Cyber Incident Response Lead

Posted 2 Days Ago
Be an Early Applicant
Hiring Remotely in Ruddington, Rushcliffe, Nottinghamshire, England
Remote
Senior level
Big Data • Marketing Tech • Analytics
The Role
As a Cyber Incident Response Lead, you will lead advanced incident response activities to investigate and contain complex cybersecurity threats. Responsibilities include managing multiple security incidents, documenting findings, interpreting application and device logs, and mentoring junior analysts. You will work with various teams to ensure effective containment and remediation actions against cyber threats.
Summary Generated by Built In

Company Description

Internal Grade D

Experian is a global data and technology company, powering opportunities for people and businesses around the world. We help to redefine lending practices, uncover and prevent fraud, simplify healthcare, create marketing solutions, and gain deeper insights into the automotive market, all using our unique combination of data, analytics and software. We also assist millions of people to realise their financial goals and help them save time and money.

We invest in people and new advanced technologies to unlock the power of data. As a FTSE 100 Index company listed on the London Stock Exchange (EXPN), we have a team of 22,500 people across 32 countries. Our corporate headquarters are in Dublin, Ireland.

Find out what its like to work for Experian by clicking here

Job Description

As a member of Experian's Global Security Office (EGSO) / Cyber Fusion Center (CFC) you will respond, contain, escalate, investigate, and coordinate mitigation of security events relative to anomalies detected and escalated by the Cyber Fusion Centre (CFC) according to Experian's Incident Response Plan. This team member will join a new, growing team of specialized, advanced responders to support escalations of complex or prioritized matters from Experian's existing 24x7 security monitoring and response functions responsible for responding to and analysing security incidents involving threats targeting Experian information assets.

These threats may include phishing, malware, network attacks, suspicious activity. Also, you will involve working with end-users, partners, technical support teams, and management to ensure remediation and recovery from these threats. Use analytics & data collected from endpoints, environmental logging, and a variety of other sources to maximise containment and eradication of threats, while expediting recovery of the business.

Please note you will have a regular Monday – Friday schedule and expectation to participate in on-call schedule or work outside of normal work hours to manage cybersecurity incidents.

You will report to the CFC Senior Director of Incident Management and Security Operations.

Main Responsibilities include:-

  • Conduct advanced incident response activities to investigate and contain complex and larger-scale cybersecurity matters (such as potential major severity incidents)
  • In the event of investigative matters requiring additional analytical support from teams such as Forensics and Cyber Threat Hunt workstreams across the teams and hold responsibility for expressing the CFC's overall understanding of the timeline of attacker activity so that appropriate containment and remediation actions can be coordinated
  • Respond to Security to cyber security events and alerts associated to threats, intrusions, and compromises per any applicable SLOs.
  • Manage multiple cases related to security incidents throughout the incident response lifecycle; including Analysis, Containment, Eradication, Recovery, and Lessons Learned.
  • Maintain case documentation, including notes, analysis findings, containment steps, and cause for each assigned security incident.
  • Maintain an understanding of common Operating Systems (Windows, Linux, Mac OS), Security Technologies (Anti-Virus, Intrusion Prevention), and Networking (Firewalls, Proxies)
  • Interpret device and application logs from a variety of sources (e.g. Firewalls, Proxies, Web Servers, System Logs, Splunk, Packet Captures) to identify cause and determine next steps for containment, eradication, and recovery.
  • Provide Advanced Support to analysts (Logs review, IP Block question). Mentor other analysts (process question, tool usage)

Qualifications


  • Must have knowledge of network protocols (TCP/IP, UDP, ICMP), standard protocols (HTTP/S, DNS, SSH, SMTP, SMB), wireless networking, networking infrastructure, and network topologies (DMZ, VPN, WAN) and network technologies (WAF, IPS, Routers, Firewalls)
  • Experience with commercial & opensource SIEMs, full packet capture tools, and network analysis tools (Splunk, Wireshark, SOF-ELK)
  • Have a demonstrated knowledge of common intrusion methods and cyber-attack tactics, techniques, and procedures (TTPs).
  • Exhibit skills using common Incident Response and Security Monitoring applications such as SIEM (Splunk), EDR (FireEye HX, CrowdStrike Falcon, McAfee mVision EDR.), WAF, IPS

Additional Information

Benefits package includes:

  • Flexible work environment, working hybrid or in the office if you prefer.
  • Great compensation package and discretionary bonus plan
  • Core benefits include pension, bupa healthcare, sharesave scheme and more
  • 25 days annual leave with 8 bank holidays and 3 volunteering days. You can purchase additional annual leave.

Experian is proud to be an Equal Opportunity and Affirmative Action employer. Innovation is an important part of Experian's DNA and practices, and our diverse workforce drives our success. Everyone can succeed at Experian and bring their whole self to work, irrespective of their gender, ethnicity, religion, colour, sexuality, physical ability or age. If you have a disability or special need that requires accommodation, please let us know at the earliest opportunity.

Find out what its like to work for Experian by clicking here

#LI-Remote

Experian Careers - Creating a better tomorrow together

Find out what its like to work for Experian by clicking here

Top Skills

Crowdstrike Falcon
Dns
Fireeye Hx
Http/S
Icmp
Ips
Mcafee Mvision Edr
SIEM
Smb
Smtp
Splunk
Ssh
Tcp/Ip
Udp
Waf
The Company
HQ: Costa Mesa, CA
16,292 Employees
On-site Workplace
Year Founded: 1980

What We Do

Experian unlocks the power of data to create opportunities for consumers, businesses and society.

During life’s big moments – from buying a home or car, to sending a child to college, to growing a business exponentially by connecting it with new customers – we empower consumers and our clients to manage data with confidence so they can maximize every opportunity.

We gather, analyse and process data in ways others can’t. We help individuals take financial control and access financial services, businesses make smarter decision and thrive, lenders lend more responsibly, and organizations prevent identity fraud and crime.

For more than 125 years, we’ve helped consumers and clients prosper, and economies and communities flourish – and we’re not done.

Our 20,600 people in 43 countries believe the possibilities for you, and our world, are growing. We’re investing in new technologies, talented people and innovation so we can help create a better tomorrow.


About Experian:

Bringing data to life requires creativity, passion, flexibility and expertise.

We want you to share in our success. That's why we offer rewards that recognise great performance.

Working in a culture of collaboration, achievement and respect we will give you the support and encouragement you need to develop your skills and talents and progress your career.

Everyday our people bring enthusiasm, innovation and inspiration to work and if this sounds like you connect with us at Experian.

Similar Jobs

GitLab Logo GitLab

Sr. Partner Success Manager - EMEA

Cloud • Security • Software • Cybersecurity • Automation
Easy Apply
Remote
28 Locations
2350 Employees

Skillsoft Logo Skillsoft

Fulfillment Coordinator

Artificial Intelligence • Consumer Web • Edtech • HR Tech • Information Technology • Software • Conversational AI
Remote
United Kingdom
2900 Employees

Smartcat Logo Smartcat

Technical Revenue Operations Manager

Artificial Intelligence • Machine Learning • Natural Language Processing • Conversational AI
Easy Apply
Remote
28 Locations
242 Employees

BlackLine Logo BlackLine

Alliances Director

Cloud • Fintech • Information Technology • Machine Learning • Software • App development • Generative AI
Remote
United Kingdom
1810 Employees

Similar Companies Hiring

Effectv Thumbnail
Marketing Tech • Digital Media • AdTech
New York, NY
2157 Employees
InCommodities Thumbnail
Renewable Energy • Machine Learning • Information Technology • Energy • Automation • Analytics
Austin, TX
234 Employees
Hedra Thumbnail
Software • News + Entertainment • Marketing Tech • Generative AI • Enterprise Web • Digital Media • Consumer Web
San Francisco, CA
14 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account