Rodeo
Get started

LRQA

Senior Security Consultant (Incident Response)

Birmingham
Posted about 14 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Job ID: 44293 Location: UK - Home Based
Position Category: Consulting
Position Type: Employee Regular

About LRQA

At LRQA our focus has always been on excellence in cyber security. We have teams that offer world-class services in red teaming, penetration testing, threat intelligence, research and development, detection and response, governance, risk, and compliance, and plenty more. Our business is global and so are our clients. We work closely with central banks, central and local government, critical national infrastructure, large retailers, and plenty more besides!

We’re an award-winning provider of cyber security services and we’re at a very exciting stage of development. We are looking for the right people to join us as we embrace the challenges thrown up by the advancements within the IT industry and within the threats faced. LRQA will be at the forefront of this arena and we want to seek the right people to join the team and make it happen.

You can find out more about us at https://www.lrqa.com/en-us/cyber-security-services/.

The Role

This is a new, exciting opportunity for a Senior Security Consultant to join LRQA’s existing dynamic Cyber Incident Response Team.

Location

This role follows a hybrid working arrangement and will involve working on client sites and from the office from time to time. We support remote work across the UK; however, the main office is in Birmingham. Applicants are required to be resident in the UK.

What You’ll Be Doing

The successful candidate will be responsible for responding to and leading cyber incidents within LRQA Group and LRQA’s professional service and Defensive Security Service (DSS) customers, providing education (internally and externally) and improving the team’s capability, in line with managerial direction.

The role will lead a team of responders, as well as conduct solo incident investigations, where the actor operates with a high level of sophistication (Organised Crime or above) using agreed mitigation, preparedness, and response and recovery approaches, as needed, to minimise the impact of a cyber incident.

They will design and execute training engagements that will prepare all levels of stakeholders for a cyber incident, and keep up to date with the latest CTI industry developments, security developments, vulnerabilities, attacks, news and techniques aligned to Mitre ATT&CK and use this to further the team’s capability.

They are expected to operate autonomously using judgement to escalate issues to senior management when appropriate.

They must continue to maintain a relevant industry level certification preferably the CREST CCIM and at least one other CREST Certified level certification in the Incident Response field, for which LRQA will provide support.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Key Role Responsibilities

The following list is indicative of the overall expectations of the role (not exhaustive):

  • In conjunction with the Customer Engagement Manager and Cyber Incident Manager, manage the collective technical response to customer cyber incidents.
  • In conjunction with the DSS leadership, develop and drive the IR strategy.
  • In conjunction with the DSS leadership, develop, refine and monitor IR policies, procedures and technical capability.
  • Conduct analysis and investigation of cyber security events across Windows, Linux, Cloud and Hybrid environments.
  • Conduct digital imaging and forensic investigation tasks on Windows and Linux hosts.
  • Conduct initial triage on suspicious artefacts using both commercial and bespoke tools
  • Provide customer training engagements to develop internal and external stakeholder preparedness for dealing with cyber incidents.
  • Provide written and verbal reports to the wider IR team, senior business partners (internal and external).
  • Conduct ongoing research around the threat landscape, including threat actors, TTPs and develop IR actions, investigation strategies and tooling.
  • A team-first, collaborative approach working across all relevant technical teams to identify opportunity for improvement in detection sets.
  • Excellent problem-solving skills and self-motivated to learn and upskill regularly.
  • A strong desire to continually challenge and develop yourself as part of a fast-paced, high-performing team.

Requirements

The following list of requirements are pre-requisites for the role:

  • Demonstrably strong incident management and analytical skills.
  • Demonstrably strong written and speaking English skills.
  • Demonstrably strong understanding of Threat Actor TTP’s.
  • Demonstrably strong commercial awareness.
  • Demonstrable ability to work on own projects and within a team.
  • At least 36 months of relevant IT Security industry experience in past 4 years.
  • An ability to lead, teach, present and inspire customers and the wider team.
  • Ability to travel to UK customer locations where requested and non-UK customer locations where mutually agreed.
  • Ability to join 24/7 on-call rota.

We value capability over credentials. We’re not looking for badge collectors. That said, one or more of the following will serve as a distinct advantage:

  • CREST CCIM / CRIA
  • GIAC GCFA / GCIH / GNFA
  • UKSC Chartered / Principal Professional in IR
  • Similar

Why Join Us?

We’ve built a team that people tend to stay with – and that’s intentional. Our cyber unit includes the full spectrum of services from SOC analysis and Incident Response through Penetration Testing, Adversarial Simulation (Red Teaming) and Threat Intelligence. There are always people available to help you and always more to learn and we have excellent and varied career progression opportunities.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

We push ourselves to be excellent, so if you enjoy solving complex technical challenges and working in an environment that supports continuous development, you’ll fit right in! Please visit our website to understand more about how we develop our people, work on cutting edge engagement and offer multiple career progression paths.

What We Offer

We offer you an exciting working environment with intellectual challenges, high levels of responsibility and client exposure and a collaborative team with strong technical depth. An attractive package is available for the right candidates.

Apply?

Interested? Apply via the ‘apply’ button with your resume and cover letter.

Pre-Employment Checks

If you are successful in securing a role with us, we will carry out preemployment checks in accordance with what is permitted under local law.

These checks may include, where legally allowed: right to work, identification, verification of employment history, education, and criminal record checks.

We will engage our third-party background screening provider, Cfirst to conduct these checks on our behalf. Cfirst performs all processing in full compliance with applicable data protection laws and adheres to strict legal, regulatory, and ethical obligations in handling personal data.

Any personal information collected for the purpose of these checks will be used solely for evaluating your suitability for employment and will be retained only for as long as necessary to fulfil these purposes and meet legal requirements.

Your data will be stored securely and managed in accordance with all relevant privacy legislation.

If you have any questions or concerns about the preemployment checks please contact us at Onboarding@lrqa.com

If you have any questions or concerns on how your data will be handled, please contact us as dataprotection@lrqa.com

At LRQA, we believe that as a leading Global Leading Assurance and Risk Management Service provider, our talented people are our risk management advantage.

We believe the best outcomes come from diverse perspectives, shared ambition and working together with integrity. That's how we build a workplace where everyone can contribute, grow and thrive.

Guided by Vision and powered by Expertise, we're united by a shared purpose. If you're driven to make a difference, you'll belong here.

All rights reserved. Terms of use. Privacy Policy.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Incident response
Cyber security
Threat intelligence
Digital forensics
Windows
Linux
Cloud security
Mitre ATT&CK
Problem-solving
Stakeholder management
Technical reporting
Risk management
Vulnerability assessment
Triage

Location

Birmingham, England, United Kingdom

Sign up to applySee more jobs like this