Back to results · Merseyside

Job verified 3 hours ago

Cyber Incident Response Team Lead (CSIRT)

Robert Walters·Merseyside (North West England)
£500 – £600 / day
Vox Summary
  • Role Responsibilities: Lead end-to-end response during security events, coordinate triage, containment, investigation, and recovery; establish and run the CSIRT operating model and develop scenario playbooks.
  • Key Requirements: Proven background in incident command, digital forensics, or high-pressure incident triage; experience building incident response frameworks and runbooks; incident response designations like GCIH, GCFA, GNFA, or CREST are highly desirable.
  • Conditions/Benefits: Role involves establishing operational runbooks from scratch and leading technical containment and recovery during active events.
Apply on sourceYou are leaving VoxJobs for reed.co.uk — the application is handled directly by the company. reed.co.uk

Job description

Blends hands-on incident command and digital forensics with programmatic capability building. Establishes the CSIRT operating model, creates scenario playbooks (ransomware, exfiltration) from scratch, and leads technical containment/recovery during active security events. About the RoleMy client is a well established business, looking for a hands-on CSIRT Lead to establish and run the cyber incident response capability across a complex, multi-site industrial and corporate estate. The role blends hands-on incident command and digital forensics coordination with the programmatic build-out of incident playbooks and operational runbooks from scratch. Key Responsibilities • Lead end-to-end response during active security events, coordinating technical triage, containment, forensic investigation, and recovery. • Build out the internal CSIRT operating model, defining runbooks for high-impact scenarios (e.g., ransomware, supply chain compromise, data exfiltration). • Coordinate crisis response communications across internal business functions, legal counsel, PR, and external regulatory bodies. • Conduct thorough post-incident reviews (PIRs) to extract root cause lessons and drive continuous security control improvements. What We Are Open To • Proven background in incident command, digital forensics, or high-pressure incident triage. • Experience building or maturing incident response frameworks and runbooks. • Incident response designations such as GCIH, GCFA, GNFA, or CREST qualifications are highly desirable. Robert Walters Operations Limited is an employment business and employment agency and welcomes applications from all candidates

Transparency panel

Original source
reed.co.uk
Posted
Jul 23, 2026 · true date
Last verified
3 hours ago
Quality score
65/100
Salary stated30
Company identified0
applyUrl0
postedAt15
Complete description20

Similar

Jobs like this one.

Lead AI Security Architect

Hays Specialist Recruitment Limited
LondonHybrid6 months initially
£700 – £800 / day
Newvia reed.co.uk·12 hours ago65/100

Something wrong with this listing? Report a fraudulent or outdated job