Назад
Company hidden
3 дня назад

Lead Threat Response Operations Analyst (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Lead Threat Response Operations Analyst (Cybersecurity): Investigating and responding to sophisticated cyber threats across on-premises, cloud, and hybrid environments with an accent on threat analysis, incident response, malware investigations, and adversary tradecraft. Focus on reconstructing attack lifecycles, leading complex investigations, coordinating containment and remediation, and improving detection and response capabilities.

Location: Sandwich, United Kingdom; hybrid work arrangement

Company

A global pharmaceutical company focused on developing medicines, digital transformation, and improving patient outcomes.

What you will do

  • Investigate and respond to sophisticated cyber threats across endpoint, identity, network, cloud, email, and threat intelligence sources.
  • Correlate security telemetry, reconstruct attack lifecycles, identify attack pathways and root causes, and recommend detection and mitigation improvements.
  • Lead incident assessments, determine severity and business impact, and coordinate containment, eradication, remediation, escalation, and response activities.
  • Communicate technical findings, incident impacts, response decisions, and remediation recommendations to technical teams, business stakeholders, and senior leadership.
  • Improve investigation methodologies, operational procedures, reporting standards, and incident response playbooks.
  • Provide technical guidance to analysts and partner teams, lead cross-functional cybersecurity projects, and participate in a scheduled on-call rotation, including weekends.

Requirements

  • Bachelor’s degree in cybersecurity, computer forensics, computer science, information security, information systems, engineering, sciences, or a related field.
  • Relevant experience in cybersecurity operations, incident response, or threat investigation, including leading complex investigations.
  • Advanced knowledge of TCP/IP, network protocols, operating systems, cloud and identity technologies, enterprise security architectures, and defense-in-depth principles.
  • Advanced Windows operating system and system administration knowledge, including security controls, native utilities, and investigative artifacts.
  • Experience with SIEM platforms such as CrowdStrike Falcon Next-Gen SIEM, Splunk, or Google SecOps, and EDR platforms such as CrowdStrike Falcon, Microsoft Defender for Endpoint, or VMware Carbon Black.
  • Experience with security investigation and forensic tools including Wireshark, Snort, Kali Linux, SIFT Workstation, REMnux, Volatility, or comparable technologies, plus Linux command-line experience.

Nice to have

  • Participation in red team or blue team simulations, capture-the-flag challenges, cyber ranges, or incident response exercises.
  • Experience with Python or PowerShell for security investigations, data analysis, and automation.

Culture & Benefits

  • Flexible workplace culture supporting work-life harmony.
  • Patient-centric environment guided by courage, joy, equity, and excellence.
  • Commitment to diversity, inclusion, accessibility, and reasonable workplace adjustments.
  • Opportunity to contribute to company-wide digital transformation and security resilience.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →