Cyber Operations & Incident Response Manager
Global SME financial seeks a Cyber Operations and Incident Response Manager to lead and line-manage London-based cyber security team (x3/x4), assure the local delivery of globally-prioritised work, and act as Incident Commander and first point of escalation for cyber security in London. The role additionally leads the Endpoint, Platform and Incident Response capability, owning the global prioritisation of that backlog against enterprise cyber risk.
Previous Experience Required:
Led or coordinated cyber security incident response as an Incident Commander or equivalent, working with MDR providers and cross-functional stakeholders (IT, Legal, Compliance).
A strong, hands-on technical background in operational cyber security spanning endpoint & EDR, identity & Active Directory, Microsoft 365 & Azure, network/ZTNA, and SIEM/log management — able to act as a senior technical authority within the team.
Demonstrable experience leading cyber security incident response (incident command), from detection through containment and remediation.
Working knowledge of MITRE ATT&CK and at least one recognised control framework (ISO 27001, CIS or NIST).
Risk-based prioritisation of remediation using threat intelligence.
Operated endpoint security and endpoint detection and response (EDR) tooling (e.g. CrowdStrike or equivalent) in a production environment.
Prioritised and managed a risk-based security backlog, applying frameworks such as MITRE ATT&CK and threat-based prioritisation.
Assured the delivery of security initiatives across distributed teams or sites, tracking vulnerability remediation and patching through to completion.
Act as Incident Commander for security incidents during London hours, coordinating first responders, IT, Legal, Compliance, specialist providers and EDF Group as required.
Serve as the first point of escalation for IT and the business in London on cyber security matters.
Work with the 24/7 Managed Detection and Response (MDR) provider to triage and escalate detections.
Coordinate local participation in incident response exercises and maintain readiness.
Track and chase vulnerability remediation and patching on London-managed systems, escalating blockers.
Own the global prioritisation of the Endpoint, Platform and Incident Response backlog, ordered against the enterprise cyber risk register and exploitation-based intelligence (e.g. MITRE ATT&CK).
Curate the backlog from inputs across Houston and London, including the endpoint detection and response (CrowdStrike) execution lead.
Maintain alignment of this domain to the enterprise risks for endpoint compromise, detection and containment, and cyber resilience.
Operate within the Global Head’s monthly prioritisation cadence; prioritisation across other domains remains with the Global Head.
Provide the local stakeholder interface for cyber security in London.
Planned and delivered complex, cross-functional security or technology initiatives end-to-end, coordinating multiple workstreams, stakeholders and dependencies to time and quality.
This is a hybrid role working 2 days a week in the London office and 3 days remotely.
Recommended Jobs
M&A Tax Partner
Job Details M&A Tax Partner Location: LondonWe are working with an award-winning, highly regarded mid-tier London firm seeking an experienced M&A Tax Partner to lead and grow its Deals Tax capabil…
Live-in Nanny in NW10, Job ID J20317
A family located in Kensal Rise is looking for a Live-in Nanny to take care of their 2 school-aged children. All general Nanny duties are required in this role. A driver is required. Preparing and se…
Test Director/ Test Programme Manager
About TTC TTC Global is a leading specialist software testing and quality engineering consultancy, helping organizations transform the way they deliver software. Founded in New Zealand, TTC operates…
Senior Mechanical Engineer
At HDR, our employee-owners are fully engaged in creating a welcoming environment where each of us is valued and respected, a place where everyone is empowered to bring their authentic selves and nove…
General Assistant
Sanctuary Students provide safe and secure accommodation to thousands of students around the country. We believe that our strength lies in our dedicated staff who help students with their everyday ne…
ECT Drama Teacher: Outstanding Barnet School
Are you a dynamic ECT Drama Teacher ready to launch a career in an "Outstanding" rated school with a strong focus on the performing arts? A mixed school in Barnet is seeking a permanent specialist st…
Market Data Administration & Data Vendor Analyst
London (On-Site / Client Facing) 3–6 Years Experience DonePlus is supporting a leading investment management environment in hiring a Market Data Administration & Vendor Operations Analyst to work…
DT Technician - Mixed Secondary School in Merton
DT Technician – Mixed Secondary School in Merton (January Start) Location: Merton Start Date: January 2026 Contract Type: Full-time, Permanent Salary: Paid to scale A mixed secondar…
VAT Senior Consultant, Advisory & Compliance, London
● This professional services firm has a track record of leading on some of the UK’s largest and most complex restructuring processes – including UK and international transactions involving M&A and ins…