Impress employers and recruiters.
Choose from hundreds of resume examples.

Impress employers and recruiters.
Choose from hundreds of resume examples.
Tailor your resume to this Incident Response Manager role.
Rezi rewrites your resume against KPMG UK's job description. Free.

Tailor your resume to this Incident Response Manager role.
Rezi rewrites your resume against KPMG UK's job description. Free.
Don't guess if your resume is good enough.
See how it scores against the Incident Response Manager posting at KPMG UK — free, in seconds.

Don't guess if your resume is good enough.
See how it scores against the Incident Response Manager posting at KPMG UK — free, in seconds.
About the Role
This Grade C role within Operational Security leads the Tier 2 Incident Response function, managing cyber security incidents escalated by the Security Operations Centre. It combines team leadership with hands-on technical direction, stakeholder coordination, and continuous improvement in a diverse technology environment.
Responsibilities
- Lead, coach, and develop Tier 2 Incident Response Analysts, setting clear standards and providing technical guidance.
- Direct complex investigations across endpoint, identity, email, cloud, and network environments, coordinating activity from escalation through recovery.
- Provide technical and operational leadership during major incidents, enabling clear decisions, effective communication, and coordinated action.
- Partner with the Security Operations Centre to improve triage quality, escalation routes, and response effectiveness.
- Work with Threat Intelligence, Detection Engineering, Vulnerability Management, and Security Engineering teams to improve visibility, detections, and response capability.
- Lead post-incident reviews and root cause analysis, turning lessons learned into practical improvements that strengthen resilience.
- Develop and maintain incident response playbooks, procedures, and operational standards, and support simulations and readiness exercises.
- Influence the UK and Switzerland Security Operations strategy, engage senior stakeholders across technology, risk, legal, and privacy, and provide senior on-call cover for major incidents.
Requirements
- Experience leading complex cyber security incident investigations within a Security Operations Centre, incident response, or cyber defence environment, including containment, eradication, and recovery.
- Experience managing and developing technical security teams through coaching, mentoring, and clear operational leadership.
- Practical experience investigating threats across endpoint, identity, email, cloud, and network technologies.
- Experience coordinating major incidents and communicating clearly with technical and non-technical stakeholders, including senior decision-makers.
- Experience improving incident response services through playbooks, post-incident reviews, root cause analysis, exercises, or operational process development.
- Experience working in a large, complex, or regulated organization and making evidence-based decisions under pressure.
- Eligible for or able to obtain Security Check clearance.
Skills
- Microsoft Sentinel
- Microsoft Defender technologies
- Microsoft Purview
- Digital forensics
- Incident response tools
- Security orchestration and automation
- Threat hunting
- Detection engineering
- GCIH
- GCFA
- CISSP
Location
- UK
- Hybrid
Work Type
- Hybrid
Experience Level
- Senior
About the Company
- KPMG is evolving Security Operations across the UK and Switzerland to create a more integrated, intelligence-led approach to cyber resilience.