Cyber Incident Response Lead
Experian
Summary
Join Experian's Global Security Office (EGSO) / Cyber Fusion Center (CFC) as a specialized, advanced responder to support escalations of complex cybersecurity matters. You will investigate and contain security events, working with various teams and stakeholders to ensure remediation and recovery. Responsibilities include conducting advanced incident response activities, managing multiple security incident cases, maintaining case documentation, and providing advanced support and mentorship to other analysts. The role requires expertise in network protocols, security technologies, and incident response applications. A regular Monday-Friday schedule with on-call expectations is required. You will report to the CFC Senior Director of Incident Management and Security Operations.
Requirements
- Must have knowledge of network protocols (TCP/IP, UDP, ICMP), standard protocols (HTTP/S, DNS, SSH, SMTP, SMB), wireless networking, networking infrastructure, and network topologies (DMZ, VPN, WAN) and network technologies (WAF, IPS, Routers, Firewalls)
- Experience with commercial & opensource SIEMs, full packet capture tools, and network analysis tools (Splunk, Wireshark, SOF-ELK)
- Have a demonstrated knowledge of common intrusion methods and cyber-attack tactics, techniques, and procedures (TTPs)
- Exhibit skills using common Incident Response and Security Monitoring applications such as SIEM (Splunk), EDR (FireEye HX, CrowdStrike Falcon, McAfee mVision EDR.), WAF, IPS
Responsibilities
- Conduct advanced incident response activities to investigate and contain complex and larger-scale cybersecurity matters (such as potential major severity incidents)
- In the event of investigative matters requiring additional analytical support from teams such as Forensics and Cyber Threat Hunt workstreams across the teams and hold responsibility for expressing the CFC's overall understanding of the timeline of attacker activity so that appropriate containment and remediation actions can be coordinated
- Respond to Security to cyber security events and alerts associated to threats, intrusions, and compromises per any applicable SLOs
- Manage multiple cases related to security incidents throughout the incident response lifecycle; including Analysis, Containment, Eradication, Recovery, and Lessons Learned
- Maintain case documentation, including notes, analysis findings, containment steps, and cause for each assigned security incident
- Maintain an understanding of common Operating Systems (Windows, Linux, Mac OS), Security Technologies (Anti-Virus, Intrusion Prevention), and Networking (Firewalls, Proxies)
- Interpret device and application logs from a variety of sources (e.g. Firewalls, Proxies, Web Servers, System Logs, Splunk, Packet Captures) to identify cause and determine next steps for containment, eradication, and recovery
- Provide Advanced Support to analysts (Logs review, IP Block question). Mentor other analysts (process question, tool usage)
Benefits
- Flexible work environment, working hybrid or in the office if you prefer
- Great compensation package and discretionary bonus plan
- Core benefits include pension, bupa healthcare, sharesave scheme and more
- 25 days annual leave with 8 bank holidays and 3 volunteering days. You can purchase additional annual leave