Skip to content

Open nowPosted 6 hours ago

Senior Incident Responder

Workable (global search)107,962 open roles

Where
London, England, United Kingdom
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Incident ResponderWorkable (global search) · London, England, United Kingdom
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 3 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.5%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 33.9%30 days
This job: posted 6 hours ago

Workable (global search) median: 3 days open

The posting

Due to continued growth, Bridewell's CSIRT is looking for a Senior Incident Responder to support our CNI and other clients. This role will investigate and respond to security incidents, contribute to incident preparation and recovery activities, and help clients strengthen their security posture.

This role focuses on supporting and maintaining incident response capabilities across endpoint, network, and cloud environments for both our SOC services and consulting engagements. The Senior Incident Responder will work with colleagues and clients to deliver effective investigations, improve response processes, and develop their technical expertise.

Requirements

Main Responsibilities:

  • Support the delivery and ongoing improvement of incident response services, including maintaining technical documentation, playbooks, and response procedures for endpoint, network, and cloud environments.
  • Follow established triage, investigation, and escalation processes when responding to alerts and security incidents across modern hybrid IT environments.
  • Investigate security incidents across endpoint, network, and cloud platforms, working with senior responders to identify appropriate containment, remediation, and recovery actions.
  • Carry out investigation, containment, and eradication activities for security incidents, escalating complex or high-priority matters when required.
  • Support the forensic acquisition, preservation, examination, and analysis of digital evidence from endpoints and other relevant systems, maintaining appropriate evidential handling and investigation records.
  • Undertake logical acquisition and forensic analysis of supported mobile devices, including Android, iOS, iPadOS, and Windows devices, using approved tooling and documented processes. Device access may require a valid passcode.
  • Work collaboratively with other incident responders and SOC analysts to ensure consistent, high-quality delivery across client environments.
  • Support customers in improving their detection and response capabilities across their IT estate.
  • Contribute to the development and maintenance of incident response plans and playbooks in line with industry standards and good practice.
  • Support and conduct threat hunts across endpoint, network, and cloud environments.
  • Perform initial malware analysis and support more detailed analysis where required during incident response activities.
  • Contribute to internal knowledge sharing and, where appropriate, technical blogs, webinars, or other industry content.
  • Support incident coordination during active incidents, providing clear updates and maintaining accurate investigation records.

Experience:

  • Practical experience of incident response, security operations, digital forensics, or a closely related cyber security role.
  • Practical knowledge of digital forensic principles, including evidence preservation, forensic acquisition, chain of custody, artefact analysis, and clear documentation of findings.
  • Experience using digital forensic tools to examine endpoint or mobile device data is desirable, familiarity with logical mobile extraction using tools such as Magnet AXIOM would be beneficial.
  • Working knowledge of enterprise endpoint technologies, network infrastructure, and at least one major cloud platform such as AWS, Azure, or GCP.
  • Relevant training or certifications, such as Security Blue Team Level 1 or 2, GCIH, GCFA, or equivalent incident response and digital forensics qualifications, are desirable.
  • Experience working in a SOC, CSIRT, MSSP, consultancy, or internal security team is desirable.
  • An understanding of incident response within regulated or CNI environments would be beneficial.
  • Awareness of common security frameworks and standards, such as NIST CSF, ISO 27001, and the NIS Regulations.
  • Ability to communicate technical findings clearly to both technical and non-technical audiences through written reports and verbal updates.
  • Familiarity with SOC processes, security monitoring, and incident response procedures across hybrid IT environments.
  • Some experience of threat hunting methodologies and tools across enterprise environments.
  • A good understanding of common attack techniques, adversary behaviours, and TTPs, including familiarity with frameworks such as MITRE ATT&CK.

This position requires travel both UK and international to client locations, approximately 20-25% of working time, with expenses. The role will require on-call responsibilities as part of the incident response rotation

Benefits

Our vision is to create a safe, inclusive digital world where people and organisations can thrive. Our values of Do the Right Thing, One Team and Above and Beyond emphasises the importance of the part we play in society, and our commitment to our people and clients. Our story to-date has been phenomenal, but success doesn’t end here and as we continue to grow and scale, we want to keep the same culture, passion and commitment to high quality that has enabled us to get this far. Bridewell will provide a great career opportunity with continual development as well as the following:

  • 25 Days Holiday - Plus buy and sell options and increasing for long service
  • Flexible Working (around core office hours)
  • Employee Shareholder Scheme and Performance Reward Model
  • Private Healthcare (Bupa)
  • Company Pension
  • Personal Day & Birthday Off - After 1 year of service
  • Family Leave – After 1 year of service
  • Enhanced Maternity based on length of service
  • Access to a Training Budget
  • Life Assurance
  • Electric Vehicle Scheme & Cycle to Work Scheme

Location: Bridewell operates a hybrid and flexible working policy, however you will be required to travel to different sites on occasion.

Note: To be eligible for this job you must either hold SC or be eligible and willing to go through security clearance.

Bridewell values diversity in the workplace and is a fair and equal opportunity employer. We are committed to creating an equal and inclusive working environment, with the aim that our employees will be truly representative of all sections of society and each person feels respected and able to give their best.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.