Blue Team Leader (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Blue Team Leader (Cybersecurity): Orchestrating security operations and defensive capabilities within the Cyber Fusion Centre with an accent on incident response, SIEM optimization, and threat detection. Focus on leading the Cyber Incident Response Team (CIRT), bridging gaps between red and blue teams, and managing security analysts to protect business assets.
Location: Hybrid; must be based in York (UK) or Lisbon (Portugal)
Company
International insurance group focusing on specialist risks and cybersecurity protection.
What you will do
- Direct the Blue Team's daily operations and align them with business security objectives and threat intelligence.
- Oversee continuous network monitoring and design incident response plans to mitigate breaches.
- Co-ordinate Blue Team exercises to improve detection and response capabilities.
- Perform gap analysis on SIEM detection use cases and onboard new data sources.
- Lead the initial response to security incidents as part of the Cyber Incident Response Team (CIRT).
- Coach and mentor analysts to support their professional development.
Requirements
- 6+ years of experience in a security operations team, with at least 2 years in a management role.
- Proven experience leading responses to security incidents and breaches.
- Deep knowledge of SIEM, EDR, XDR, and network security appliances such as firewalls.
- Strong leadership and communication skills for managing and coaching a team.
- Must be based in or able to work from the York (UK) or Lisbon (Portugal) offices.
- BSc or MSc in Cybersecurity is highly desirable.
Nice to have
- Advanced certifications such as CISSP, CISM, GCIH, or GPEN.
- Industry-recognized security vendor certifications.
- Knowledge of forensics technologies and processes.
Culture & Benefits
- Hybrid working model to support a healthy work-life balance.
- Performance-based bonus and contributory pension.
- 25 days annual leave plus 2 additional days.
- 4-week paid sabbatical for every 5 years of service.
- Private medical insurance for the employee and their family.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →