Threat Hunting and Incident Response Lead

5 days ago


London, Greater London, United Kingdom Transport for London Full time

Job Summary

We are seeking an experienced Threat Hunting and Incident Response Lead to join our Cyber Security Operations Centre (SOC) team at Transport for London. The successful candidate will be responsible for leading our threat hunting and incident response function, identifying and remediating potential threats to our systems and services.

The ideal candidate will have extensive experience in threat hunting, incident response, and security operations. You will be responsible for coordinating hunting activities across teams and with key stakeholders to identify and remediate potential threats.

About the Position

This is a full-time position based in North Greenwich, London, with 50% office attendance model. We offer a competitive salary range of £55,000-£60,000 per annum, plus fantastic company benefits, including final salary pension scheme, free tube and bus travel, and 30 days annual leave.

Responsibilities

  1. Provide leadership across the SOC, supporting Senior and Junior Analysts to prioritize and direct activities, driving behaviours and ensuring effective incident handling.
  2. Enhance TfL's operational capabilities within the team; work closely with the SOC Manager ensuring capabilities across all Security Service lines as well as ensuring best practice whilst driving continual improvement.
  3. Proactively monitor TfL systems for malicious activity and intrusions using real-time data and alerting from various data sources measured against agreed SLAs.
  4. Ensure processes and operational documentation is maintained, fit for purpose and updated regularly to reflect changing business needs.
  5. Implement the TfL hunting process for security activities, in collaboration with key stakeholders across the organisation.
  6. Support the tuning of detection content and monitoring tooling to provide high fidelity alerting worthy of further investigation and mitigating false positives.
  7. Keep up to date with current cyber developments and trends, and maintain your skills through continuous personal development and working collaboratively with colleagues, both internal and external to the team.

Requirements

  • Security Fundamentals training/certifications
  • Incident Response training/certifications
  • Hunting experience in previous roles
  • Conversant with technologies supported by the SOC and including experience with 4 or more: IR, VM, TI, Phishing, SIEM, BA, EDR, MDR.
  • Demonstrable skills in using security tooling to provide contextual data to allow for a thorough assessment of an event.
  • Ability to communicate effectively written and verbally and influence others in order to minimise TfL's Cyber Risk through effective monitoring, detection and where necessary mitigation.
  • Ability to effectively use a SIEM solution to identify events that warrant further investigation.
  • Ability to use Threat Intelligence to aid the detection of potential cyber security events and incidents.

Benefits

  • Final salary pension scheme
  • Free travel for you on the TfL network
  • Reimbursement of 75% of the cost of a standard class Ticket for National Rail travel from home or 75% reimbursement on a 28-day flexi ticket
  • 30 days annual leave plus public and bank holidays
  • TfL is committed to work-life balance, operating a hybrid working approach where business and role requirements allow
  • Private healthcare discounted scheme (optional)
  • Tax-efficient cycle-to-work programme
  • Retail, health, leisure and travel offers
  • Discounted Eurostar travel


  • London, Greater London, United Kingdom WeAreTechWomen Full time

    About the Opportunity:WeAreTechWomen is seeking an experienced Threat Hunting and Incident Response Expert to join our team. This role plays a critical part in our cybersecurity efforts, contributing to the proactive identification and mitigation of potential security threats.Responsibilities:Assist in identifying potential security threats within our...


  • London, Greater London, United Kingdom Qube Research & Technologies Limited Full time

    At Qube Research & Technologies Limited, we are committed to delivering high-quality returns for our investors. As a leader in quantitative and systematic investment management, we prioritize innovation and collaboration in our work.We are seeking an Incident Response and Threat Hunting Expert to join our global security team. The successful candidate will...


  • London, Greater London, United Kingdom Iceberg Full time

    We are excited to partner with an investment bank in London that is looking to expand its EMEA capability at the AVP level. We are seeking a specialist with relevant experience in incident response, threat modeling, and cybersecurity frameworks.Job Description:Key Responsibilities:Develop and Refine Security Monitoring Controls: Develop and refine security...


  • London, Greater London, United Kingdom Sportradar Full time

    We're looking for a Senior AWS Technology Specialist to join our Information Security team at Sportradar. As a key member of our team, you will lead incident response and proactive threat hunts, managing incidents in strict alignment with relevant frameworks, such as NIST or ISO, and any applicable regulatory requirements.Job DescriptionThe Senior Incident...


  • London, Greater London, United Kingdom Cognita Asia Holdings Pte Ltd Full time

    Job Summary:We are looking for a seasoned Cyber Security Incident Response Lead to oversee the proactive monitoring and strengthening of our technical security framework. The ideal candidate will have a robust understanding of threat actor techniques, Microsoft Security suite, and experience in integrating MS products with third-party services.The role...


  • London, Greater London, United Kingdom Iceberg Cyber Security Full time

    Cybersecurity Leadership Role Iceberg Cyber Security seeks an experienced cybersecurity leader to spearhead advanced incident response and threat-hunting initiatives in their EMEA capability. As a respected expert in your field, you will have the opportunity to make a lasting impact on internal operations and enhance overall cybersecurity posture. Key...


  • London, Greater London, United Kingdom Iceberg Cyber Security Full time

    Secure the Future with Iceberg Cyber SecurityWe're looking for an experienced cybersecurity professional to lead our incident response team and shape the future of cybersecurity within our organization.The successful candidate will have a strong background in incident response, threat modeling, and SIEM tools, as well as excellent knowledge of network...


  • London, Greater London, United Kingdom Cognita Asia Holdings Pte Ltd Full time

    Cyber Security Incident Response LeadCognita is a global leader in independent education, and we are committed to safeguarding and promoting the welfare of children and young people. We are seeking a highly skilled Cyber Security Incident Response Lead to join our Group IT Team.The successful candidate will have extensive experience in cyber security...


  • London, Greater London, United Kingdom Sportradar Full time

    The estimated salary for this position is £100,000 - £160,000 per annum.Job OverviewSportradar is an Equal Opportunity Employer committed to encouraging diversity within our teams. We are seeking a Senior Incident Response Specialist to join our team at Sportradar, where you will play a critical part in protecting our organization's assets and improving...

  • Digital Threat Lead

    2 weeks ago


    London, Greater London, United Kingdom PDS Cyber Services Full time

    **PDS Cyber Services: A Leading Cyber Security Company**We are committed to providing innovative solutions to protect our clients from cyber threats. As a **Digital Threat Lead**, you will play a key role in our team, coordinating the day-to-day tactical and operational delivery of threat intelligence, threat hunting, vulnerability management, and malware...


  • London, Greater London, United Kingdom Iceberg Cyber Security Full time £75,000

    We are seeking a highly skilled cybersecurity professional to join our team in London.About the RoleThis exciting opportunity allows you to contribute your expertise in incident response, threat modeling, and cybersecurity frameworks to help expand our EMEA capability.Main Responsibilities:Develop and refine security monitoring controls and use-cases,...


  • London, Greater London, United Kingdom Harrington Starr Full time

    Enterprise Threat Intelligence LeadHarrington Starr is searching for a highly skilled Enterprise Threat Intelligence Lead to spearhead strategic threat detection and mitigation efforts. As a key member of our team, you will be responsible for driving threat intelligence initiatives and leading incident response activities.The ideal candidate will possess...


  • London, Greater London, United Kingdom Iceberg Cyber Security Full time

    Senior Cybersecurity RoleIceberg Cyber Security is looking for a seasoned cybersecurity professional to join their team. This role offers the opportunity to develop and implement cutting-edge cybersecurity strategies.Job Summary:Lead incident response and threat-hunting efforts.Collaborate with the team to design and implement robust security...


  • London, Greater London, United Kingdom Cognita Asia Holdings Pte Ltd Full time

    About the RoleThe Cyber Security Incident Response Lead will be responsible for the proactive monitoring and strengthening of our technical security framework. This role involves automating incident management processes, providing critical input on projects, and ensuring secure cloud infrastructure and proactive threat hunting.A competitive salary depending...

  • Threat Hunting Expert

    20 hours ago


    London, Greater London, United Kingdom Palo Alto Networks Full time

    Threat Hunting Expert Wanted:">We're looking for a skilled Threat Hunting Expert to join our Unit 42 National Security Team (NATSEC) in EMEA. As a key member of this team, you will work closely with a globally distributed team to track advanced persistent threats and provide timely intelligence to support customer requirements.">Your Impact:">">Provide...


  • London, Greater London, United Kingdom Cognita Asia Holdings Pte Ltd Full time

    Cognita: A Global Leader in Independent EducationAvoiding Cyber ThreatsIn today's digital age, cyber threats are becoming increasingly sophisticated. At Cognita, we take the security of our students' data very seriously. As the Cyber Security Incident Response Lead, you will be responsible for proactively monitoring and strengthening our technical security...


  • London, Greater London, United Kingdom Sportradar Full time

    The estimated salary for this position is £90,000 - £140,000 per annum.About UsSportradar is the world's leading sports technology company, at the intersection between sports, media, and betting. Our innovative solutions empower over 1,700 sports federations, media outlets, betting operators, and consumer platforms across 120 countries.Job DescriptionWe...


  • London, Greater London, United Kingdom Iceberg Cyber Security Full time £75,000

    About the RoleIceberg Cyber Security is looking for an experienced IT security specialist to join our team as an AvP Cybersecurity Expert. We are seeking a highly skilled individual with a strong background in incident response, threat modeling, and cybersecurity frameworks.The successful candidate will be responsible for developing and refining security...


  • London, Greater London, United Kingdom Cybervance, Inc. Full time

    Job Details:We are seeking an experienced Cloud Incident Response Trainer to join our team at CyberVance. The ideal candidate will have a strong background in cloud incident response, with a focus on Microsoft Azure security tools and frameworks.About the RoleThe successful candidate will be responsible for delivering live virtual training sessions that...


  • London, Greater London, United Kingdom Cognita Asia Holdings Pte Ltd Full time

    Required Skills and QualificationsThe ideal candidate will possess a robust understanding of threat actor techniques and the MS Security suite, including MDC, MDI, MDCA, MDO, and Azure networking. They should have 3-5 years in an incident response/SOC role, with a track record of integrating MS products with third-party services, creating automated...