Skip to main content
AfterDuty

Senior / Lead Incident Response Engineer

Arcus Search · London, Greater London

Type
Full-time
Posted
11 days ago

Overview

Your incident command and high-pressure decision-making experience directly applies to leading cybersecurity incident response.

About this role

Job Title: Senior / Lead Incident Response Engineer

Type: Permanent

The Opportunity

We are working with a leading, technology-driven financial services organisation to appoint two Senior / Lead Incident Response Engineers on a permanent basis.

These are senior-level positions within a highly sophisticated cybersecurity environment, suited to candidates who have built their careers in cybersecurity engineering and have subsequently developed deep expertise in incident response and major incident management.

The organisation is looking for individuals who have already operated through large-scale, high-impact and business-critical cyber incidents and who are capable of taking complete ownership when the pressure is on.

This is not a role for someone who simply participates in an incident response process. You will be expected to lead from the front, take accountability, coordinate technical teams, make critical decisions and drive incidents through to resolution.

Key Responsibilities

  • Take end-to-end ownership of major cybersecurity incidents, from initial detection and triage through containment, eradication, recovery and post-incident activity.
  • Lead the technical response to high-severity and business-critical security incidents.
  • Coordinate response activity across Security, Engineering, Infrastructure, Cloud, IT and wider technology teams.
  • Lead complex investigations to establish the scope, impact, root cause and attack path of an incident.
  • Provide clear technical direction and decision-making during fast-moving and high-pressure situations.
  • Communicate incident status, risk and recommended actions clearly to senior technical and business stakeholders.
  • Drive post-incident reviews, ensuring lessons learned are translated into tangible security and resilience improvements.
  • Develop and continuously improve incident response processes, playbooks and operational procedures.
  • Identify opportunities to improve detection, containment, investigation and recovery capabilities.
  • Work closely with Security Operations, Detection Engineering, Threat Intelligence, Cloud Security and wider cybersecurity teams.
  • Help develop incident response tooling, automation and engineering capabilities.
  • Contribute to the maturity of the organisation's wider cyber incident and crisis management framework.
  • Provide technical leadership and mentorship to other security professionals.

About You

The ideal candidate will have a strong cybersecurity engineering background combined with significant experience in incident response.

You will ideally have

  • Extensive experience in cybersecurity engineering, security operations, DFIR or a related technical security discipline.
  • Proven experience leading major cybersecurity incidents within large, complex organisations.
  • A track record of taking full ownership and accountability for critical incidents.
  • Experience operating effectively when information is incomplete, the situation is changing rapidly and the business impact is significant.
  • Strong technical knowledge across areas such as cloud, identity, endpoints, networks, applications and security tooling.
  • A strong understanding of modern attack techniques, including identity compromise, credential theft, lateral movement, cloud compromise, data exfiltration and ransomware/extortion.
  • Experience with technologies such as SIEM, EDR/XDR, threat intelligence, forensic and incident response platforms.
  • Excellent analytical and investigative capabilities.
  • The ability to lead and influence highly technical teams without relying solely on formal authority.
  • Exceptional communication skills, including the ability to provide concise and accurate updates to senior stakeholders during live incidents.
  • A strong sense of ownership, accountability and urgency.

The Background We're Looking For

You may currently be working as a

  • Lead Incident Response Engineer
  • Senior Incident Response Engineer
  • Cyber Incident Response Lead
  • Senior Cybersecurity Engineer – Incident Response
  • Cyber Incident Manager
  • Major Incident Response Lead
  • DFIR / Incident Response Lead

Alternatively, you may have a broader security engineering title but have increasingly specialised in incident response and major incident management.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background

  • Intelligence & OSINT
  • Incident command & response
  • Investigative casework
  • Security operations

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Your evidence handling, chain of custody, and investigative discipline from policing are directly applicable to digital forensic investigations.

    Posted 4 days ago

  • Information Security Analyst

    Howard Kennedy LLP · London

    Full-time

    Your incident response and investigative discipline from policing directly apply to triaging and managing security alerts.

    Posted 4 days ago

  • SOC Team Lead

    Methods Business and Digital Technology · London

    Full-time

    £45,000 – £50,000Estimated

    Your incident command and crisis management experience translates directly to leading a SOC under pressure.

    Posted 6 days ago

  • Contract

    £500 a dayEstimated

    Your experience managing complex multi-agency operations and governance in policing prepares you for this programme management role.

    Posted 6 days ago