Senior Incident Response Consultant (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Incident Response Consultant (Cybersecurity): Leading incident response engagements to neutralize cyber threats and conduct root cause analysis with an accent on ransomware and BEC investigations. Focus on directing forensic investigations, coordinating with executive stakeholders, and mapping threats to the MITRE ATT&CK framework.
Location: Remote (Must have legal authorization to work in the United Kingdom without employer sponsorship)
Company
Global leader in cybersecurity delivering Managed Detection and Response (MDR) and Security Operations.
What you will do
- Lead kick-off and daily update calls with customers to coordinate threat containment and deliver forensic findings.
- Direct forensic investigations, identify priorities, and delegate tasks to analysts.
- Conduct multiple Rapid Response incidents concurrently, specializing in ransomware and BEC cases.
- Produce executive-level reports with event timelines mapped to the MITRE ATT&CK framework.
- Provide daily handover notes to global teams across different time zones.
- Contribute to the development of the Rapid Response service through moderate complexity projects.
Requirements
- 5+ years of experience leading incident response investigations involving ransomware.
- Proven track record in neutralizing ransomware threats and leading BEC investigations.
- Deep understanding of the Incident Response process and cyber risk qualification.
- Strong grasp of the MITRE ATT&CK framework.
- Legal authorization to work in the UK without employer sponsorship.
- Ability to work a specific schedule (Fri, Sat, Sun, Mon) and some weekends/holidays.
Nice to have
- Cybersecurity certifications such as CISSP, GCFA, or similar.
- Experience with SIEM technology like Splunk or ELK.
- Ability to write SQL queries.
- Proficiency in PowerShell, Python, or Bash scripting.
Culture & Benefits
- Remote-first organizational structure.
- Opportunity to work within an elite group of global incident responders.
- Collaborative environment with a focus on mentoring and developing junior analysts.
- Exposure to high-impact, complex cybersecurity incidents for organizations worldwide.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →