5 часов назад
Head of Cyber Defence & Incident Response (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Head of Cyber Defence & Incident Response (Cybersecurity): Leading cyber defence and incident response across hybrid on-premises and cloud environments with an accent on security monitoring, vulnerability management, threat intelligence, and MSSP governance. Focus on directing high-severity incident response, optimising SIEM/SOAR and endpoint tooling, building threat hunting and tabletop exercise programmes, and improving detection, recovery, and executive reporting.
Location: Hradec Kralove, Czechia; hybrid work model
Company
supports businesses in digital transformation through secure, sustainable automation across digital and physical channels.
What you will do
- Lead cyber defence operations and incident response across on-premises and cloud environments, reporting to the CISO.
- Own the incident response lifecycle, including preparation, detection, analysis, containment, eradication, recovery, governance, and post-incident reviews.
- Act as incident commander during major security events, coordinating forensic triage, recovery, stakeholder communications, and executive updates.
- Manage the MSSP relationship, including service definitions, SLAs/KPIs, escalation paths, quality assurance, continuous improvement, and commercial governance.
- Optimise SIEM, SOAR, EDR/XDR, NDR, email security, vulnerability scanning, logging, alert quality, automation, and operational runbooks.
- Establish threat management, vulnerability management, threat hunting, tabletop exercises, security metrics, and continuous improvement programmes.
Requirements
- Strong experience leading cyber defence or SOC operations and incident response, including investigation, containment, recovery, and major incident coordination.
- Hands-on understanding of SIEM, SOAR, EDR/XDR, NDR, email security, log pipelines, detection engineering, and operational workflows.
- Experience managing an MSSP or outsourced SOC, including SLAs/KPIs, governance, escalations, and service improvement.
- Strong experience with vulnerability and threat management programmes, prioritisation, remediation SLAs, and executive reporting.
- Experience defending hybrid environments with identity signals, network telemetry, endpoint visibility, and cloud-native security monitoring.
- Fluent English at an excellent written and verbal communication level is required.
Nice to have
- GCIH, GCIA, GNFA, CISSP, CISM, or equivalent experience.
- Experience with threat hunting, purple teaming, and MITRE ATT&CK.
- Experience with Microsoft Defender, Sentinel, Splunk, CrowdStrike, Palo Alto, AWS, or Azure security services.
- Experience coordinating with IT, engineering, legal/privacy, and business leadership during investigations and recovery.
Culture & Benefits
- Hybrid work combining office and remote work according to role requirements.
- Access to a global 24/7 online learning platform and development opportunities.
- Competitive total rewards covering wellbeing and work-life balance.
- Employee assistance programme for mental health support.
- Inclusive communities and philanthropy programmes.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
17 часов назад
Senior Security Monitoring Analyst (Cybersecurity)
3 500€
13 часов назад
Senior Cloud Security Engineer
6 дней назад
AI Product Security Engineer
7 дней назад
Threat Research Software Engineer (Cybersecurity)
2 700€
8 часов назад
Senior Security Specialist
Proton
18 часов назад