Skip to main content
AfterDuty

Senior Manager, Global Cyber Security Incident Response (Global CSIRT)

KPMG · London, Greater London

Type
Full-time
Posted
5 days ago

Overview

Your incident command and crisis coordination experience from policing transfers directly to leading major cyber incidents.

About this role

Job details

*Location:*Birmingham, London, Manchester, Reading, Watford

*Capability:*KPMG Core

*Experience Level:*Senior Manager

*Type:*Full Time

*Business Area:*KPMG International

*Contract type:*Permanent

Job description

KPMG International sets strategy, supports collaboration and protects the reputation of a global network of independent professional services firms. Within Global Digital, the Global Information Security Group provides trusted security services that support KPMG’s digital transformation and help protect the network and its clients from cyber threats.

The Global Cyber Security Incident Response Team forms part of Information Security Services and works alongside the Global Security Operations Centre to detect, investigate and support the remediation of potential threats. In this senior operational role, you will support the strategic direction, effectiveness and continued maturity of the global incident response capability. You will provide calm, credible leadership during major incidents, strengthen collaboration across member firms and deliver improvements that enhance cyber resilience and operational excellence. The role includes participation in an on-call rota and out-of-hours support for critical incidents when required.

Roles and responsibilities

  • Lead major and crisis-level cyber security incident response, ensuring clear command, timely escalation, coordinated decision-making and effective service restoration.
  • Provide support to the Global Cyber Security Incident Response Team Lead when required, representing the function and supporting strategic priorities and executive decisions
  • Coordinate technical, legal, privacy, risk, communications and operational stakeholders to deliver an effective global response to complex incidents.
  • Strengthen governance, reporting and service quality so stakeholders have clear oversight of incident response performance, risks and improvement priorities.
  • Drive capability improvements through automation, orchestration, artificial intelligence-enabled investigations, tooling enhancements and modern security operations practices.
  • Build trusted relationships across KPMG member firms to improve consistency, collaboration and alignment in incident response approaches.
  • Guide and influence incident response teams in the UK and US, promoting effective practices, operational excellence and continuous learning.
  • Coach and mentor team members, support talent development and help create an inclusive, collaborative and high-performing environment.

Experience and skills needed

  • Demonstrable leadership of complex cyber security incidents, including incident command, technical investigation oversight, cross-functional coordination, crisis communications and post-incident reviews.
  • Experience leading an incident response, security operations centre or cyber defence function, with evidence of developing people and improving team capability.
  • Experience advising and working with senior stakeholders across information security, technology, legal, privacy, risk, compliance and corporate communications during major incidents.
  • Strong knowledge of cyber defence operations and incident response, including the use of endpoint detection and response, security information and event management, incident response management and case management platforms.
  • Evidence of improving security operations through governance, service improvement, automation, orchestration, tooling or artificial intelligence-enabled investigation and response.
  • Strong analytical, decision-making and stakeholder management skills, with the ability to remain composed, communicate clearly and lead with empathy under pressure.

Qualifications required

A bachelor’s degree, master’s degree or doctorate in computer science, computer engineering, information technology, cyber security or a related field, or equivalent relevant industry experience. Professional information security certifications such as CISM, CISSP, GCIA, GCIH, GREM or GCFA are desirable.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background

  • Incident command & response
  • Investigative casework
  • Working to legislation & regulation
  • Security operations
  • Team & shift leadership

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • EMEA Assurance Lead

    Scale AI · London

    Full-time

    Scale is powering the generative AI wave by providing the data and infrastructure for companies to build large-scale foundation models. AI is rapidly changing the world, and Scale is growing to meet that rapid demand across global markets, including accelerating public sector business across EMEA.

    Posted 2 days ago

  • Full-time

    Your incident command and multi-agency coordination experience directly translates to building operational resilience and crisis management frameworks.

    Posted 3 days ago

  • Service Owners x3

    Summer-Browning Associates Ltd · London

    Contract

    SBA are supporting a Central Government client seeking three experienced Service Owners for a major secure, cloud-first transformation programme. Ideal candidate will hold or have held Security Clearance and worked in Tier 2, SECRET-grade or similarly secure environments such as defence.

    Posted 4 days ago

  • £113,200 – £192,400Estimated

    Your UK security clearance and understanding of national security stakeholders directly match the customer network this role demands.

    Posted 7 days ago