Rodeo
Get started

Outbreach

Cyber Incident Responder

United Kingdom
£120k/yr
Posted about 17 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

About Outbreach

Outbreach is a specialist cyber incident response and crisis management firm working with mid-market organizations in the UK and the Gulf. We bring together incident management, digital forensics, legal, crisis communications, and recovery under one roof so that a client in the middle of a breach has one partner rather than five. We are recruiting on-call bench Incident Responders who can be called on to supplement our permanent team when clients experience an incident.

The Role

The Incident Responder (IR) is the main person responsible for the technical operational tasks necessary to provide our clients with a high-quality, rapid, and comprehensive response to a breach. They will be at the forefront of all incidents and absolutely critical to the successful resolution. They will be intimately familiar with a wide variety of attacks, from ransomware to BEC, insider threat, and DDoS, to name just a few examples.

The IR will be expected to work closely with Incident Managers and feed information to and from specialists in other areas of the incident response such as forensic, legal, or PR. The IR will be able to handle pressure, multiple conflicting demands, and possibly chaotic environments with limited knowledge of the company or crisis. They will be expected to help bring order to the incident and contribute to the swift attainment of the client's objectives.

Key Responsibilities

  • Leading the restoration of our client's IT systems after a cyber attack.
  • Working with the Incident Manager to help triage an initial call.
  • Assessing the state of the IT systems, reporting on the damage incurred, and any other exposure.
  • Implementing temporary infrastructure to sustain key business operations during the incident.
  • Collecting and analyzing intrusion artefacts such as logs, source code, and malware.
  • Conducting a root cause analysis to determine how the attack happened, any lateral movement, or infection.
  • Fully cleaning and removing any residual infection, malware, or other damage caused by the attacker.
  • Ensuring that vulnerabilities are remediated to prevent future reinfection by the same or similar method.
  • Collaborating with Forensic, Legal, PR, Comms, and third parties to ensure a comprehensive response.
  • Monitoring external sources to determine threats, evidence of breaches, and breach impact.
  • Documenting response activities, findings, and recommendations.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Outside of Live Incidents

  • Engaging with proactive audit and investigations to plan for a breach.
  • Conducting threat hunting and other pre-breach or breach confirmation operations.
  • Helping to refine and improve playbooks, runbooks, and overall response methodology.

Skills and Experience

  • Cyber security experience is required for this role, including 3+ years as a cyber incident responder.
  • 5+ years in a technical support or engineering role, or demonstrable advanced technology knowledge.
  • Strong knowledge of operational security across multiple platforms and all major cloud providers.
  • Certifications such as GCIH, GCIA, or GCFA/GCFE.
  • Real enthusiasm for cyber security demonstrated by research, testing, or other activities.
  • Advanced knowledge of the MITRE ATT&CK framework and common TTPs.
  • Extensive experience with Business Continuity and Disaster Recovery.
  • Incredibly methodical and attentive to the smallest of details.
  • Strong communication skills and presentable to clients and senior executives.

Highly Desirable but not Vital

  • Experience gained from a consultancy or highly regulated organization.
  • Experience working in a 24/7 operation.
  • Previous experience as a SOC analyst or Red Team.
  • Risk and compliance practices.
  • Working knowledge of Public Relations, Communications, Marketing, and Law.
  • Experience within high pace, high-pressure environments and desire to work in incidents and crisis management.
  • Security clearance.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Commitment

As a bench Incident Responder, you will be called whenever a suitable incident is raised by our clients, which matches your skill and experience level. There is no expectation for you to remain on call or to accept any incident when you are not available. However, once you commit to an incident, you will become a key member of the response team and will be expected to remain engaged for the duration of the incident. At the least this would be for one day, but in most cases will likely be for two to four weeks.

Full training and support will be provided to successful candidates, who will be expected to attend regular paid meetings to ensure they are familiar with the company, its methodologies, and market.

Pay and Benefits

  • Remote working with much of your work being done where you please.
  • Flexible hours that can be scaled up or down as suits you.
  • Working in an expanding cyber security business where you can grow in your career and help shape the business.
  • Training and development budget aligned with formal relevant qualifications.
  • Hourly pay equivalent to over £120,000 a year, with a significant increase for unsociable hours if needed.
  • Eligible for company stock options, subject to minimum hours.

Location: United Kingdom, remote.
Engagement: On-call bench role, hourly paid.
Full details and the application form are also at outbreach.com/career/incident-responder-uk/

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

United Kingdom

Sign up to applySee more jobs like this