Posted 23 July, 2026
Cyber Incident Response Manager
Hays Specialist Recruitment Limited
Liverpool, ENG, GB
Full Time
Job Description
Contract
\nDay Rate: £750 per dayIR35 Status: Outside IR35Contract Length: 6 months initiallyLocation: Hybrid - Liverpool
\nOverview
\nI'm supporting an organisation seeking an experienced Cyber Incident Response Manager to lead and mature its Incident Response capability across a complex enterprise environment.
\nResponsibilities
\n- \n
- Own and manage cyber incidents from detection through to resolution. \n
- Review, enhance, and develop Incident Response frameworks, runbooks, and playbooks. \n
- Ensure alerts from SIEM, EDR, CTI, and SOC services are effectively integrated into Incident Response processes. \n
- Lead tabletop exercises and testing activities. \n
- Work closely with SOC, Threat Intelligence, Technology, and Business teams. \n
- Drive continual improvement of the Incident Response service. \n
- Support both BAU incidents and strategic capability development. \n
- Manage incidents relating to both IT and OT environments. \n
Essential Experience (Non-Negotiable)
\n- \n
- Proven Incident Response in leading within large enterprise environments. \n
- Experience leading and managing cyber incidents. \n
- Strong experience in leading on the creating, reviewing, and improving runbooks and playbooks. \n
- Experience designing or enhancing Incident Response frameworks. \n
- Experience running tabletop exercises. \n
- Strong understanding of SIEM, EDR, SOC and Threat Intelligence integration. \n
Environment
\n- \n
- Microsoft Sentinel \n
- Microsoft Defender for Endpoint \n
- Recorded Future \n
- Darktrace \n
- Microsoft Purview \n
- ThreatLocker \n
If you are interested in the role please send you CV
\nHays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at hays.co.uk
