KPMG UK
Incident Release Manager

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Incident Release Manager
Location: London
About the role
This role sits within Group Corporate Services, which supports KPMG's people and business through firmwide specialist services and operational capabilities. Within Security Operations, you will join the Tier 2 Incident Response team and take ownership of complex investigations across a diverse technology environment serving KPMG in the UK and Switzerland.
You will act as a senior escalation point for high-priority and major cyber security incidents, combining hands-on technical investigation with calm coordination and clear communication. The role is based in the UK on a hybrid basis and is at Grade D. Participation in the Security Operations on-call rota is required, including providing technical and operational leadership outside standard business hours. You must be eligible for Security Check clearance or able to obtain it.
Roles and responsibilities
- Lead investigations into complex and high-severity cyber security incidents, establishing the scope, business impact and risk.
- Coordinate containment, eradication and recovery activities so incidents progress efficiently to a controlled resolution.
- Provide senior technical guidance to analysts and act as an escalation point during high-priority and major incidents, including through the on-call rota.
- Conduct forensic investigation and evidence collection across endpoint, identity, cloud, email and network technologies.
- Produce clear investigation timelines, root cause analysis and post-incident reports for technical and business stakeholders.
- Work with Threat Intelligence and Detection Engineering teams to apply knowledge of emerging threats, improve detection coverage and strengthen investigations.
- Lead proactive threat hunting to identify previously undetected activity, security weaknesses and opportunities to improve controls.
- Improve incident response playbooks, processes, automation and operational standards, sharing knowledge across the wider cyber security function.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Experience and skills needed
- Demonstrable experience in security operations, incident response, cyber defence or digital forensics, including ownership of escalated security incidents.
- Evidence of investigating threats across endpoint, identity, cloud, email and network environments and translating findings into appropriate response actions.
- Practical knowledge of attacker tactics, techniques and procedures, with experience applying this knowledge to investigations or threat hunting.
- Experience leading technical investigations, building incident timelines and completing root cause analysis and post-incident reporting.
- Strong analytical and problem-solving skills, with evidence of making sound decisions and coordinating activity during high-pressure incidents.
- Clear written and verbal communication skills, with experience explaining technical findings to technical and non-technical stakeholders and collaborating across security teams.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Experience and skills beneficial:
- Experience with Microsoft Sentinel, Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Cloud, Microsoft Purview, digital forensics and incident response tools, security orchestration and automation platforms, threat hunting methods, or cloud security technologies across Microsoft Azure, Amazon Web Services or Google Cloud Platform.
- Relevant certifications, such as Microsoft Certified: Security Operations Analyst Associate (SC-200), CompTIA Cybersecurity Analyst (CySA+), GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA), Microsoft Certified: Azure Security Engineer Associate (AZ-500), or an equivalent qualification.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location