Haystack
← Back to Jobs
Temporary/Casual
Other

Incident Response Lead

McGregor BoyallLondon🇬🇧United KingdomPosted 30 Jul 2026

Quick Overview

Work Type
On Site
Schedule
Temporary/Casual
Level
Mid Senior

Job Description

Cyber Operations & Incident Response Lead, Cloud, Security, Hybrid

You will lead and line-manage the London-based cyber security team, delivering cyber operations services, assure the local delivery of globally-prioritised work, and act as Incident Commander and first point of escalation for cyber security in London.

The role additionally leads to the Endpoint, Platform and Incident Response capability, owning the global prioritisation of that backlog against enterprise cyber risk.

Experience required:
A strong, hands-on technical background in operational cyber security spanning endpoint & EDR, identity & Active Directory, Microsoft 365 & Azure, network/ZTNA, and SIEM/log management - able to act as a senior technical authority within the team. Tools: Azure, Active Directory, CrowdStrike Falcon, Zscaler, Vulnerability Management (Qualys, Tenable Nessus, Rapid7), Incident Response ownership experience & Playbooks/Mitre Att&ck)
Demonstrable experience leading cyber security incident response (incident command), from detection through containment and remediation.
Working knowledge of MITRE ATT&CK and at least one recognised control framework (ISO 27001, CIS or NIST).
Risk-based prioritisation of remediation using threat intelligence.
Own the global prioritisation of the Endpoint, Platform and Incident Response backlog, ordered against the enterprise cyber risk register and exploitation-based intelligence (eg MITRE ATT&CK).
Curate the backlog from inputs across Houston and London, including the endpoint detection and response (CrowdStrike) execution lead.
Maintain alignment of this domain to the enterprise risks for endpoint compromise, detection and containment, and cyber resilience.
Operate within the Global Head's monthly prioritisation cadence; prioritisation across other domains remains with the Global Head.
Assure local execution of globally-prioritised work to agreed quality, pace and outcomes.
Drive London-side delivery of in-flight initiatives through completion.
Track and chase vulnerability remediation and patching on London-managed systems, escalating blockers.
3 days on site required in central London

Cyber Operations & Incident Response Lead, Cloud, Security, Hybrid

McGregor Boyall is an equal opportunity employer and do not discriminate on any grounds.

Skills

Active Directory
Azure

Similar jobs