Global Head of Incident Response and Cyber Threat
3 days ago
The Global Head of Incident Response & Cyber Threat Intelligence leads a multi-discipline team within our Cyber Defence and Security Operations function. This person will need to have a good technical aptitude, a calm approach under pressure, excellent communicative skills to technical and non-technical audiences, and have a genuine passion for security.
The role is aligned to our hybrid working style, predominant based from home with office travel when required. This may include travel between offices beyond your base location and on occasion, international travel.
The Incident Response & Cyber Threat Intelligence team forms just one of the pillars in our wider Cyber Defence function and so there will be career development opportunities to broaden your experience in other pillars such as SOC, Penetration Testing etc.
**The Role**
Work closely with the Director of Cyber Defence and Chief Information Security Officer in defining and implementing overall strategies of Incident Response and Threat Intelligence.
- Define service maturity model and roadmap.
- Identify ways to utilize resources effectively and efficiently.
- Flag and declare service and capability limitations and boundaries.
Leadership, performance and development.
- Make sure all direct reports and their direct reports have performance objectives and career development plans, monitoring results vs objectives.
- Create plans to improve performance gaps and monitor them accordingly.
- Create, monitor and support career development plans.
Provide oversight and direction to Information and Cyber Security Defence (ICSD) members for Incident Response under the guidance of the Global Director for Cyber Defence and Security Operations.
- Designates relevant additional tasks and functions to ICSD members.
- Engages with External Teams as required such as Incident Response Retainer Services.
- Ensures that Quality Assurance and that the Lessons learned process is conducted and fed into the Continuous Service Improvements.
- Ensures this incident response plan is properly implemented, followed, reviewed, and updated accordingly.
- Facilitates efficient and secure communications and information flow.
- Provides appropriate status updates to the Director of Cyber Defence and Security Operations/CSIG/GCISO.
Maintains the Incident Response Plan.
- Assist with the appropriate cyber security incident management training for ICSD members.
- Facilitates an annual review of the ICSIRP, incorporating updates and revisions to the document.
- Maintains Information and Cyber Security Incident Response Plan (ICSIRP) revision approval documentation.
- Supports annual testing of the ICSIRP as part of the Annual Cyber Tabletop run by an independent External Third-Party.
- Escalate Severity 1 and 2 incidents to CSIG.
Ensure delivery of quality service and achieve goals by leveraging Key Performance Indicators (KPI) and Metrics.
- Establish a set of performance measurements for all managed teams and capabilities and set threshold where possible.
- Regularly record KPI/Metrics results and report them to relevant stakeholders and working groups.
- Inform Leadership Team of any potential red flags or trends that will have significant impact to WTW.
Support audit and regulatory requirements and requests.
- Ensure timely submission of requested documents, evidence, etc.
- Act as owners for relevant security controls.
- Attend sessions and conduct walk-throughs in response to audit queries.
- Be accountable for the management and closure of agreed Management Action Plans (MAP’s).
Review efficient use of technology and toolsets.
- Regularly assess efficacy (cost, coverage, etc) of used toolsets and recommend them for renewal or transformation.
- Support relevant technology POC or testing.
Participate in Projects that have elements of Incident Response (IR) and Threat Intelligence (TI).
- Contribute to listing requirements that have a direct and indirect impact on IR and TI.
- Attend regular project meetings and provide needed support.
Perform other tasks assigned by the ICS Leadership Team.
- Lead and participate on relevant working groups and committees.
**The Requirements**
- Experience in leading and managing Incident Response and comfortable talking to stakeholders and colleagues on both a technical and non-technical level.
- Experience of managing a team of Information Security / Cyber professionals and had an impact in their career development.
- You will be working as part of the Information and Cyber Security team across different locations and therefore you must be a true team player, with the ability and desire to engage with colleagues and clients, on some occasions, to deliver the highest standards of service and support.
- Extensive experience working as part of a cyber defence centre, information and cyber security or security operations centre and handled a variety of security job domains.
- To be effective, you need to have great troubleshooting skill
-
Global Head of Cyber Threat
2 weeks ago
London, United Kingdom WTW Full timeWe are seeking passionate people to grow the Cyber Security team within WTW and provide an excellent service and trusted expertise to all parts of our business. As part of a business wide transformation, we have an exciting opening for a new role of Global Head of Cyber Threat. As part of the Cyber Defence and Security Operations department, you will be a...
-
Senior Cyber Incident Response
1 week ago
Greater London, United Kingdom S&P Global Full timeA global financial services company in London is seeking a Senior CIRT Analyst to join their Cyber Defence team. This role involves coordinating responses to cybersecurity events and collaborating closely with various teams to enhance security measures globally. The ideal candidate will have over three years of experience in incident response, a deep...
-
Cyber Security Incidence Response
3 weeks ago
london (city of london), United Kingdom Pioneer Search Full timeCyber Security Analyst - Incident Response London - Hybrid | Up to £65,000 + benefits A global specialist insurer is building out its internal cyber defence capability and is seeking an experienced analyst to strengthen its Security Operations Centre. You'll join a collaborative team focused on both proactive threat hunting and live incident response,...
-
Cyber Security Incident Response
7 days ago
London, United Kingdom Thomas Miller Full timeCyber Security Incident Response & Threat Intelligence AnalystTeam OverviewThe Cyber Security Operations Team is responsible for monitoring, detecting, and responding to cyber threats across Thomas Millers estate. We ensure the protection of digital assets and safeguard confidentiality, integrity and availability of systems. Working in a fast-paced...
-
Cyber Security Incident Response
6 days ago
London, United Kingdom Thomas Miller Full timeCyber Security Incident Response & Threat Intelligence Analyst Team Overvie wThe Cyber Security Operations Team is responsible for monitoring, detecting, and responding to cyber threats across Thomas Millers estate. We ensure the protection of digital assets and safeguard confidentiality, integrity and availability of systems. Working in a fast-paced...
-
Cyber Security Incidence Response
4 weeks ago
City of London, United Kingdom Pioneer Search Full timeCyber Security Analyst - Incident ResponseLondon - Hybrid | Up to £65,000 + benefitsA global specialist insurer is building out its internal cyber defence capability and is seeking an experienced analyst to strengthen its Security Operations Centre.You'll join a collaborative team focused on both proactive threat hunting and live incident response,...
-
Cyber Technical Incident Response
1 week ago
Greater London, United Kingdom Trades Workforce Solutions Full timeCyber Incident Response (Senior Consultant & Manager Levels) Are you passionate about Cyber Security, Digital Forensics, and Incident Response? We’re looking for Cyber Incident Response Consultants / Managers to join a growing global cyber practice, working across major enterprise clients and government‑grade environments. This is a hands‑on,...
-
Incident Response/threat Hunting Specialist
2 weeks ago
London, United Kingdom Barclay Simpson Full time**Incident Response/Threat Hunting Specialist**: - London - £90,000 + bens - Sector: Professional Services, Commerce and Industry - Job reference: 40942 I’m working with a boutique consultancy, who are seeking to grow to their existing cyber function with another dedicated incident response/threat hunting specialist. This role is varied, offering the...
-
Cyber Security Incident Response
6 days ago
London Area, United Kingdom Thomas Miller Full timeCyber Security Incident Response & Threat Intelligence Analyst Team Overvie wThe Cyber Security Operations Team is responsible for monitoring, detecting, and responding to cyber threats across Thomas Millers estate. We ensure the protection of digital assets and safeguard confidentiality, integrity and availability of systems. Working in a fast-paced...
-
Cyber Security Incident Response
6 days ago
London Area, United Kingdom Thomas Miller Full timeCyber Security Incident Response & Threat Intelligence AnalystTeam OverviewThe Cyber Security Operations Team is responsible for monitoring, detecting, and responding to cyber threats across Thomas Millers estate. We ensure the protection of digital assets and safeguard confidentiality, integrity and availability of systems. Working in a fast-paced...