Senior / Lead Incident Response Engineer

Arcus Search

Greater London

Hybrid

GBP 90,000 - 150,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Arcus Search is recruiting for two Senior / Lead Incident Response Engineers in London on a permanent basis. You will take end-to-end ownership of major incidents, coordinate across Security, Engineering, IT and Cloud teams, and drive investigations to root cause and resolution.

This is a high-responsibility role in a fast-paced cybersecurity environment. The ideal candidate has extensive cybersecurity engineering and incident response experience, with a proven track record of leading major

Qualifications

  • Extensive experience in cybersecurity engineering, security operations, DFIR or related security discipline.
  • Proven experience leading major cybersecurity incidents within large organisations.
  • Track record of taking full ownership for critical incidents.
  • Ability to lead and influence technically without formal authority.

Responsibilities

  • Take end-to-end ownership of major cybersecurity incidents from detection to post-incident activity.
  • Lead the technical response to high-severity incidents and coordinate across teams.
  • Lead complex investigations to determine scope, impact, root cause and attack paths.
  • Provide clear technical direction and decisions during fast-moving incidents.

Skills

Cybersecurity engineering
Security operations
DFIR
Major incidents leadership

Tools

SIEM
EDR/XDR
Threat intelligence
Forensic tools

Job description

Job Title: Senior / Lead Incident Response Engineer

Type: Permanent

Location: London – Hybrid

The Opportunity

We are working with a leading, technology-driven financial services organisation to appoint two Senior / Lead Incident Response Engineers on a permanent basis.

These are senior-level positions within a highly sophisticated cybersecurity environment, suited to candidates who have built their careers in cybersecurity engineering and have subsequently developed deep expertise in incident response and major incident management.

The organisation is looking for individuals who have already operated through large-scale, high-impact and business-critical cyber incidents and who are capable of taking complete ownership when the pressure is on.

This is not a role for someone who simply participates in an incident response process. You will be expected to lead from the front, take accountability, coordinate technical teams, make critical decisions and drive incidents through to resolution.

Key Responsibilities
  • Take end-to-end ownership of major cybersecurity incidents, from initial detection and triage through containment, eradication, recovery and post-incident activity.
  • Lead the technical response to high-severity and business-critical security incidents.
  • Coordinate response activity across Security, Engineering, Infrastructure, Cloud, IT and wider technology teams.
  • Lead complex investigations to establish the scope, impact, root cause and attack path of an incident.
  • Provide clear technical direction and decision-making during fast-moving and high-pressure situations.
  • Communicate incident status, risk and recommended actions clearly to senior technical and business stakeholders.
  • Drive post-incident reviews, ensuring lessons learned are translated into tangible security and resilience improvements.
  • Develop and continuously improve incident response processes, playbooks and operational procedures.
  • Identify opportunities to improve detection, containment, investigation and recovery capabilities.
  • Work closely with Security Operations, Detection Engineering, Threat Intelligence, Cloud Security and wider cybersecurity teams.
  • Help develop incident response tooling, automation and engineering capabilities.
  • Contribute to the maturity of the organisation's wider cyber incident and crisis management framework.
  • Provide technical leadership and mentorship to other security professionals.
About You

The ideal candidate will have a strong cybersecurity engineering background combined with significant experience in incident response.

You will ideally have:

  • Extensive experience in cybersecurity engineering, security operations, DFIR or a related technical security discipline.
  • Proven experience leading major cybersecurity incidents within large, complex organisations.
  • A track record of taking full ownership and accountability for critical incidents.
  • Experience operating effectively when information is incomplete, the situation is changing rapidly and the business impact is significant.
  • Strong technical knowledge across areas such as cloud, identity, endpoints, networks, applications and security tooling.
  • A strong understanding of modern attack techniques, including identity compromise, credential theft, lateral movement, cloud compromise, data exfiltration and ransomware/extortion.
  • Experience with technologies such as SIEM, EDR/XDR, threat intelligence, forensic and incident response platforms.
  • Excellent analytical and investigative capabilities.
  • The ability to lead and influence highly technical teams without relying solely on formal authority.
  • Exceptional communication skills, including the ability to provide concise and accurate updates to senior stakeholders during live incidents.
  • A strong sense of ownership, accountability and urgency.
The Background We're Looking For
You may currently be working as a:
  • Lead Incident Response Engineer
  • Senior Incident Response Engineer
  • Cyber Incident Response Lead
  • Senior Cybersecurity Engineer – Incident Response
  • Major Incident Response Lead
  • DFIR / Incident Response Lead

Alternatively, you may have a broader security engineering title but have increasingly specialised in incident response and major incident management.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Incident Response Lead — Major Cyber Incidents
Senior Incident Response Lead — Major Cyber Incidents

Arcus Search • Greater London

Hybrid
GBP 90,000 - 150,000
Incident Response Consultant - Systems Integrator
Incident Response Consultant - Systems Integrator

Hamilton Barnes Associates Limited • England

Hybrid
GBP 40,000 - 50,000
Mentorship
Exposure to advanced tools
Flexible working arrangement
Senior Manager – Associate Director Technical Incident Responder, Cyber Incident Response
Senior Manager – Associate Director Technical Incident Responder, Cyber Incident Response

Cyber UK • Greater London, Manchester

Hybrid
GBP 60,000 - 80,000
Security Engineer - Detection & Response | Leading Global Investment Group
Security Engineer - Detection & Response | Leading Global Investment Group

Techfellow Limited • Greater London

Hybrid
GBP 250,000 - 350,000
Senior Consultant, Digital Forensics and Incident Response
Senior Consultant, Digital Forensics and Incident Response

Control Risks • Greater London

On-site
GBP 90,000 - 130,000
Hybrid working arrangements
Lead Incident Response Analyst
Lead Incident Response Analyst

IntaPeople: STEM Recruitment • Cardiff

Hybrid
GBP 55,000
Bespoke learning plans
Bonus plan
Senior Lead Security Operations Analyst - Companies House - G7
Senior Lead Security Operations Analyst - Companies House - G7

Manchester Digital • Manchester

Hybrid
GBP 90,000 - 130,000
Senior Consultant, Digital Forensics and Incident Response
Senior Consultant, Digital Forensics and Incident Response

Control Risks • City Of London

Hybrid
GBP 90,000 - 130,000
Hybrid working
Senior SOC & Incident Response Engineer
Senior SOC & Incident Response Engineer

DGH Recruitment • London

On-site
GBP 40,000 - 50,000
Cyber Security Operations Specialist
Cyber Security Operations Specialist

Tank Recruitment • Bath

On-site
GBP 55,000 - 85,000