Overview
The Cyber Incident Response Lead will oversee and enhance the incident response capabilities for a large organization undergoing a significant cyber security transformation. Working in a hybrid environment, this role involves collaborating with various technical teams to manage cyber security incidents effectively and improve operational processes. The contractor will play a crucial role in ensuring the organization can respond promptly and efficiently to security threats, while also driving continuous improvement through post-incident reviews and stakeholder reporting.
Responsibilities
- Lead the end-to-end response to cyber security incidents.
- Develop and improve incident response processes, playbooks, and operating procedures.
- Coordinate technical teams during high-priority security events.
- Work closely with Security Operations, Infrastructure, Cloud, and Operational Technology teams.
- Lead post-incident reviews and drive continuous improvement.
- Support cyber exercises, tabletop scenarios, and resilience testing.
- Produce reporting and recommendations for senior stakeholders.
- Collaborate with third-party security providers and specialist partners.
Requirements
- Proven experience leading Cyber Security Incident Response.
- Strong Security Operations background.
- Experience with SIEM, EDR, and enterprise security tooling.
- Knowledge of Digital Forensics and Incident Response (DFIR).
- Experience developing Incident Response playbooks.
- Excellent stakeholder management skills.
- Experience working within large enterprise environments.
- Exposure to Operational Technology (OT) or critical infrastructure is advantageous.