Incident Manager
Role details
Job location
Tech stack
Job description
I'm supporting a growing professional services and advisory business that is looking to hire a Cyber Response Manager into its Cyber Response Services team. The roleThis is the recovery side of incident response. When a client has been hit by ransomware, an Active Directory compromise or a major network intrusion, you are the person who helps them rebuild safely, remove attacker persistence and get business critical services running again. You will work alongside forensic teams, legal advisers, insurers and client executives, turning incident findings into practical recovery actions.Lead cyber recovery workstreams during major incidents.Deliver hands-on remediation across Active Directory, Windows, Linux, network, cloud and endpoint estates.Drive patching and vulnerability remediation, prioritised on business risk and threat actor behaviour.Review and redesign network segmentation, firewall rules and administrative access paths to reduce reinfection risk.Establish isolated recovery environments, validate backups and sequence secure restoration.Define phased recovery plans covering stabilisation, remediation and longer-term security roadmaps.Manage delivery end to end, including reporting, proposals and mentoring junior team members.Between incidents, you will support clients on resilience and recovery readiness work, and help build the internal capability across playbooks, tooling, automation and lab environments.The ideal candidate will haveDeep hands-on infrastructure experience across Windows Server, Active Directory, Linux, networking and cloud, including Azure, AWS and Microsoft 365.Proven experience supporting cyber incident recovery: ransomware, Active Directory compromise, network intrusion or large-scale infrastructure incidents.Demonstrated capability leading remediation, including identity hardening, secure rebuild, backup validation and service restoration.A solid grasp of network architecture and security, with the ability to redesign environments to improve resilience.A broad understanding of the incident response lifecycle, from triage through containment, eradication and recovery., Strong stakeholder
Requirements
management skills, with credibility in front of both engineers and executives.Effective project and delivery management capability across multiple concurrent workstreams.Current SC or DV clearance, or eligibility and willingness to obtain it.Relevant degree or industry certification is welcome, though hands-on experience counts equally.Package£75,000 - £85,000 base salaryExcellent benefits packageInvestment in industry certifications and structured trainingAccess to nationally significant incidents across government and critical infrastructureA clear path into senior cyber response and recovery leadershipThis would suit someone who has come up through infrastructure, moved into cybersecurity, and enjoys being the person who actually rebuilds the environment when everything is on fire. You will need to be technically credible with engineering teams and equally clear with a board that wants to know when the business will be running again.Please message me directly if you would like to discuss the role in confidence.
Benefits & conditions
Cyber Response ManagerSalary: £75,000 - £85,000 + excellent benefitsLocation: United Kingdom - Variety of office locations availableWorking pattern: hybrid, 60% with clients or in the office, 40% elsewhere. On-call rotation and short-notice travel of up to 2 to 3 weeks.Clearance: current SC or DV, or eligibility and willingness to obtain it.