At a Glance
- Tasks: Lead advanced incident response to tackle complex cybersecurity threats and ensure business recovery.
- Company: Join Experian, a global leader in data and technology, transforming opportunities for people and businesses.
- Benefits: Enjoy flexible working options, competitive pay, generous leave, and a supportive work culture.
- Why this job: Be part of a dynamic team making a real impact in cybersecurity while developing your skills.
- Qualifications: Knowledge of network protocols, SIEM tools, and incident response practices is essential.
- Other info: Work in a diverse environment that values innovation and inclusivity.
The predicted salary is between 43200 - 72000 £ per year.
As a member of Experian's Global Security Office (EGSO) / Cyber Fusion Center (CFC) you will respond, contain, escalate, investigate, and coordinate mitigation of security events relative to anomalies detected and escalated by the Cyber Fusion Centre (CFC) according to Experian's Incident Response Plan. This team member will join a new, growing team of specialized, advanced responders to support escalations of complex or prioritized matters from Experian's existing 24x7 security monitoring and response functions responsible for responding to and analysing security incidents involving threats targeting Experian information assets. These threats may include phishing, malware, network attacks, and suspicious activity. You will work with end-users, partners, technical support teams, and management to ensure remediation and recovery from these threats. Use analytics & data collected from endpoints, environmental logging, and a variety of other sources to maximize containment and eradication of threats, while expediting recovery of the business. Please note you will have a regular Monday – Friday schedule and expectation to participate in on-call schedule or work outside of normal work hours to manage cybersecurity incidents. You will report to the CFC Senior Director of Incident Management and Security Operations.
Main Responsibilities include:
- Conduct advanced incident response activities to investigate and contain complex and larger-scale cybersecurity matters (such as potential major severity incidents).
- In the event of investigative matters requiring additional analytical support from teams such as Forensics and Cyber Threat Hunt workstreams across the teams, hold responsibility for expressing the CFC's overall understanding of the timeline of attacker activity so that appropriate containment and remediation actions can be coordinated.
- Respond to Security cyber security events and alerts associated with threats, intrusions, and compromises per any applicable SLOs.
- Manage multiple cases related to security incidents throughout the incident response lifecycle; including Analysis, Containment, Eradication, Recovery, and Lessons Learned.
- Maintain case documentation, including notes, analysis findings, containment steps, and cause for each assigned security incident.
- Maintain an understanding of common Operating Systems (Windows, Linux, Mac OS), Security Technologies (Anti-Virus, Intrusion Prevention), and Networking (Firewalls, Proxies).
- Interpret device and application logs from a variety of sources (e.g. Firewalls, Proxies, Web Servers, System Logs, Splunk, Packet Captures) to identify cause and determine next steps for containment, eradication, and recovery.
- Provide Advanced Support to analysts (Logs review, IP Block question).
- Mentor other analysts (process question, tool usage).
Experience and Skills
- Must have knowledge of network protocols (TCP/IP, UDP, ICMP), standard protocols (HTTP/S, DNS, SSH, SMTP, SMB), wireless networking, networking infrastructure, and network topologies (DMZ, VPN, WAN) and network technologies (WAF, IPS, Routers, Firewalls).
- Experience with commercial & open-source SIEMs, full packet capture tools, and network analysis tools (Splunk, Wireshark, SOF-ELK).
- Have a demonstrated knowledge of common intrusion methods and cyber-attack tactics, techniques, and procedures (TTPs).
- Exhibit skills using common Incident Response and Security Monitoring applications such as SIEM (Splunk), EDR (FireEye HX, CrowdStrike Falcon, McAfee mVision EDR), WAF, IPS.
Additional Information
- Benefits package includes: Flexible work environment, working hybrid or in the office if you prefer.
- Great compensation package and discretionary bonus plan.
- Core benefits include pension, Bupa healthcare, sharesave scheme and more.
- 25 days annual leave with 8 bank holidays and 3 volunteering days. You can purchase additional annual leave.
Experian is proud to be an Equal Opportunity and Affirmative Action employer. Innovation is an important part of Experian's DNA and practices, and our diverse workforce drives our success. Everyone can succeed at Experian and bring their whole self to work, irrespective of their gender, ethnicity, religion, colour, sexuality, physical ability or age. If you have a disability or special need that requires accommodation, please let us know at the earliest opportunity.
Cyber Incident Response Lead employer: Experian Group
Contact Detail:
Experian Group Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Cyber Incident Response Lead
✨Tip Number 1
Familiarise yourself with the specific tools and technologies mentioned in the job description, such as Splunk, Wireshark, and various EDR solutions. Having hands-on experience or certifications in these areas can significantly boost your confidence during interviews.
✨Tip Number 2
Stay updated on the latest cybersecurity threats and trends. Being able to discuss recent incidents or emerging attack vectors will demonstrate your passion for the field and your proactive approach to learning.
✨Tip Number 3
Network with professionals in the cybersecurity field, especially those who work in incident response. Attend industry conferences, webinars, or local meetups to build connections that could lead to referrals or insider information about the role.
✨Tip Number 4
Prepare for scenario-based questions that may be asked during the interview. Think through how you would handle specific security incidents, including your thought process for containment and recovery, to showcase your problem-solving skills.
We think you need these skills to ace Cyber Incident Response Lead
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in cybersecurity, particularly in incident response. Emphasise your familiarity with network protocols, security technologies, and any specific tools mentioned in the job description.
Craft a Strong Cover Letter: In your cover letter, express your passion for cybersecurity and detail your experience with handling security incidents. Mention specific examples of how you've responded to threats or managed complex cases in the past.
Showcase Relevant Skills: Clearly outline your technical skills related to incident response, such as knowledge of SIEM tools, packet capture tools, and your understanding of common intrusion methods. Use bullet points for clarity.
Highlight Team Collaboration: Since the role involves working with various teams, mention your experience in collaborative environments. Provide examples of how you've worked with technical support teams or management to resolve security incidents.
How to prepare for a job interview at Experian Group
✨Showcase Your Technical Knowledge
Make sure to brush up on your understanding of network protocols, security technologies, and incident response tools. Be prepared to discuss specific experiences where you've used these skills in real-world scenarios.
✨Demonstrate Problem-Solving Skills
Prepare to share examples of how you've handled complex cybersecurity incidents in the past. Highlight your analytical thinking and ability to coordinate with different teams to resolve issues effectively.
✨Understand the Company’s Culture
Familiarise yourself with Experian's values and mission. Showing that you align with their commitment to innovation and diversity can set you apart from other candidates.
✨Ask Insightful Questions
Prepare thoughtful questions about the Cyber Fusion Centre's operations and future challenges. This shows your genuine interest in the role and helps you assess if the company is the right fit for you.