Incident Response Lead
Quick Overview
Job Description
Cyber Operations & Incident Response Lead, Cloud, Security, Hybrid
You will lead and line-manage the London-based cyber security team, delivering cyber operations services, assure the local delivery of globally-prioritised work, and act as Incident Commander and first point of escalation for cyber security in London.
The role additionally leads to the Endpoint, Platform and Incident Response capability, owning the global prioritisation of that backlog against enterprise cyber risk.
Experience required:
A strong, hands-on technical background in operational cyber security spanning endpoint & EDR, identity & Active Directory, Microsoft 365 & Azure, network/ZTNA, and SIEM/log management - able to act as a senior technical authority within the team. Tools: Azure, Active Directory, CrowdStrike Falcon, Zscaler, Vulnerability Management (Qualys, Tenable Nessus, Rapid7), Incident Response ownership experience & Playbooks/Mitre Att&ck)
Demonstrable experience leading cyber security incident response (incident command), from detection through containment and remediation.
Working knowledge of MITRE ATT&CK and at least one recognised control framework (ISO 27001, CIS or NIST).
Risk-based prioritisation of remediation using threat intelligence.
Own the global prioritisation of the Endpoint, Platform and Incident Response backlog, ordered against the enterprise cyber risk register and exploitation-based intelligence (eg MITRE ATT&CK).
Curate the backlog from inputs across Houston and London, including the endpoint detection and response (CrowdStrike) execution lead.
Maintain alignment of this domain to the enterprise risks for endpoint compromise, detection and containment, and cyber resilience.
Operate within the Global Head's monthly prioritisation cadence; prioritisation across other domains remains with the Global Head.
Assure local execution of globally-prioritised work to agreed quality, pace and outcomes.
Drive London-side delivery of in-flight initiatives through completion.
Track and chase vulnerability remediation and patching on London-managed systems, escalating blockers.
3 days on site required in central London
Cyber Operations & Incident Response Lead, Cloud, Security, Hybrid
McGregor Boyall is an equal opportunity employer and do not discriminate on any grounds.
Skills
Similar jobs
Casualty Claims Adjuster
Eames Consulting · London, United Kingdom
21 minutes agoNewly Qualified Accountants Network (ACA / ACCA), Private Equity / Venture Capital, London, UK - PER, Private Equity Recruitment
PER, Private Equity Recruitment · London, United Kingdom
1 hour agoTechnical Delivery Lead (Python, Databricks) - CER Financial
CER Financial · London, United Kingdom
1 hour ago£515 - £894/moService Delivery & Customer Success Manager
Sanderson Recruitment Plc · Hamilton, United Kingdom
2 hours agoD365 F&O Global Lead
Akkodis · United Kingdom
2 hours ago£90k/yrTechnical Operative 1
Hays Talent Solutions · Hatfield, United Kingdom
2 hours ago€45/hr