Cyber Incident Response Manager

3 weeks ago


London Area, United Kingdom IAG Tech Full time

Company Description


IAG Tech is a community of IT and digital professionals from across the International Airlines Group (IAG). We drive the technology behind some of the biggest and most successful brands in global aviation, including British Airways, Aer Lingus, and Iberia.

Brought together in 2019, we are a unique community with a shared vision to deliver Technology Excellence and be recognised as industry leaders in the use of technology.

Our mission is to delight customers, enable employees, accelerate business performance, protect our business and increase shareholder value, through the innovative and agile use of technology and data.

We use product-centric delivery teams using agile methods to implement new capabilities at pace and maximise business outcomes. With a relentless focus on improving system performance and stability, we continually strive to find new and better ways to innovate and support the Group.

At IAG Tech we share common values to help us create the right culture to underpin our thriving community:

Innovation | we value identifying new ways of using technology to solve business challenges

Empowerment | we value giving people the freedom to operate, that they take accountability, and collaborate with colleagues

Professionalism | we value having and developing the right knowledge and competency to be able to do our jobs to the best of our ability

Transparency | we value honesty and integrity and always share the reality in a manner the business understands

Agility | we value responsiveness, speed and flexibility in everything we do

We celebrate when we see great examples of our values in action and challenge each other when we see these values being ignored.


Job Description


In this role you will be working in partnership with IAG Tech, IAG Group and the Operating Companies to:

Overall Management:

  • Manage and lead the CIRT team and third party incident retainer and forensic partners
  • Ensure the alignment of team objectives with organizational goals and priorities.

Incident Response:

  • Develop, implement, and maintain the CIRT's incident response plan and procedures.
  • Oversee the preparation, identification, analysis, containment, eradication, and recovery of security incidents.
  • Coordinate the CIRT's response with other internal teams (such as IT, legal, communications).
  • Track and report on security incidents and trends.
  • Maintain awareness of current security threats and vulnerabilities.

Cyber Table Top Exercise and Breach Attack Simulation Exerciseg

Resource Allocation:

  • Allocate resources effectively in CIRT
  • Manage staffing, budgeting, and technology investments to support operational objectives.

Tool Management:

  • Contribute to deployment, configuration, and maintenance of security tools and technologies for incident preparation and response.
  • Contribute to optimizing the performance of security tools to maximize effectiveness and efficiency.

Compliance and Reporting:

  • Ensure compliance with relevant regulations, standards, and industry best practices.
  • Prepare and present CIRT & incident reports/dashboards to Operations, Management, Exec & Auditors

Continuous Improvement:

  • Identify areas for improvement and innovation across SOC functions.
  • Implement measures to enhance operational efficiency, effectiveness, and resilience over time.

Escalation Handling

  • Perform Management on-call responsibilities


Qualifications


What we are looking for:

Skills:

  • Ability to lead and manage a large team of security analysts and specialists.
  • Strong leadership skills to inspire and motivate team members, set objectives, and drive performance.
  • Expertise in incident detection, analysis, and response methodologies.
  • Proficiency in coordinating and leading incident response efforts during security breaches and incidents.
  • Deep understanding of cybersecurity principles, technologies, and best practices.
  • Knowledge of security tools and technologies used in a SOC environment, such as SIEM (Security Information and Event Management), IDS/IPS (Intrusion Detection and Prevention Systems), and EDR (Endpoint Detection and Response) solutions.
  • Ability to assess and prioritize security risks based on their potential impact and likelihood.
  • Knowledge of relevant regulatory requirements and industry standards (e.g., GDPR, PCI DSS).
  • Experience in ensuring SOC operations comply with legal, regulatory, and contractual obligations.
  • Strong verbal and written communication skills to articulate complex technical concepts to diverse audiences.
  • Skill in building and fostering a collaborative and cohesive team environment.
  • Ability to troubleshoot complex security issues and develop innovative solutions to address them.
  • Adaptability to rapidly changing threat landscapes and evolving technologies.
  • Capacity to adjust SOC strategies and operations in response to emerging threats and organizational needs.
  • Commitment to continuous learning and professional development to stay abreast of the latest cybersecurity trends, technologies, and best practices.


Experience

  • 5-10 years experience in Security Operations
  • Prior experience in a CIRT Team
  • Leadership in Security Incident Response (SIR)
  • Expertise in SIEM/SOAR tools
  • Broad knowledge of security concepts (threat intel, vulnerability management, network security)
  • Experience in threat analysis & security alert detection
  • Familiarity with security frameworks (MITRE ATT&CK, NIST CSF)
  • Security team leadership or strong leadership potential
  • Experience in performance management
  • Excellent communication & collaboration skills
  • Security scripting and automation skills (Python, Bash) (Optional)
  • Knowledge of cloud security concepts and best practices (Optional)
  • Understanding of security compliance regulations (PCI DSS, ) (Optional)

Qualifications

  • Recognized Security qualifications desirable e.g. CISM, CISSP (preferred)
  • Project Management experience and certification (preferred)


Additional information


Benefits

The chance to enjoy a challenging career in an exciting, fast-moving environment in a dynamic industry, working in a multi-cultural environment with great offices in many locations. We aim to provide all our people with a work/life balance, as well as the many benefits offered by a global organisation, including health insurance, pension, and performance bonuses.


Diversity and Inclusion

IAG Tech is part of the IAG GBS organisation, and our people are at the heart of everything we do. We recognise that we can only deliver the required business outcomes if we have a thriving community of technology professionals. Together we strive to become the very best at what we do.

We focus on making Tech a great place to work, with a community that we feel proud to belong to. To help make this a reality, our people strategy focuses on six key domains: Engagement, Talent Management, Reward and Recognition, Performance Management, Learning and Development and Culture.

We understand the importance of Diversity and Inclusion in the workplace to deliver this strategy – everyone should feel part of our team. We want to foster an inclusive workplace, celebrate individuality and embrace differences so that everyone in IAG Tech can achieve their goals and ambitions, regardless of their personal circumstances or background.

As a Group, IAG has an ambition that 40% of senior management roles are held by women by 2025. IAG Tech fully supports that ambition, and we are working to help make it a reality. With this in mind, we have set ourselves the challenging target of recruiting 50% female colleagues by 2030.



  • London, Greater London, United Kingdom Marsh McLennan Full time

    Marsh Advisory's Consulting Solutions provides you with the insights, deep technical expertise, and global resources needed to create and implement risk management strategies that help you move beyond cost savings to building resilienceR_ Senior Managing Consultant - Incident Response AdvisoryWhat can you expect?Marsh takes an analytical, data-driven, and...


  • London, Greater London, United Kingdom Lorien Full time

    Cyber Response & Recovery ManagerJob Summary:Lorien is seeking a highly skilled Cyber Response & Recovery Manager to join our team. As a key member of our Cyber Security Operations team, you will be responsible for leading our incident response efforts and ensuring the highest level of service delivery to our clients.Key Responsibilities:Manage and...


  • London, Greater London, United Kingdom Lorien Full time

    Cyber Response & Recovery ManagerJob Summary:Lorien is seeking a highly skilled Cyber Response & Recovery Manager to join our team. As a key member of our Cyber Security Operations team, you will be responsible for leading our incident response efforts and ensuring the highest level of service delivery to our clients.Key Responsibilities:Manage and...


  • London, Greater London, United Kingdom Royal Mail Group Full time

    Position Title: Senior Cyber Incident ResponderWork Arrangement: HybridKey Responsibilities:Oversaw the management of security incidents with a strategic approach.Ensured the operational readiness of the Security Operations team for incident response scenarios.Identified, implemented, and optimized tools for managing security incidents.Reviewed and enhanced...


  • London, Greater London, United Kingdom Oliver James Full time

    Job SummaryOliver James is seeking a highly skilled Cyber Security Incident Response Manager to join our team in London. As a key member of our cyber security practice, you will be responsible for delivering incident response services to our clients, working collaboratively with colleagues and clients to identify and mitigate cyber threats.About the RoleThis...


  • London, Greater London, United Kingdom Oliver James Full time

    Job Summary:Oliver James is seeking a highly skilled Cyber Security Incident Response Manager to join our team in London. As a key member of our cyber security practice, you will be responsible for delivering incident response services to our clients, working collaboratively with colleagues and clients to identify and mitigate cyber threats.Key...


  • London, Greater London, United Kingdom Oliver James Full time

    Job Summary:Oliver James is seeking a highly skilled Cyber Security Incident Response Manager to join our team in London. As a key member of our cyber security practice, you will be responsible for delivering incident response services to our clients, working collaboratively with colleagues and clients to identify and mitigate cyber threats.Key...


