Security Incident Response Manager
Job details
---------------
Location: Aberdeen, Birmingham, Bristol, Cambridge, Cardiff, Edinburgh, Glasgow, Leeds, London, Manchester, Milton Keynes, Newcastle upon Tyne, Nottingham, Reading, South Coast \- Southampton, Watford
Capability: Corporate Services
Experience Level: Manager
Type: Full Time
Business Area: Digital (Internal)
Contract type: Permanent
Job description
-------------------
About the role
This Grade C role sits within Operational Security in Group Corporate Services, the internal specialist capability that helps KPMG's people and business operate effectively and securely. KPMG is evolving Security Operations across the UK and Switzerland to create a more integrated, intelligence\-led approach to cyber resilience.
As Security Incident Response Manager, you will lead the Tier 2 Incident Response function and be accountable for managing cyber security incidents escalated by the Security Operations Centre. You will combine team leadership with hands\-on technical direction, stakeholder coordination and continuous improvement across a diverse technology environment.
The role is based in the UK with hybrid working. Participation in the Security Operations on\-call rota is required, including acting as a senior escalation point for high\-priority and major incidents outside standard business hours. You must be eligible for Security Check clearance or able to obtain it.
Roles and responsibilities
- Lead, coach and develop Tier 2 Incident Response Analysts, setting clear standards and providing technical guidance.
- Direct complex investigations across endpoint, identity, email, cloud and network environments, coordinating activity from escalation through recovery.
- Provide technical and operational leadership during major incidents, enabling clear decisions, effective communication and coordinated action.
- Partner with the Security Operations Centre to improve triage quality, escalation routes and response effectiveness.
- Work with Threat Intelligence, Detection Engineering, Vulnerability Management and Security Engineering teams to improve visibility, detections and response capability.
- Lead post\-incident reviews and root cause analysis, turning lessons learned into practical improvements that strengthen resilience.
- Develop and maintain incident response playbooks, procedures and operational standards, and support simulations and readiness exercises.
- Influence the UK and Switzerland Security Operations strategy, engage senior stakeholders across technology, risk, legal and privacy, and provide senior on\-call cover for major incidents.
- Experience leading complex cyber security incident investigations within a Security Operations Centre, incident response or cyber defence environment, including containment, eradication and recovery.
- Experience managing and developing technical security teams through coaching, mentoring and clear operational leadership.
- Practical experience investigating threats across endpoint, identity, email, cloud and network technologies.
- Experience coordinating major incidents and communicating clearly with technical and non\-technical stakeholders, including senior decision\-makers.
- Experience improving incident response services through playbooks, post\-incident reviews, root cause analysis, exercises or operational process development.
- Experience working in a large, complex or regulated organisation and making evidence\-based decisions under pressure. Experience with Microsoft Sentinel, Microsoft Defender technologies, Microsoft Purview, digital forensics and incident response tools, security orchestration and automation, threat hunting or detection engineering would be an advantage. Certifications such as GCIH, GCFA, CISSP or an equivalent are also desirable.
-----------------------------------
Corporate Services operates as a £multi\-million business within our business and, through our combined efforts, we enable the firm to serve our people, our clients and wider society. The internal expertise, advice, support and services we provide to our client\-facing business are fundamental to the success of our firm. Through collaboration, agility, fresh thinking and innovation, we help our people across the firm to work in a way that’s smarter and more sustainable. We’re a cross\-functional team, bringing together technically knowledgeable experts across a wide range of critical activities to help grow, run and protect our business. Our areas span Corporate Affairs and Marketing, Digital, Finance and Commercial, People and Resourcing, and Risk and Legal.
Read about Corporate Services
Service Overview
--------------------
Digital is the firm's primary provider of internal business and technology services, data, and innovation. We deliver secure, resilient, and standardised technology solutions that ensure our operations run seamlessly and empower colleagues to provide exceptional client service. Our mission is to propel KPMG into the future. We drive our digital strategy, safeguard against cyber threats, manage data responsibly, and provide cutting\-edge tools for seamless collaboration. Through innovation and accelerated adoption of digital and AI capabilities, we support growth and transformation, unlocking significant value for both our colleagues and clients.
Read about Digital
This listing is from Indeed. View original listing ↗