The Cyber Incident Responder will be responsible for managing the organisation s response to all severity levels (Sev 1-4) of security incidents. The role involves leading the investigation, recovery, and follow-up of security incidents, allocated based on time of day, business area, and the individual s skills and experience. The responder will work closely with the team to ensure timely recovery from security incidents and collaborate with other departments to implement processes, procedures, and technologies to prevent future occurrences.
Additionally, the role includes reviewing, improving, and maintaining a comprehensive suite of security incident response procedures and playbooks. The Cyber Incident Responder will also be expected to conduct threat analysis, provide incident reports, and participate in post-incident reviews to identify lessons learned and areas for improvement.
What youll be doing:
- Manage Security Incidents: Effectively oversee the management, investigation, and forensic analysis of security incidents.
- Team Collaboration: Collaborate with team members to optimise incident response processes, procedures, and approaches.
- Procedure and Playbook Maintenance: Continuously review, enhance, and maintain security incident response procedures and playbooks.
- Stakeholder Engagement: Develop and maintain strong relationships with internal stakeholders, suppliers, and external agencies.
- Incident Simulations: Participate in and enhance regular cyber security incident simulations and exercises to ensure preparedness.
- Threat Analysis and Reporting: Conduct threat analysis, generate incident reports, and participate in post-incident reviews to identify lessons learned and areas for improvement.
What youll need:
- Computer Science Degree (desirable but not essential)
- CISSP or similar
- Certified Incident Handler or similar
Certified Forensic Analyst or similar
- Experience of managing security incidents within a large multinational organisation
- Experience of driving security investigations and forensics
- Experience of working within a high pressured security incident response team
- Experience of working with suppliers, external stakeholder and internal teams and developing strong and trusting working relationships