Now hiring

Head of Cyber Defence & Incident Response @ Quadient

East Bay Lane 14, LondonOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

Salary: £49,000 - 89,000 per year

Requirements: Strong experience leading cyber defence/SOC and incident response, including major incident coordination, investigation, containment and recovery.Hands-on understanding of detection and response tooling and concepts, including SIEM, SOAR, EDR/XDR, NDR, email security and log pipelines, with experience in tuning, use-case engineering and operational workflows.Proven experience managing an MSSP or outsourced SOC capability, including SLAs/KPIs, service governance, escalations and continuous improvement.Strong experience running vulnerability management and threat management programmes, including prioritisation based on exploitability, exposure and business impact.Knowledge of incident response processes, digital forensics fundamentals, evidence handling, and working with legal/privacy and external forensic partners.Experience defending hybrid environments, including identity signals, network telemetry, endpoint visibility and cloud-native security monitoring.Ability to operate under pressure and lead cross-functional teams through high-severity incidents, communicating clearly and making timely risk-based decisions.Fluent in English with excellent written and verbal communication skills, including producing clear architecture guidance, standards and security design documentation.Desirable: certifications such as GCIH, GCIA, GNFA, CISSP, CISM, or equivalent experience in incident response and security operations.Desirable: experience with threat hunting, purple teaming, and using MITRE ATT&CK to structure detections, gaps analysis and defensive improvements.Desirable: experience with security operations in cloud platforms and common tools such as Microsoft Defender, Sentinel, Splunk, CrowdStrike, Palo Alto, and AWS/Azure security services.Desirable: calm under pressure, highly collaborative, operationally rigorous, and committed to continuous improvement. Responsibilities: Own the incident response lifecycle, ensuring playbooks, tooling and decision-making processes are in place and exercised.Lead and coordinate response to security incidents, acting as incident commander where required, including stakeholder communications, forensic triage and recovery coordination.Manage the MSSP relationship end-to-end, including service definition, SLAs/KPIs, escalation paths, continuous improvement plans, quality assurance and commercial governance.Optimise security monitoring and response tooling across technology teams, including use-case coverage, alert quality, automation, logging strategy and operational runbooks.Own the vulnerability management programme across on-prem and cloud, including scanning coverage, prioritisation, remediation SLAs, exception handling, verification and executive reporting.Drive threat management by operationalising threat intelligence into defensive priorities such as detection use cases, hardening actions, control uplift and proactive hunting themes.Lead continuous improvement of the defence stack by rationalising tools, tuning detections, improving signal quality, reducing noise and expanding automation.Establish and run a threat hunting programme using hypothesis-driven approaches, telemetry coverage mapping and lessons learned from incidents and red-team activity.Run regular tabletop exercises and simulations, including ransomware and cloud compromise scenarios, to validate and improve roles, escalation paths and technical procedures.Own incident response governance, including severity model, on-call and escalation processes, evidence handling, case management and alignment to legal/regulatory obligations.Define and report cyber defence metrics, presenting insights and recommendations to senior leadership.Lead post-incident reviews and root cause analysis, ensuring lessons learned translate into measurable improvements.Support business continuity and crisis management processes during cyber events, contributing to executive updates and coordinated communications with Legal/Privacy and other stakeholders.Maintain and improve incident response documentation and readiness, including playbooks, runbooks and contact trees, and ensure training is delivered for technical responders and business stakeholders.Communicate cyber risk and active incidents clearly to technical and non-technical audiences, including concise executive briefings and after-action summaries. Technologies: AWSAzureCloudSupportNetworkSecuritySplunk More:

We are Quadient, supporting businesses of all sizes in their digital transformation and growth journey through reliable, secure and sustainable automation processes. Our teams are driven by the connections we create with our clients and each other, and we offer a future-focused environment where you can grow your career, develop your skills and make a real impact. We offer a hybrid work model, access to global learning opportunities through our 24/7 online learning platform, inclusive communities, a comprehensive rewards package covering wellness and work/life balance, a generous referral scheme and an employee assistance program for mental health support. Our Smart Work approach balances flexibility with collaboration, and our values of Empowerment, Passion, Inspiration and Community define how we work together in a people-first culture.

last updated 36 week of 2026

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores