Lead, mentor, and manage a global team of 6-10 Security Operations Center Incident Responders, fostering a culture of excellence and continuous improvement. Oversee and direct incident response functions, ensuring adherence to established playbooks and best practices across diverse computing environments. Drive strategic initiatives to enhance incident detection, containment, and eradication capabilities. Lead and support in-depth triage and investigations of urgent cyber incidents. Manage team performance, conduct regular reviews, and facilitate career development for direct reports. Ensure the team effectively performs host-based analytical functions (e.g., digital forensics, metadata, malware analysis, etc.) through investigating Windows, Unix-based, appliances, and Mac OS X systems to uncover Indicators of Compromise (IOCs) and/or Tactics, Techniques and Procedures (TTPs). Oversee the creation and tracking of metrics based on the MITRE ATT&CK Framework and other standard security-focused models, using these to drive continuous improvement. Lead collaboration with application and infrastructure stakeholders to identify key components and information sources such as various environments (on-premises versus other distributed systems), servers, workstations, middleware, applications, databases, logs, etc. Direct incident response efforts using forensic and other custom tools to identify sources of compromise and/or malicious activities. Collaborate with global multidisciplinary groups for triaging and defining the scope of large-scale incidents. Direct the documentation and presentation of investigative findings for high-profile events and other incidents of interest to senior leadership. Lead and participate in readiness exercises such as purple team, table tops, etc. Develop and implement training programs for junior and mid-level colleagues on relevant best practices and advanced incident response techniques. Act as a key escalation point for critical incidents and provide expert guidance to the team. Working knowledge of networking protocols and infrastructure designs; including routing, firewall functionality, host and network intrusion detection/prevention systems, encryption, load balancing, and other network protocols. Working knowledge of relational database systems and concepts (SQL Server, PostgreSQL, etc.). Working knowledge of virtualization products (e.g., VMware Workstation).
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Number of Employees
5,001-10,000 employees