Incident Response Lead - #2113781

McGregor Boyall


Date: 2 weeks ago
City: London
Salary: £650 - £750 / day
Contract type: Full time
Work schedule: Full day
McGregor Boyall

Cyber Operations & Incident Response Lead, Cloud, Security, Hybrid


You will lead and line-manage the London-based cyber security team, delivering cyber operations services, assure the local delivery of globally-prioritised work, and act as Incident Commander and first point of escalation for cyber security in London.


The role additionally leads to the Endpoint, Platform and Incident Response capability, owning the global prioritisation of that backlog against enterprise cyber risk.


Experience required:

A strong, hands-on technical background in operational cyber security spanning endpoint & EDR, identity & Active Directory, Microsoft 365 & Azure, network/ZTNA, and SIEM/log management - able to act as a senior technical authority within the team. Tools: Azure, Active Directory, CrowdStrike Falcon, Zscaler, Vulnerability Management (Qualys, Tenable Nessus, Rapid7), Incident Response ownership experience & Playbooks / Mitre Att&ck)

Demonstrable experience leading cyber security incident response (incident command), from detection through containment and remediation.

Working knowledge of MITRE ATT&CK and at least one recognised control framework (ISO 27001, CIS or NIST).

Risk-based prioritisation of remediation using threat intelligence.

Own the global prioritisation of the Endpoint, Platform and Incident Response backlog, ordered against the enterprise cyber risk register and exploitation-based intelligence (e.g. MITRE ATT&CK).

Curate the backlog from inputs across Houston and London, including the endpoint detection and response (CrowdStrike) execution lead.

Maintain alignment of this domain to the enterprise risks for endpoint compromise, detection and containment, and cyber resilience.

Operate within the Global Head's monthly prioritisation cadence; prioritisation across other domains remains with the Global Head.

Assure local execution of globally-prioritised work to agreed quality, pace and outcomes.

Drive London-side delivery of in-flight initiatives through completion.

Track and chase vulnerability remediation and patching on London-managed systems, escalating blockers.

3 days on site required in central London


Cyber Operations & Incident Response Lead, Cloud, Security, Hybrid


McGregor Boyall is an equal opportunity employer and do not discriminate on any grounds.

How to apply

To apply for this job you need to authorize on our website. If you don't have an account yet, please register.

Post a resume

Similar jobs

Remediation Data Analyst

LANCESOFT LTD,
£290 - £400 / day
13 hours ago
Remediation Data Analyst Contract Length: 18 MONTHS Location: London 2 days per week, hybrid Security Clearance: BPSS but will go through SC when in post Must Have: Remediation Experience Banking Experience R/Python Experience Excel Experience Analyse the needs of the...
LANCESOFT LTD

Senior Manager - Private Clients Tax

Park Street People,
13 hours ago
We are looking for an ambitious and commercially minded Private Client Tax Senior Manager to join their team in London. Working with a broad range of clients, you will take ownership of delivering high quality tax services while acting as...

Senior Analytics Engineer (Snowflake, SQL, Looker) Contract

Tenth Revolution Group,
£650 / day
13 hours ago
Senior Analytics Engineer Contract | Inside IR35 | £650 per day - 6 Months The Opportunity Our client, a leading software company, is looking for a Senior Analytics Engineer to join its established data team. You'll play a key role...
Tenth Revolution Group