372,956open jobs
9,661companies
50,233added this week
Browse all
Salary
$103k – $154k per year
Location
Remote/Hybrid (United Kingdom)
Seniority
Middle · 3+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Arctic Wolf Networks is a cybersecurity leader specializing in Managed Detection and Response (MDR) and security operations center (SOC) solutions as a service. Headquartered in Eden Prairie, Minnesota, the company utilizes its cloud-native platform to ingest and analyze network, endpoint, and cloud telemetry to detect and remediate cyber threats in real time. Operating a concierge-based delivery model, it provides organizations worldwide with tailored risk management, incident response, and security awareness training to safeguard digital assets.

At Arctic Wolf, we're not just navigating the cybersecurity landscape - we're redefining it. Our global team of dedicated Pack members is driving innovation and setting new industry standards every day. Our impact speaks for itself: we've earned recognition on the Forbes Cloud 100, CNBC Disruptor 50, Fortune Future 50, and Fortune Cyber 60 lists, and we recently took home the 2024 CRN Products of the Year award. We’re proud to be named a Leader in the IDC MarketScape for Worldwide Managed Detection and Response Services and earning a Customers' Choice distinction from Gartner Peer Insights. Our Aurora Platform also received CRN’s Products of the Year award in the inaugural Security Operations Platform category. Join a company that’s not only leading, but also shaping, the future of security operations.

Our mission is simple: End Cyber Risk. We’re looking for a Manager, Incident Reponse to be part of making this happen, based in the UK.

About the Role

The Manager, Incident Response is responsible for leading and maturing Arctic Wolf's Incident Response practice by combining strategic leadership, operational management, and advanced technical incident response expertise. This role leads and develops a team of Incident Response professionals while maintaining the technical depth required to support and lead complex investigations, cyber extortion events, ransomware engagements, business email compromise matters, and large-scale recovery efforts.

The Manager is accountable for delivering world-class incident response services, ensuring operational excellence, maintaining technical quality standards, driving process improvements, developing team capabilities, and supporting organizational growth. This individual serves as both a management leader and a senior technical escalation resource capable of leading the most complex investigations and customer engagements

Team Leadership & People Management

  • Lead, mentor, develop, and manage a hybrid/remote team of Incident Response professionals.
  • Ensure operational standardization across delivery regions
  • Recruit, hire, onboard, train, and retain top DFIR talent.
  • Conduct performance reviews, career development planning, coaching sessions, and succession planning.
  • Foster a culture of collaboration, accountability, technical excellence, and continuous improvement.
  • Ensure team members receive exposure to a variety of investigative and recovery activities to support career growth.
  • Lead team development initiatives through formal mentoring, peer coaching, technical reviews, and knowledge-sharing programs.
  • Serve as an escalation point for personnel, client, and delivery-related issues.

Incident Response Operations

  • Oversee the delivery of Incident Response services to ensure consistent, scalable, and high-quality outcomes.
  • Scope incoming matters, monitor, and manage incident response engagements across the team.
  • Assign personnel to engagements based on skillsets, availability, customer needs, and goals.
  • Maintain awareness of all active investigations and recovery efforts, stepping in when escalation or leadership intervention is required.
  • Ensure proper case management practices, utilization targets, resource planning, scheduling, and workload balancing.
  • Develop and implement operational processes, standards, and quality assurance mechanisms.
  • Review incident reports, executive summaries, investigative findings, and customer deliverables prior to delivery.
  • Establish and maintain key performance indicators (KPIs), service metrics, and operational reporting capabilities.
  • Drive continuous improvement initiatives that enhance efficiency, consistency, customer satisfaction, and service quality.
  • Provide technical leadership and mentorship to team members throughout engagements and forensic activities

Technical Incident Response & Forensics

  • Lead and support advanced digital forensic and incident response investigations.
  • Conduct and oversee host, network, cloud, and log-based forensic analysis.
  • Perform investigative activities involving Windows, Linux, macOS, Azure, AWS, and Google Cloud environments.
  • Guide containment, eradication, recovery, and remediation activities during active security incidents.
  • Validate investigative findings and technical conclusions developed by team members.
  • Develop complex investigation strategies and incident response plans for customer environments.
  • Conduct forensic analysis through collected evidence to determine threat actor activity and timeline, identify persistent mechanisms, data impact and indicators of compromise.
  • Maintain expert-level knowledge of emerging threats, attack methodologies, ransomware trends, and DFIR best practices.
  • Participate directly in the most complex, high-risk, or high-visibility engagements, when required.

Customer & Stakeholder Engagement

  • Serve as a senior trusted advisor during active cybersecurity incidents.
  • Communicate technical findings to executive leadership, legal counsel, insurance carriers, and technical stakeholders.
  • Lead scoping discussions and engagement planning for new incident response matters.
  • Support cyber extortion and ransomware negotiation strategy development and approval.
  • Present recovery plans, investigative findings, and strategic recommendations to customer stakeholders.
  • Build and maintain relationships with legal counsel, cyber insurance carriers, strategic partners, and customers.
  • Support business development activities, attend industry events, and thought leadership initiatives as needed.
  • Recommend Arctic Wolf solutions and services where appropriate based on customer needs.

Strategic Leadership & Program Development

  • Partner with Directors and Executive Leadership to execute the vision, strategy, and growth plans for the Incident Response organization.
  • Identify opportunities for automation, innovation, tooling improvements, and operational efficiencies.
  • Define and standardize processes, methodologies, documentation, and service delivery frameworks.
  • Drive reporting and analytics initiatives that demonstrate business impact, customer outcomes, operational efficiency, and risk reduction.
  • Collaborate across Product, Engineering, Security Operations, Concierge, MDR, Sales, Marketing, and Customer Success teams.
  • Support strategic planning, budgeting, forecasting, workforce planning, and organizational scaling initiatives.
  • Champion quality assurance programs, service delivery excellence, and customer experience improvements

General Responsibilities

  • Create and participate in escalation, evening, weekend, and holiday on-call rotations.
  • Conduct peer reviews, quality reviews, and case audits.
  • Promote information sharing, documentation, and organizational learning.
  • Maintain required technical certifications and professional development goals.
  • Perform other duties as assigned in support of Arctic Wolf's Incident Response mission and organizational objectives.

Key Skills

  • Digital Forensics & Incident Response (DFIR)
  • Leadership and Team Development
  • Incident Command and Crisis Management
  • Cyber Extortion and Ransomware Response
  • Executive Communication
  • Customer Relationship Management
  • Strategic Planning
  • Operational Excellence
  • Process Development and Standardization
  • Performance Metrics and Reporting
  • Cloud and Enterprise Incident Response
  • Investigation Quality Assurance
  • Resource Planning and Utilization Management
  • Stakeholder Management
  • Cross-Functional Collaboration
  • Project and Program Management

Minimum Qualifications

  • 3+ years of experience leading technical teams, people management, or service delivery organizations.
  • Demonstrated experience leading complex cyber incident investigations and recovery efforts.
  • Strong knowledge of host, network, cloud, and enterprise forensic analysis.
  • Experience managing customer-facing engagements involving legal counsel, cyber insurance carriers, and executive stakeholders.
  • Exceptional verbal and written communication skills.
  • Experience developing operational processes, performance metrics, and quality assurance programs.
  • Ability to lead multiple concurrent initiatives and prioritize effectively in high-pressure environments.
  • Fluency in English, verbal and written

Preferred Qualifications

  • Bachelor's degree in Information Security, Digital Forensics, Computer Science, Cybersecurity, or a related discipline.
  • Industry certifications such as GCFA, GCFE, CISSP, GCIH, EnCE, ACE, or equivalent.
  • Experience within consulting, managed security services, or incident response service organizations.
  • Experience presenting at industry conferences, customer events, or technical forums.
  • Experience supporting large-scale enterprise incident response programs and global service delivery teams

About Arctic Wolf

At Arctic Wolf, we foster a collaborative and inclusive work environment that thrives on diversity of thought, background, and culture. This is reflected in our multiple awards, including Top Workplace USA (2021-2024), Best Places to Work - USA (2021-2024), Great Place to Work - Canada (2021-2024), Great Place to Work - UK (2025), and Kununu Top Company - Germany (2025). Our commitment to bold growth and shaping the future of security operations is matched by our dedication to customer satisfaction, with over 7,000 customers worldwide and more than 2,000 channel partners globally. As we continue to expand globally and enhance our technology, Arctic Wolf remains the most trusted name in the industry.

Our Values

Arctic Wolf recognises that success comes from delighting our customers, so we work together to ensure that happens every day. We believe in diversity and inclusion, and truly value the unique qualities and unique perspectives all employees bring to the organization. And we appreciate that-by protecting people’s and organisations’ sensitive data and seeking to end cyber risk- we get to work in an industry that is fundamental to the greater good. We celebrate unique perspectives by creating a platform for all voices to be heard through our Pack Unity program. We encourage all employees to join or create a new alliance. See more about our Pack Unity here. We also believe and practice corporate responsibility, and have recently joined the Pledge 1% Movement, ensuring that we continue to give back to our community. We know that through our mission to End Cyber Risk we will continue to engage and give back to our communities.

All wolves receive compelling compensation and benefits packages, including:

  • Equity for all employees
  • 28 days annual leave, 8 bank holidays and paid volunteering days off
  • Pension plan employer match
  • Training and career development programs
  • Robust Employee Assistance Program (EAP) with mental health service
  • Comprehensive private benefits plan including medical insurance, virtual GP, optical and dental cashback, life insurance (4x basic salary) and group income protection.
  • Fertility support and paid parental leave

Arctic Wolf is an Equal Opportunity Employer and considers applicants for employment without regard to race, colour, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under federal, provincial, or local law. Arctic Wolf is committed to fostering a welcoming, accessible, respectful, and inclusive environment ensuring equal access and participation for people with disabilities. As such, we strive to make our entire employee experience as accessible as possible and provide accommodations as required for candidates and employees with disabilities and/or other specific needs where possible. Please let us know if you require any accommodations by emailing [email protected].

Security Requirements

  • Conducts duties and responsibilities in accordance with AWN’s Information Security policies, standards, processes and controls to protect the confidentiality, integrity and availability of AWN business information (in accordance with our employee handbook and corporate policies).
  • Background checks are required for this position.
  • This position may require access to information protected under U.S. export control laws and regulations, including the Export Administration Regulations (“EAR”). Please note that, if applicable, an offer for employment will be conditioned on authorisation to receive software or technology controlled under these U.S. export control laws and regulations.

Ready to Make an Impact?

Apply now with your CV to join one of the fastest-growing and most innovative cybersecurity companies in the world.

The base salary range for this job family is 76,000 to 114,000 GBP annually. This range reflects the base pay the company reasonably expects to offer for this position, aligned to the broader job family base pay structure. Actual base pay may vary based on skills, experience, and location, including job family level. In addition to base pay, Arctic Wolf offers variable incentive compensation, new hire equity grants, and a comprehensive benefits package.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
372,956 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
United Kingdom
$122k – $253k per year (Estimated) • Remote • Full-Time • 7+ years exp
Java
AI/ML
AI Agents
Claude
Claude Code
Copilot
Cursor
LangGraph
LLM Evaluation
LLM Guardrails
Model Context Protocol
OpenAI Codex
LangChain
DevOps
AWS
Azure
GCP
Nexus Repository
Cybersecurity
Cosign
SBOM
Sigstore
SLSA
Sonatype Nexus IQ
Apply
$26k – $65k per year (Estimated) • In office • Full-Time • 5+ years exp • Pune
Java
Node JS
Python
JavaScript
DevOps
AWS
Azure
GCP
Apply
$49k – $124k per year (Estimated) • Equity • Remote/Hybrid • Full-Time • 5+ years exp • Braga • Lisbon • Coimbra
PowerShell
Python
TypeScript
Databases
DynamoDB
OpenSearch
PostgreSQL
Redis
AI/ML
AI Agents
Edge AI
DevOps
Amazon CloudWatch
Amazon ECS
Amazon EventBridge
Amazon S3
API Gateway
AWS
AWS CDK
AWS Fargate
AWS Lambda
AWS Step Functions
Azure
CI/CD
CloudFormation
Docker
FinOps
GCP
Git
GitHub
IAM
Platform Engineering
Cybersecurity
OWASP Dependency-Check
Prowler
SonarQube
Management
Confluence
Jira
Apply
Full Stack Engineer 2 hours ago
$47k – $103k per year (Estimated) • In office • Full-Time • 12+ years exp • Gurgaon • Bengaluru
Java
SQL
TypeScript
JavaScript
Frontend
Angular
DevOps
AWS
Azure
Apply
$32k – $109k per year (Estimated) • Remote/Hybrid • Full-Time • 3+ years exp • Lisbon
JavaScript
Node JS
SQL
TypeScript
Node JS
Express
Nest.JS
AI/ML
Claude
Claude Code
Copilot
Cursor
Frontend
React.js
DevOps
AWS
Azure
CI/CD
Docker
Git
GitHub
Kubernetes
Rest API
Apply
$32k – $72k per year (Estimated) • In office • Full-Time • 6+ years exp • Bengaluru
C++
Java
Python
YARA
Databases
Amazon Aurora
DevOps
Azure
GCP
Kubernetes
Cybersecurity
MITRE ATT&CK
Suricata
YARA
Zeek
Apply
$45k – $98k per year (Estimated) • In office • Full-Time • 14+ years exp • Bengaluru
Go
Python
Databases
Amazon Aurora
DynamoDB
AI/ML
AI Agents
DevOps
AWS Lambda
Azure
CI/CD
Docker
GCP
Git
Jenkins
Kubernetes
Platform Engineering
Terraform
AWS
Apply
$45k – $98k per year (Estimated) • In office • Full-Time • 14+ years exp • Bengaluru
Go
Python
Databases
Amazon Aurora
DynamoDB
AI/ML
AI Agents
DevOps
AWS Lambda
Azure
CI/CD
Docker
GCP
Git
Jenkins
Kubernetes
Platform Engineering
Terraform
AWS
Apply
$32k – $72k per year (Estimated) • In office • Full-Time • 5+ years exp • Bengaluru
Go
Python
SQL
JavaScript
Databases
Amazon Aurora
Apache Kafka
RabbitMQ
Frontend
React.js
DevOps
Amazon EC2
Ansible
AWS
Azure
Bazel
CI/CD
CloudFormation
Configuration Management
Datadog
Docker
GCP
GitHub Actions
Grafana
Jenkins
Kubernetes
Prometheus
Rest API
Terraform
Amazon ECS
GitHub
Cybersecurity
SonarQube
QA
Sentry
Apply
$11k – $42k per year (Estimated) • In office • Full-Time • 2+ years exp • Associate's Degree • Bengaluru
PowerShell
Python
Management
Confluence
Jira
ServiceNow
Apply
$98k – $236k per year (Estimated) • In office • Full-Time • Bachelor's Degree • London
Apex
Apex
MuleSoft
AI/ML
Agentforce
AI Agents
EU AI Act
Cybersecurity
GDPR
Marketing
Salesforce
Apply
$83k – $189k per year (Estimated) • In office • Full-Time • Dublin
Apply
$55k – $136k per year (Estimated) • In office • Full-Time • United Kingdom
DevOps
AWS
Azure
Hyper-V
Kubernetes
VMWare
Apply
$94k – $167k per year (Estimated) • In office • Full-Time • United Kingdom
Apply
$47k – $117k per year (Estimated) • Remote • Full-Time • 3+ years exp • Bachelor's Degree • United Kingdom
JavaScript
SQL
Databases
MS SQL
DevOps
SLI/SLO/SLA
Analytics
ETL/ELT
Power BI
Apply
See all jobs
This is one of many
372,956 more open roles from verified company boards, updated every day.