> Markdown version of [/jobs/ext/85562-incident-response-engineer](https://www.wearedevelopers.com/jobs/ext/85562-incident-response-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Incident Response Engineer - **Company:** Checkout.com - **Location:** London, UK - **Contract:** Permanent contract - **Skills:** Software as a Service, Cloud Computing, Cyber Security, Security Information and Event Management, Malware, Vulnerability Analysis - **Published:** May 28, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=061224dbd78a61e8 ## About the Role Do you have experience in Management?, * Proven, hands-on experience leading response to real security incidents * Strong investigation capability across endpoint, identity, and cloud environments * Demonstrated experience prioritising vulnerability or patching risk in large, complex estates * Ability to remain decisive and effective during incidents, and analytical between them * Clear communicator who can influence outcomes without needing direct ownership of every fix * Pragmatic mindset: reduce risk first, optimise later * DFIR, forensics, or malware analysis experience * Proven ability to correlate vulnerability data with runtime telemetry and attacker behaviour to drive actionable risk reduction * Cloud-first incident response or exposure management experience * Exposure to compliance-driven security requirements * Experience working alongside vulnerability scanning platforms without being constrained by them ## Description This role exists to ensure security incidents are rare, contained, and unsurprising. You will own the technical direction of security incident response and response readiness across the company. When a serious incident occurs, you lead from the front - investigating, containing, and driving resolution with calm authority. When incidents are not happening, you are actively eliminating the conditions that would cause the next one. This is not a role for someone who waits for alerts. It is for someone who constantly asks "what will break next, and why?" - and then fixes that problem before an attacker finds it. You will operate across endpoint, identity, cloud, and SaaS environments, working closely with Security Operations, IT, and Engineering to reduce real risk, not theoretical risk. What you'll be responsible for Incident Response & Technical Leadership * Leading the end-to-end technical response to high-severity security incidents * Owning investigation, containment, eradication, and recovery activities * Acting as the senior technical authority during live incidents * Providing clear, decisive guidance to Security Operations under pressure * Coordinating response across endpoint, identity, cloud, and SaaS platforms * Supplying executives, legal, and risk stakeholders with accurate technical context and impact assessments * Ensuring incidents are driven to resolution, not just stabilised Response Readiness & Proactive Risk Reduction * Designing, maintaining, and continuously improving incident response playbooks and runbooks * Identifying systemic weaknesses that increase incident likelihood or blast radius, including: + Unpatched or inconsistently patched systems + Exposed services and misconfigurations + Degraded or ineffective controls * Using SIEM and security tooling to prioritise patching and vulnerability risk based on real exposure and exploitability, not CVSS scores alone * Partnering with IT, Cloud, and Engineering teams to drive remediation based on business risk * Tracking remediation through to completion and validating effectiveness post-fix Learning, Detection, and Maturity * Turning incidents, near-misses, and exposure findings into: + Improved detections + Stronger preventative controls + Faster and less disruptive response * Driving readiness through simulations, tabletop exercises, and scenario testing * Raising the overall maturity of the Cyber Security function by pushing advanced response and exposure management practices into BAU operations ## Related Videos - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)