Response Manager, you will lead the Tier 2 Incident Response function and be accountable for managing cyber security incidents escalated by the Security Operations Centre. You will combine team leadership with hands-on technical direction, stakeholder coordination and continuous improvement across a diverse technology environment.

The role is based in the UK with hybrid working. Participation in the Security Operations on-call rota is required, including acting as a senior escalation point for high-priority and major incidents outside standard business hours. You must be eligible for Security Check clearance or able to obtain it.

Roles and responsibilities

Lead, coach and develop Tier 2 Incident Response Analysts, setting clear standards and providing technical guidance.

Direct complex investigations across endpoint, identity, email, cloud and network environments, coordinating activity from escalation through recovery.

Provide technical and operational leadership during major incidents, enabling clear decisions, effective communication and coordinated action.

Partner with the Security Operations Centre to improve triage quality, escalation routes and response effectiveness.

Work with Threat Intelligence, Detection Engineering, Vulnerability Management and Security Engineering teams to improve visibility, detections and response capability.

Lead post-incident reviews and root cause analysis, turning lessons learned into practical improvements that strengthen resilience.

Develop and maintain incident response playbooks, procedures and operational standards, and support simulations and readiness exercises.

Influence the UK and Switzerland Security Operations strategy, engage senior stakeholders across technology, risk, legal and privacy, and provide senior on-call cover for major incidents.

Experience and skills needed

Experience leading complex cyber security incident investigations within a Security Operations Centre, incident response or cyber defence environment, including containment, eradication and recovery.

Experience managing and developing technical security teams through coaching, mentoring and clear operational leadership.

Practical experience investigating threats across endpoint , identity, email, cloud and network technologies.

Experience coordinating major incidents and communicating clearly with technical and non-technical stakeholders, including senior decision-makers .

Experience improving incident response services through playbooks, post-incident reviews, root cause analysis, exercises or operational process development.

Experience working in a large, complex or regulated organisation and making evidence-based decisions under pressure. Experience with Microsoft Sentinel, Microsoft Defender technologies, Microsoft Purview, digital forensics and incident response tools, security orchestration and automation, threat hunting or detection engineering would be an advantage. Certifications such as GCIH, GCFA, CISSP or an equivalent are also desirable.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Incident Response Analyst
Senior Security Incident Response Analyst

KPMG LLP • Greater London

Hybrid
GBP 70,000 - 90,000
Senior Manager, Global Cyber Security Incident Response (Global CSIRT)
Senior Manager, Global Cyber Security Incident Response (Global CSIRT)

KPMG LLP • Greater London

On-site
GBP 90,000 - 130,000
Senior Manager, Global Cyber Security Incident Response (Global CSIRT)
Senior Manager, Global Cyber Security Incident Response (Global CSIRT)

KPMG Careers • Greater London

On-site
GBP 90,000 - 130,000
Manager, Global Cyber Security Incident Response (Global CSIRT)
Manager, Global Cyber Security Incident Response (Global CSIRT)

KPMG International Cooperative • City of Westminster

On-site
GBP 90,000 - 130,000
Senior Manager – Associate Director Technical Incident Responder, Cyber Incident Response
Senior Manager – Associate Director Technical Incident Responder, Cyber Incident Response

Cyber UK • Greater London, Manchester

Hybrid
GBP 60,000 - 80,000
Incident Response Consultant - Systems Integrator
Incident Response Consultant - Systems Integrator

Hamilton Barnes Associates Limited • England

Hybrid
GBP 40,000 - 50,000
Mentorship
Exposure to advanced tools
Flexible working arrangement
Cyber Response & Recovery Manager – German Speaker
Cyber Response & Recovery Manager – German Speaker

Cyber UK • Manchester

Hybrid
GBP 70,000 - 110,000
Cyber Incident Response - Senior Manager
Cyber Incident Response - Senior Manager

LT Harper Recruitment Group • Greater London

On-site
GBP 90,000 - 130,000
Senior Global Cyber Security Incident Response Lead
Senior Global Cyber Security Incident Response Lead

KPMG Careers • Greater London

On-site
GBP 90,000 - 130,000
Cyber Response & Recovery – Manager (Remediation focus)
Cyber Response & Recovery – Manager (Remediation focus)

Cyber UK • United Kingdom

Hybrid
GBP 90,000 - 130,000