  • London, Greater London, United Kingdom Oliver James Full time

    Job Summary:Oliver James is seeking a highly skilled Cyber Security Incident Response Manager to join our team in London. As a key member of our cyber security practice, you will be responsible for delivering incident response services to our clients, working collaboratively with colleagues and clients to identify and mitigate cyber threats.Key...


  • London, Greater London, United Kingdom Oliver James Full time

    Job Summary:Oliver James is seeking a highly skilled Cyber Security Incident Response Manager to join our team in London. As a key member of our cyber security practice, you will be responsible for delivering incident response services to our clients, working collaboratively with colleagues and clients to identify and mitigate cyber threats.Key...


  • London, United Kingdom Oliver James Full time

    Oliver James are partnered by a global cyber security business who are seeking to hire an Incident & Response Manager to be based in London (on a hybrid basis). The role can pay up to c£70,000 basic salary excluding bonuses and benefits initially. Additionally, first class training, development, research and clear progression is available. Oliver James...


  • London, Greater London, United Kingdom Lorien Full time £5,000 - £15,000

    Cyber Security Manager - Incident Response LeaderJob Summary:Lorien is seeking a highly skilled Cyber Security Manager to lead our incident response team. As a Cyber Security Manager, you will be responsible for managing and coordinating cyber security incidents for our clients, working closely with the cyber response leadership team.Key...


  • London, Greater London, United Kingdom Lorien Full time £5,000 - £15,000

    Cyber Security Manager - Incident Response LeaderJob Summary:Lorien is seeking a highly skilled Cyber Security Manager to lead our incident response team. As a Cyber Security Manager, you will be responsible for managing and coordinating cyber security incidents for our clients, working closely with the cyber response leadership team.Key...


  • London, Greater London, United Kingdom Lorien Full time £5,000 - £15,000

    Cyber Security Manager - Incident Response LeaderJob Summary:Lorien is seeking a highly skilled Cyber Security Manager to lead our incident response team. As a Cyber Security Manager, you will be responsible for managing and coordinating cyber security incidents for our clients, working closely with the cyber response leadership team.Key...


  • London, Greater London, United Kingdom Lorien Full time £5,000 - £15,000

    Cyber Security Manager - Incident Response LeaderJob Summary:Lorien is seeking a highly skilled Cyber Security Manager to lead our incident response team. As a Cyber Security Manager, you will be responsible for managing and coordinating cyber security incidents for our clients, working closely with the cyber response leadership team.Key...


  • London, United Kingdom Iceberg Cyber Security Full time

    My client is a unique insurance organisation who operates a cyber function for its customers. They are on the lookout for a Cyber Incident Analyst to join their team to support the delivery and coordination of incident reports and activities internally as well as for external partners. The position is based in the City Of London area on a hybrid working...


  • London Area, United Kingdom Provide Full time

    Cyber Incident Response Team Manager – Cybersecurity - Up to £100k - Hybrid - Bonus - Excellent Benefits.My client one of the world’s most renowned aviation groups is searching for a Senior Incident Response Analyst to join their team!Skills:Capable of leading and managing a large team of security analysts and specialists.Strong leadership abilities to...


  • London Area, United Kingdom Provide Full time

    Cyber Incident Response Team Manager – Cybersecurity - Up to £100k - Hybrid - Bonus - Excellent Benefits.My client one of the world’s most renowned aviation groups is searching for a Senior Incident Response Analyst to join their team!Skills:Capable of leading and managing a large team of security analysts and specialists.Strong leadership abilities to...


  • London, United Kingdom Provide Full time

    Cyber Incident Response Team Manager Hybrid – Twice a week in the office (Heathrow Airport)Up to £100,000 + up to 30% bonus + Benefits-------------------------------------------------------------------------------------Are you ready to tackle cyber threats head-on in a dynamic and high-stakes environment? Joining as a Cyber Incident Response Team Manager...


  • London, United Kingdom Provide Full time

    Cyber Incident Response Team Manager Hybrid – Twice a week in the office (Heathrow Airport) Up to £100,000 + up to 30% bonus + Benefits ------------------------------------------------------------------------------------- Are you ready to tackle cyber threats head-on in a dynamic and high-stakes environment? Joining as a Cyber Incident Response Team...


  • London, United Kingdom Provide Full time

    Cyber Incident Response Team Manager Hybrid – Twice a week in the office (Heathrow Airport)Up to £100,000 + up to 30% bonus + Benefits-------------------------------------------------------------------------------------Are you ready to tackle cyber threats head-on in a dynamic and high-stakes environment? Joining as a Cyber Incident Response Team Manager...