Skip to main content
AfterDuty

Incident and Preparedness Specialist

BT Group · Bristol, South West England

Type
Full-time
Posted
5 days ago

Overview

Your incident command and multi-agency coordination experience directly applies to managing cyber incident response and preparedness.

About this role

Job Title: Incident and Preparedness Specialist

Req ID: 62601

Job Function: Cyber Security

Posting Start Date: 10/09/2026

Posting End Date: 24/09/2026

Division: Networks

Job Location: GBR Bristol - Assembly, GBR-Manchester-New Bailey

Advertised Salary: Competitive with Great Benefits

Job Req ID: 62601

Posting Date: 10th Sep 2026

Our brand, reputation, ability to serve our customers and grow our business is founded on a strong security posture and ability to defend against harm and minimise risk. This role part of a team responsible for the delivery and coordination of BT Group’s Cyber Operations activities relating to Priority 3 through Priority 1 cyber security incidents, ensuring effective response, containment, recovery and restoration of services to minimise business impact.

The position is also responsible for supporting the maintenance and enhancing BT’s readiness to respond to major cyber incident through the delivery of cyber preparedness activities, exercises, training programmes and cross-functional engagement. It is responsible for the governance and execution of Security bronze-level incident management processes, supporting the wider Business Continuity Management framework and coordinating cyber preparedness assessments across the organisation.

The role also develops, maintains and reports on cyber preparedness metrics and KPIs, driving continuous improvement in cyber resilience, operational readiness and incident response capabilities to ensure BT remains prepared to address an evolving threat landscape.

The role is hybrid (3 days in office) & can be based in either Bristol or Manchester.

SC Clearance Eligibility Is Required

What you’ll be doing

  • Responsible for coordinating and delivering Priority 3 through Priority 1 cyber incident response activities, ensuring effective containment, remediation, recovery and communication throughout the incident lifecycle.
  • Responsible for maintaining BT's readiness to respond to major cyber incidents through the delivery of cyber preparedness activities, supporting operational resilience and response effectiveness.
  • Responsible for the execution and continual improvement of Security Bronze-level incident management processes, supporting the wider BT Business Continuity Management framework.
  • Responsible for coordinating and delivering the BT Cyber Exercising Programme, including federated exercising activities across business units and key stakeholders.
  • Responsible for delivering cross-business cyber incident preparedness training, awareness and engagement activities to strengthen organisational readiness. Responsible for the creation, maintenance, analysis and reporting of cyber preparedness metrics, KPIs and management information to support informed decision-making and continuous improvement.
  • Responsible for conducting cyber preparedness assessments and developing recommendations that strengthen cyber resilience across BT.
  • Builds and maintains effective relationships across BT Group to support the consistent delivery of security operations services and identify opportunities to improve cyber resilience and operational effectiveness.
  • Provides guidance, support and knowledge sharing to colleagues, contributing to the development of team capability and operational performance.
  • Drives continuous improvement initiatives across cyber incident management and preparedness processes to enhance efficiency, effectiveness and resilience.
  • Works closely with Cyber Operations, Security and business stakeholders to support the development and enhancement of incident management capabilities, processes and technologies.
  • Represents BT Group in internal and external forums, exercises and collaboration activities, sharing best practice and contributing to the continued development of cyber response capabilities.
  • Leads the coordination of containment, remediation, recovery actions and incident reporting, ensuring leadership teams receive timely and accurate updates throughout major incidents. Holds deputy status and DOA for Principal, Incident and preparedness where required.

Experience Required For The Role

  • Experience (3+ years) within complex and fast-moving operational environments, such as Cyber Security, Incident Management or Crisis Management. This is a highly visible role that offers the opportunity to influence key decisions, work with senior leaders and make a real impact during critical operational situations.
  • Skilled in interpreting data to determine risk and business impact and triage accordingly.
  • Understanding of Cyber security and the fundamentals of Cyber Incident response and management.
  • Experience in engaging senior stakeholders to including MD level.
  • Experience in using a range of security or IT tooling to interpret data.
  • Experienced in being part of industry collaboration groups, including partners/vendors.
  • Experience in delivering consultancy to internal stakeholders.
  • Typically qualified to degree level, or equivalent professional experience.

Skills Required For The Role

  • Strong ability to lead cyber security incident response activities, providing clear direction and coordination during complex and high-pressure situations.
  • Excellent stakeholder engagement skills, with the ability to communicate effectively and build trusted relationships across technical teams, business functions, senior management and external organisations.
  • Proven ability to influence decisions and drive outcomes across multiple teams, to achieve effective and timely resolution of cyber security incidents.
  • Experience building and maintaining collaborative relationships with external partners, customers, suppliers, industry peers and organisations.
  • Strong decision-making and prioritisation skills, with the ability to assess risk, balance competing demands and coordinate resources effectively during operational and incident response activities.
  • Growth mindset wanting to learn and develop new skills and continue to build as a Cyber Security Principal.
  • Demonstrable commitment to continuous learning and professional development, keeping abreast of emerging cyber threats, technologies and industry best practice.
  • Communication, Visual & Written skills: exemplary communication, visual & written skills.
  • Inclusive Leadership: creative, imaginative and technically capable with an ability to inspire people to deliver beyond their assumed limits. The ability to unite behind a vision and purpose. A connected leader with an ability to lead global, direct and matrixed managed teams.

Technical skills

  • Incident management during high pressure and high impacting incidents. Leading containment efforts.
  • Understanding of business implications during a cyber attack and who key decision makers are.
  • Experience in creating and delivering exercises and simulations.

Our Package

Tailored benefits make a real difference. That’s why we offer a comprehensive range to support your growth, wellbeing, and everyday life. You can design the package to suit you and your lifestyle. Your core benefits include:

  • 10% on target annual bonus
  • Access to an online private GP 24/7 for you and your immediate family
  • Market-leading paid carers leave with up to 2 weeks off
  • Equalised maternity, paternity, and adoption leave – 18 weeks’ full pay and 8 weeks’ half pay
  • Discounted EE and BT products, including mobile and broadband
  • Market leading Pension scheme – 5% from you and 10% from us
  • Holiday purchase scheme

You can select additional benefits, including healthcare, dental, gym memberships and more when you’re ready.

BT Group is the UK’s leading communications group and the holding company behind some of the country’s most recognised brands – including BT, EE, Openreach and Plusnet. Our purpose is as simple as it is ambitious: we connect for good. Our customers include consumers, small, medium and large businesses, public sector organisations and other communications providers.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Bristol

Why this fits a police background — match score 80/100

  • Incident command & response
  • Security operations

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Your incident command and calm analytical approach under pressure directly translate to leading cyber incident response.

    Posted 2 days ago

  • Information Security Analyst

    REX Cyber Security · Bristol

    Full-time

    Information Security Analyst 📍 Bristol | Hybrid Working | £45,000 - £55,000 We’re working with a leading professional services company in Bristol that is looking to appoint an Information Security Analyst to join its established security function.

    Posted 7 days ago

  • Junior Cyber Security Analyst

    Executive Jet Support Ltd · Bristol

    Full-time

    Your incident response and investigative discipline transfer directly to triaging and escalating security threats.

    Posted 12 days ago

  • Incident Response Analyst

    HM Revenue & Customs · Bristol

    Contract

    Your fraud investigation and evidence-handling skills from policing transfer directly to triaging identity-led fraud incidents.

    Posted 20 days ago