> Markdown version of [/jobs/ext/2216386-senior-security-consultant-incident-response](https://www.wearedevelopers.com/jobs/ext/2216386-senior-security-consultant-incident-response). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Consultant (Incident Response) - **Company:** LRQA Group Limited 2021 - **Location:** Birmingham, UK (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Cloud Computing, Cyber Security, Computer Telephony Integration, Linux, Mitre Att&ck, Cybercrime - **Published:** August 25, 2026 - **Apply:** https://jobs.lrqa.com/talentcommunity/apply/1429139033/?locale=en_US ## About the Role The following list of requirements are pre-requisites for the role: * Demonstrably strong incident management and analytical skills. * Demonstrably strong written and speaking English skills. * Demonstrably strong understanding of Threat Actor TTP's. * Demonstrably strong commercial awareness. * Demonstrable ability to work on own projects and within a team. * At least 36 months of relevant IT Security industry experience in past 4 years. * An ability to lead, teach, present and inspire customers and the wider team. * Ability to travel to UK customer locations where requested and non-UK customer locations where mutually agreed. * Ability to join 24/7 on-call rota. We value capability over credentials. We're not looking for badge collectors. That said, one or more of the following will serve as a distinct advantage: * CREST CCIM / CRIA * GIAC GCFA / GCIH / GNFA * UKSC Chartered / Principal Professional in IR * Similar ## Description This is a new, exciting opportunity for a Senior Security Consultant to join LRQA's existing dynamic Cyber Incident Response Team., This role follows a hybrid working arrangement and will involve working on client sites and from the office from time to time. We support remote work across the UK; however, the main office is in Birmingham. Applicants are required to be resident in the UK. What You'll Be Doing The successful candidate will be responsible for responding to and leading cyber incidents within LRQA Group and LRQA's professional service and Defensive Security Service (DSS) customers, providing education (internally and externally) and improving the team's capability, in line with managerial direction. The role will lead a team of responders, as well as conduct solo incident investigations, where the actor operates with a high level of sophistication (Organised Crime or above) using agreed mitigation, preparedness, and response and recovery approaches, as needed, to minimise the impact of a cyber-incident. They will design and execute training engagements that will prepare all levels of stakeholders for a cyber-incident, and keep up to date with the latest CTI industry developments, security developments, vulnerabilities, attacks, news and techniques aligned to Mitre ATT&CK and use this to further the team's capability. They are expected to operate autonomously using judgement to escalate issues to senior management when appropriate. They must continue to maintain a relevant industry level certification preferably the CREST CCIM and at least one other CREST Certified level certification in the Incident Response field, for which LRQA will provide support. Key Role Responsibilities The following list is indicative of the overall expectations of the role (not exhaustive): * In conjunction with the Customer Engagement Manager and Cyber Incident Manager, manage the collective technical response to customer cyber incidents. * In conjunction with the DSS leadership, develop and drive the IR strategy. * In conjunction with the DSS leadership, develop, refine and monitor IR policies, procedures and technical capability. * Conduct analysis and investigation of cyber security events across Windows, Linux, Cloud and Hybrid environments. * Conduct digital imaging and forensic investigation tasks on Windows and Linux hosts. * Conduct initial triage on suspicious artefacts using both commercial and bespoke tools * Provide customer training engagements to develop internal and external stakeholder preparedness for dealing with cyber incidents. * Provide written and verbal reports to the wider IR team, senior business partners (internal and external). * Conduct ongoing research around the threat landscape, including threat actors, TTPs and develop IR actions, investigation strategies and tooling. * A team-first, collaborative approach working across all relevant technical teams to identify opportunity for improvement in detection sets. * Excellent problem-solving skills and self-motivated to learn and upskill regularly. * A strong desire to continually challenge and develop yourself as part of a fast-paced, high-performing team., If you are successful in securing a role with us, we will carry out preemployment checks in accordance with what is permitted under local law. These checks may include, where legally allowed: right to work, identification, verification of employment history, education, and criminal record checks. We will engage our thirdparty background screening provider, Cfirst to conduct these checks on our behalf. Cfirst performs all processing in full compliance with applicable data protection laws and adheres to strict legal, regulatory, and ethical obligations in handling personal data. Any personal information collected for the purpose of these checks will be used solely for evaluating your suitability for employment and will be retained only for as long as necessary to fulfil these purposes and meet legal requirements. Your data will be stored securely and managed in accordance with all relevant privacy legislation. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [The Geometry of Incidents: Connecting User Impact to Architecture](https://www.wearedevelopers.com/magazine/764-the-geometry-of-incidents-connecting-user-impact-to-architecture) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk)