KPMG UK
Incident Response Manager

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
About the role
This Grade C role sits within Operational Security in Group Corporate Services, the internal specialist capability that helps KPMG's people and business operate effectively and securely. KPMG is evolving Security Operations across the UK and Switzerland to create a more integrated, intelligence-led approach to cyber resilience.
As Security Incident Response Manager, you will lead the Tier 2 Incident Response function and be accountable for managing cyber security incidents escalated by the Security Operations Centre. You will combine team leadership with hands-on technical direction, stakeholder coordination, and continuous improvement across a diverse technology environment.
The role is based in the UK with hybrid working. Participation in the Security Operations on-call rota is required, including acting as a senior escalation point for high-priority and major incidents outside standard business hours. You must be eligible for Security Check clearance or able to obtain it.
Roles and responsibilities
- Lead, coach, and develop Tier 2 Incident Response Analysts, setting clear standards and providing technical guidance.
- Direct complex investigations across endpoint, identity, email, cloud, and network environments, coordinating activity from escalation through recovery.
- Provide technical and operational leadership during major incidents, enabling clear decisions, effective communication, and coordinated action.
- Partner with the Security Operations Centre to improve triage quality, escalation routes, and response effectiveness.
- Work with Threat Intelligence, Detection Engineering, Vulnerability Management, and Security Engineering teams to improve visibility, detections, and response capability.
- Lead post-incident reviews and root cause analysis, turning lessons learned into practical improvements that strengthen resilience.
- Develop and maintain incident response playbooks, procedures, and operational standards, and support simulations and readiness exercises.
- Influence the UK and Switzerland Security Operations strategy, engage senior stakeholders across technology, risk, legal, and privacy, and provide senior on-call cover for major incidents.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Experience and skills needed


Get help with your application
Your very own career expert that helps elevate your application to the next level.
- Experience leading complex cyber security incident investigations within a Security Operations Centre, incident response, or cyber defence environment, including containment, eradication, and recovery.
- Experience managing and developing technical security teams through coaching, mentoring, and clear operational leadership.
- Practical experience investigating threats across endpoint, identity, email, cloud, and network technologies.
- Experience coordinating major incidents and communicating clearly with technical and non-technical stakeholders, including senior decision-makers.
- Experience improving incident response services through playbooks, post-incident reviews, root cause analysis, exercises, or operational process development.
- Experience working in a large, complex, or regulated organization and making evidence-based decisions under pressure.
- Experience with Microsoft Sentinel, Microsoft Defender technologies, Microsoft Purview, digital forensics and incident response tools, security orchestration and automation, threat hunting, or detection engineering would be an advantage. Certifications such as GCIH, GCFA, CISSP, or an equivalent are also desirable.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location