Technical Lead, Incident Response
S-RM
| Company | S-RM |
| Category | Engineering |
| Location | London |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Lead |
| Salary | Not stated by the employer |
| Posted | 19 Mar 2026 |
| Last verified | 3 Aug 2026 |
| Source | Employer ATS (greenhouse) |
Description
WHO WE ARE
S-RM is a global intelligence and cyber security consultancy. Since 2005, we’ve helped some of the most demanding clients in the world solve some of their toughest information security challenges.
We’ve been able to do this because of our outstanding people. We’re committed to developing sharp, curious, driven individuals who want to think critically, solve complex problems, and achieve success.
But we also know that work isn’t everything. It’s about the lives and careers it helps us build. We’re immensely proud of this culture and we invest in our people’s wellbeing, learning, and ideas every day.
We’re excited you’re thinking about joining us.
WORKING IN CYBER AT S-RM
Our Cyber Security division is the fastest-growing part of S-RM. The cyber sector is always evolving, and our Advisory , Ethical Hacking, and Incident Response practices are in more demand than ever.
We’re building a team to meet this challenge. We’re quick to respond, innovate, and improve. We don’t get too hung up on hierarchy or bureaucracy. If your ideas are good enough, we’ll empower you to implement them. If you’re the best person to talk to a customer, you’ll get that opportunity, regardless of the title in your email signature. And when you need a hand, your team will always have your back.
We also don’t believe there’s a typical cyber security professional. We’ve built a team of intelligence analysts, technical specialists, software developers, investigators, risk managers, and more. You’ll always find a range of perspectives and expertise to help you learn and grow.
If that sounds like your kind of team, we’d like to hear from you.
THE ROLE
Our Incident Response Consultants are a critical part of our Cyber Security consulting practice’s success. As a Technical Lead, you will deploy your incident response expertise in a senior, client‑facing delivery role across our incident response services.
You will work across the full lifecycle of security incidents to help our clients respond and recover, spanning both traditional incident response scenarios (such as ransomware, business email compromise and intrusion investigations) and modern incidents affecting cloud platforms, CI/CD pipelines and software delivery environments.
WHAT YOU WILL DO
You will be responsible for leading and delivering technical investigations for clients, including:
Leading technical incident response engagements from first contact through to closure
Acting as the primary technical resource on response cases, applying your own expertise and providing guidance to colleagues on the project team.
Overseeing host‑, network‑ and cloud‑based investigations , including:
Triage and containment
System recovery and remediation support
Technical evidence collection and forensic analysis
Log, malware and root cause analysis
Investigating a wide range of incident types , including but not limited to:
Ransomware and extortion incidents
Business Email Compromise (BEC)
Unauthorised access and data breaches
Incidents involving cloud environments, CI/CD pipelines, automation and software supply chains
Applying cloud and DevOps‑related expertise where required , for example when incidents involve:
Compromised cloud identities, APIs or control planes
Abuse of CI/CD pipelines, source code repositories or secrets
Infrastructure‑as‑Code and automated deployment wor