Director Cyber Defence Operations

3 weeks ago


London, United Kingdom Pearson Full time

Director - Cyber Defense Operations DFIR

The Director Cyber Defence Operations is responsible for leading a global team providing proactive threat detection and response capabilities across a vast technology environment encompassing both traditional on-premise and cutting-edge cloud native assets.The role will drive the strategic direction of the function, as well as providing hands-on expertise in predicting, preventing, detecting and responding to security threats of all types and sophistications. The Director Cyber Defence Operations will be a vocalproponent of modern approaches to autonomic security operations, driving a threat intelligence lead, data driven and engineering rooted philosophy across the team and wider business.

The Director Cyber Defence Operations will be a role model to the team and will succeed by continually upskilling others through their experiences, mindset and capabilities. Always challenging the status quo, looking at areas for development and not beingafraid to seek out and eradicate problems to ensure the security of the business.

Key Responsibilities:

- Lead and manage a global team of specialists performing continuous threat detection and response operations including:

- Signals acquisition
- Detection engineering
- Attack analysis
- Proactive threat hunting
- Incident response / incident management
- Digital forensics / malware analysis
- Own, develop, maintain and exercise cyber incident response plans, processes and playbooks.
- Work closely with Security Engineering teams to:

- Recommend system tuning/configuration improvements.
- Leverage and oversee automation & orchestration initiatives.
- Drive strategic capability development roadmap for TDR.
- Integration and exploitation of cyber threat intelligence in conjunction with internal CTI team and external sources.
- Ensure operational excellence through measurements, KPIs, reporting and continual process improvement.
- Evangelise forward thinking data and engineering lead operational models such as:

- Detection-as-code
- Autonomic security operations
- DevSecOps
- Continuous validation/testing
- Cloud-native security operations.
- Develop and manage a personnel skill and capabilities development framework.
- Continuous professional development through training, conferences and self-education.

**Required Skills**:

- Significant and demonstrable experience working in advanced detection, threat hunting and/or incident response function as a lead.
- Experience developing incident response processes and supporting documentation.
- Application and exploitation of common frameworks such as MITRE ATT&CK, NIST etc.
- Proficient in performing complex investigations on a variety of platforms and operating systems with a deep understanding of digital forensics processes and tools across Windows, MacOS and Linux.
- Hands-on experience with modern detection technologies such as EDR/XDR, SIEM (Splunk/Sentinel), SOAR, NIPS/HIPS.
- Extensive knowledge of networking concepts, including network detection and response tooling and intrusion prevention (Snort, Zeek, Suricata etc.)
- Proficient with investigating large-scale data compromise events across a hybrid on-premise, public and private cloud environment (AWS, Azure, GCP preferred).
- Understanding and experience investigating and responding to incidents in cloud native technologies such as containers (Kubernetes, AWS ECS/Fargate) and serverless (AWS Lambda).
- Knowledge of digital forensics forensic best practices and industry standard methodologies including chain of custody, evidence acquisition and appropriate tooling (X-Ways, EnCase, Volatility, Rekall, Wireshark, SIFT etc.)
- Able to articulate and visually present complex forensic investigation and analysis results equally effectively to both industry professionals and internal business partners.
- Proficiency in at least one or more modern programming or scripting languages (Python, Go, Rust etc.)
- Evidence of previous security solution design, implementation and engineering successes.
- Understating of DevSecOps approach and implementation of “everything-as-code" models.
- Experience acting as a technical team lead and mentor to junior team members.
- Strong verbal and written communication skills.

Qualifications & Experience:

- Degrees non-essential - equivalent prior work experience in the field, a must.
- Industry standard certifications (GCFA, GNFA, GCFE, CFCE, OSCP, CREST etc) are a plus but not essential.
- Memberships and participation in relevant professional associations (ISC2, ISACA etc).
- Previous contributions to the industry (conference talks, code projects, volunteering).

**Job**: TECHNOLOGY

**Organization**: Corporate Strategy & Technology

**Schedule**: FULL_TIME

**Req ID**: 9085


  • Cyber Defence

    2 days ago


    London, United Kingdom KPMG Full time

    Job description Cyber Defence Manager - 103793 Base Location: Hybrid/UK based (core office in London) plus network of 20 offices nationally: The KPMG Connected Technology function is a cornerstone of our business. We do work that matters to our local business and communities – supporting technical innovation and adoption of cutting-edge...

  • Cyber Defence

    2 days ago


    London, United Kingdom KPMG-UnitedKingdom Full time

    Job description Cyber Defence Manager - 103793 Base Location: Hybrid/UK based (core office in London) plus network of 20 offices nationally: The KPMG Connected Technology function is a cornerstone of our business. We do work that matters to our local business and communities - supporting technical innovation and adoption of cutting-edge solutions across...

  • Defence Digital

    2 days ago


    City of London, Greater London, United Kingdom Cyber Security Jobsite Full time

    BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments.     Security Consultant –...

  • Defence Digital

    2 days ago


    City of London, Greater London, United Kingdom Cyber Security Jobsite Full time

    BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments.     Security Consultant - Policy...

  • Director - Cyber

    21 hours ago


    London, United Kingdom Eames Consulting Full time

    Eames is currently working with a global insurance broker who are seeking a Director in Cyber to spearhead the expansion and refinement of their portfolio in the London Market. This pivotal role offers a chance to join a broker poised for rapid growth, providing hands-on leadership and substantial autonomy to shape the future direction of the cyber...

  • Head of Cyber

    4 weeks ago


    London, United Kingdom eFinancialCareers Full time

    Gresham Hunt are currently partnered with a leading investment bank who are seeking an experienced Cyber and IT Resilience professional for their growing 2nd Line of Defence function. This is a Director level position in which you will lead the 2LOD oversightof Technology Resilience across the Group. - Previous experience working a 2nd Line of Defence...


  • London, United Kingdom Careers In Group Full time

    Leading response to serious and cross-cutting cyber incidents, threats and vulnerabilities for government, including collaborating with NCSC, the Central Digital and Data Office (CDDO) and departments to minimise risks to critical assets and public services,providing technical expertise to support response, briefing Ministers and senior officials, and taking...


  • London, United Kingdom RiverSafe Ltd. Full time

    Make an impact with your next career move Employment Full-time Location London (Canary Wharf) Office / hybrid Function Professional Services THE COMPANY RiverSafe is a premier Cyber Security consultancy based in the heart of Canary Wharf and we are meeting the huge demand we have seen head on! We have a proven track record of delivering services to a...

  • Programme Manager

    1 month ago


    London, United Kingdom techUK Full time

    **Job Title**: Programme Manager - Defence **Location**: London **Salary**: £32,000 - £44,000 per annum based upon experience plus discretionary bonus and comprehensive benefits **Job Type**:Permanent, Full-Time **Overview of techUK's Defence Programmes**: The Defence programme works to help the UK's Defence technology sector align itself with the MOD,...


  • London, United Kingdom RiverSafe Ltd. Full time

    Make an impact with your next career move Employment Full-time Location London (Canary Wharf) Office / hybrid Function Professional Services The Company RiverSafe is a premier Cyber Security consultancy based in the heart of Canary Wharf and we are meeting the huge demand we have seen head on! We have a proven track record of delivering services to a...


  • London, United Kingdom Jobleads-UK Full time

    Make an impact with your next career moveEmploymentFull-timeLocationLondon (Canary Wharf) Office / hybridFunctionProfessional ServicesThe CompanyRiverSafe is a premier Cyber Security consultancy based in the heart of Canary Wharf and we are meeting the huge demand we have seen head on! We have a proven track record of delivering services to a well-known...

  • IGH Cyber Director

    2 days ago


    London, United Kingdom KPMG-UnitedKingdom Full time

    Job descriptionThe RoleThe role will be working in the UK Cyber Security practice within Connected Technology - Technology Risk. Our clients are increasingly under cyber-attack and regulatory scrutiny to demonstrate effective management of cyber risk. Our specialists provide independent, jargon free advice and advanced technical capabilities to help our...


  • London, United Kingdom Ministry of Defence Full time

    **Details**: **Reference number**: - 327768**Salary**: - £57,670- A Civil Service Pension with an average employer contribution of 27%**Job grade**: - Grade 7**Contract type**: - Permanent**Business area**: - MOD - Defence Nuclear Organisation**Type of role**: - Project Delivery**Working pattern**: - Flexible working, Full-time, Job share,...


  • London, United Kingdom Ministry of Defence Full time

    **Details**: **Reference number**: - 285353**Salary**: - £56,530- Salary includes London weighting**Job grade**: - Grade 7**Contract type**: - Permanent**Business area**: - MOD - Strategic Command**Type of role**: - Administration / Corporate Support - Governance - Policy**Working pattern**: - Flexible working, Full-time, Job share, Part-time**Number...

  • IGH Cyber Director

    2 days ago


    London, United Kingdom Cloudsecurityexpo Full time

    You will need to login before you can apply for a job. Job description The Role The role will be working in the UK Cyber Security practice within Connected Technology - Technology Risk. Our clients are increasingly under cyber-attack and regulatory scrutiny to demonstrate effective management of cyber risk. Our specialists provide independent, jargon...

  • IGH Cyber Director

    2 days ago


    London, United Kingdom KPMG Full time

    The Role The role will be working in the UK Cyber Security practice within Connected Technology – Technology Risk. Our clients are increasingly under cyber-attack and regulatory scrutiny to demonstrate effective management of cyber risk. Our specialists provide independent, jargon free advice and advanced technical capabilities to help our clients...

  • IGH Cyber Director

    3 weeks ago


    London, United Kingdom Phoenix Recruitment Limited Full time

    Cyber Security Director - Healthcare Sector I am working on a mandate with one of the world's foremost professional services consultancies. In response to heightened instances of cyber attacks targeting their clientele and the intensified regulatory scrutiny within the industry, our client seeks to strengthen its Technology Consulting Practice and...


  • London, United Kingdom WTW Full time

    We are seeking passionate people to grow the Cyber Security team within WTW and provide an excellent service and trusted expertise to all parts of our business. As part of a business wide transformation, we have an exciting opening for a new role of Global Head of Cyber Threat. As part of the Cyber Defence and Security Operations department, you will be a...


  • London, United Kingdom Cabinet Office Full time

    **Details**: **Reference number**: - 254853**Salary**: - £35,241 - £39,352**Job grade**: - Higher Executive Officer**Contract type**: - Permanent**Business area**: - CO - Government Security Group**Type of role**: - Operational Delivery**Working pattern**: - Flexible working, Full-time, Job share**Number of jobs available**: -...


  • London, United Kingdom Live Nation (Music) UK Limited Full time

    Cyber Defence Lead Detection Engineer page is loaded Cyber Defence Lead Detection Engineer Apply locations Farringdon, London, United Kingdom time type Full time posted on Posted 2 Days Ago job requisition id JR-63169 Job Summary: Company: Live Nation Entertainment Department: Trust and Security Location: UK, remote Reports to: Senior Manager of...