Incident Response Lead - #2113781
McGregor Boyall
Cyber Operations & Incident Response Lead, Cloud, Security, Hybrid
You will lead and line-manage the London-based cyber security team, delivering cyber operations services, assure the local delivery of globally-prioritised work, and act as Incident Commander and first point of escalation for cyber security in London.
The role additionally leads to the Endpoint, Platform and Incident Response capability, owning the global prioritisation of that backlog against enterprise cyber risk.
Experience required:
A strong, hands-on technical background in operational cyber security spanning endpoint & EDR, identity & Active Directory, Microsoft 365 & Azure, network/ZTNA, and SIEM/log management - able to act as a senior technical authority within the team. Tools: Azure, Active Directory, CrowdStrike Falcon, Zscaler, Vulnerability Management (Qualys, Tenable Nessus, Rapid7), Incident Response ownership experience & Playbooks / Mitre Att&ck)
Demonstrable experience leading cyber security incident response (incident command), from detection through containment and remediation.
Working knowledge of MITRE ATT&CK and at least one recognised control framework (ISO 27001, CIS or NIST).
Risk-based prioritisation of remediation using threat intelligence.
Own the global prioritisation of the Endpoint, Platform and Incident Response backlog, ordered against the enterprise cyber risk register and exploitation-based intelligence (e.g. MITRE ATT&CK).
Curate the backlog from inputs across Houston and London, including the endpoint detection and response (CrowdStrike) execution lead.
Maintain alignment of this domain to the enterprise risks for endpoint compromise, detection and containment, and cyber resilience.
Operate within the Global Head's monthly prioritisation cadence; prioritisation across other domains remains with the Global Head.
Assure local execution of globally-prioritised work to agreed quality, pace and outcomes.
Drive London-side delivery of in-flight initiatives through completion.
Track and chase vulnerability remediation and patching on London-managed systems, escalating blockers.
3 days on site required in central London
Cyber Operations & Incident Response Lead, Cloud, Security, Hybrid
McGregor Boyall is an equal opportunity employer and do not discriminate on any grounds.
How to apply
To apply for this job you need to authorize on our website. If you don't have an account yet, please register.
Post a resumeSimilar jobs
Remediation Data Analyst
Senior Manager - Private Clients Tax
Senior Analytics Engineer (Snowflake, SQL, Looker) Contract