At a Glance
- Tasks: Lead a dynamic Blue Team to protect our business from cyber threats.
- Company: Join Hiscox, a leader in cybersecurity with a commitment to diversity and inclusion.
- Benefits: Enjoy hybrid working, competitive salary, bonus, and generous leave policies.
- Other info: Opportunity for continuous learning and career growth in a vibrant team.
- Why this job: Make a real impact in cybersecurity while developing your skills in a supportive environment.
- Qualifications: 6+ years in security operations, with strong leadership and technical skills.
The predicted salary is between 60000 - 80000 € per year.
Build a brilliant future with Hiscox.
The Blue Team Leader works in our Cyber Fusion Centre, and plays a pivotal role in the protection of our business assets and interests from cyber threats. You will focus on the development of our proactive and defensive capabilities, orchestrating security operations and optimising the efforts of our Blue Team. You will support in the development and implementation of our overall cybersecurity strategy, and plan activities and initiatives to meet our business security objectives. You will need to be naturally inquisitive, have a comprehensive understanding of the latest cyber threats and how to counter them. You will also be a member of our Cyber Incident Response Team (CIRT) and will need to lead our initial response.
You will work closely with our Red Team Leader and Cyber Delivery Leader to identify threats and vulnerabilities present in our network and systems, and turn these into a pipeline of continuous improvement for our cyber defences. You will also work closely with our Head of Cyber Fusion Centre to co-ordinate daily activities in support of their primary objectives. You will also be responsible for working with project delivery teams from across our business, where you will provide expert technical security advice and guidance and support their onboarding activities to the Fusion Centre. You will need hands-on experience working with a multitude of different security technologies, be able to lead and coach your team of analysts and be able to work in a high-paced operational environment.
The role is based in either York (UK) or Lisbon (Portugal) and is a permanent position. Travel to other team locations will be required as necessary.
Key Responsibilities- Direct and guide the Blue Team in their daily operations, ensuring alignment with our business security objectives and latest threat intelligence.
- Oversee the continuous monitoring of our networks and systems for security breaches or anomalies.
- Design and maintain incident response plans to address and mitigate potential security breaches.
- Co-ordinate Blue Team exercises to ensure analysts are confident in detecting and responding to cyber threats, and that we have the required data points needed to support detection of potential incidents.
- Allocate and manage resources effectively to ensure optimal team performance and address any skill, performance or resource gaps.
- Perform routine gap analysis of detection use cases and identify new data sources for onboarding to the SIEM platform to ensure observability of the latest TTPs.
- Leverage actionable threat intelligence to develop new detection use cases to support the ongoing continuous improvement of our SIEM capabilities.
- Ensure the operational resilience of our proactive and defensive cyber capabilities, including our technology, people and process used to support detection and response.
- Lead initial response to detection of security incidents, ensuring timely and effective resolution, escalation where necessary and perform any post incident analysis for lessons learned.
- Coach and mentor your team to support their professional development, fostering an environment of continuous learning and improvement.
- Develop and maintain our security operations policies, processes and playbooks.
- Maintain an up-to-date knowledge of the latest security tools and technologies, and how these could be used to mitigate our priority threats.
- Provide regular reports on security status, incidents and KRIs to senior management and stakeholders.
- 6+ years experience in a security operations team, preferably 2 years in a management role.
- Demonstrable experience leading response to security incidents and breaches.
- Excellent understanding of defensive security strategies and cyber incident response processes.
- Excellent working knowledge of SIEM based tools and technologies.
- Excellent working knowledge of EDR and XDR technologies.
- Excellent working knowledge of firewalls and other network security appliances.
- Excellent problem solving and analytical skills, with the ability to make sound decisions under pressure.
- Excellent leadership and management skills, with strong communications and interpersonal skills.
- Good understanding of forensics technologies and processes.
- BSc or MSc in Cybersecurity is highly desirable.
- Advanced cyber certifications such as CISSP, CISM, GCIH and GPEN are desirable.
- Industry recognised security vendor certifications are desirable.
At Hiscox we care about our people. We hire the best people for the job and we’re committed to diversity and creating a truly inclusive culture, which we believe drives success. Working life doesn’t always have to be in the office, so we have introduced hybrid working to encourage a healthy work life balance. This hybrid working model is set by the team rather than the business to enable you to manage your own personal work-life balance. We see it as the best of both worlds; structure and sociability on one hand, and independence and flexibility on the other. Our benefits package includes a bonus, contributory pension, 25 days annual leave plus 2 Hiscox days and a 4 week paid sabbatical with every 5 years’ worth of service, private medical for all the family and much more. Work with amazing people and be part of a unique culture.
Blue Team Leader in York employer: Hiscox
Hiscox is an exceptional employer that prioritises the well-being and professional growth of its employees, offering a dynamic work environment in either York or Lisbon. With a strong commitment to diversity and inclusion, the company fosters a culture of continuous learning and improvement, supported by a comprehensive benefits package that includes hybrid working options, generous leave policies, and opportunities for career advancement. Join us to work alongside talented professionals in a role that not only challenges you but also contributes significantly to the security of our business.
StudySmarter Expert Advice🤫
We think this is how you could land Blue Team Leader in York
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the cybersecurity field. Attend meetups, webinars, or even local events. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those related to security operations. This gives potential employers a taste of what you can do and sets you apart from the crowd.
✨Tip Number 3
Prepare for interviews by brushing up on common cybersecurity scenarios. Think about how you'd handle specific incidents or threats. Practising your responses will help you feel more confident and ready to impress during the interview.
✨Tip Number 4
Don't forget to apply through our website! We love seeing applications directly from candidates who are genuinely interested in joining our team. Plus, it shows you're proactive and keen on being part of our Cyber Fusion Centre.
We think you need these skills to ace Blue Team Leader in York
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Blue Team Leader role. Highlight your experience in security operations and any leadership roles you've held. We want to see how your skills align with our needs!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about cybersecurity and how you can contribute to our Cyber Fusion Centre. Let us know what makes you tick!
Showcase Your Technical Skills:Don’t hold back on showcasing your technical expertise! Mention specific tools and technologies you’ve worked with, especially SIEM, EDR, and XDR. We love seeing hands-on experience that matches our requirements.
Apply Through Our Website:We encourage you to apply through our website for a smoother process. It’s the best way for us to receive your application and keep track of it. Plus, it shows you’re keen on joining our team!
How to prepare for a job interview at Hiscox
✨Know Your Cybersecurity Stuff
Make sure you brush up on the latest cyber threats and defensive strategies. Familiarise yourself with SIEM tools, EDR/XDR technologies, and incident response processes. Being able to discuss these topics confidently will show that you're not just a candidate, but a potential leader in the field.
✨Showcase Your Leadership Skills
As a Blue Team Leader, you'll need to demonstrate your ability to lead and mentor a team. Prepare examples of how you've successfully managed teams in the past, especially during high-pressure situations. Highlight your coaching style and how you foster continuous learning within your team.
✨Prepare for Scenario-Based Questions
Expect to face scenario-based questions that test your problem-solving skills and decision-making under pressure. Think about past incidents you've handled and be ready to explain your thought process, actions taken, and lessons learned. This will showcase your analytical skills and experience in real-world situations.
✨Align with Their Culture
Hiscox values diversity and a healthy work-life balance, so be prepared to discuss how you can contribute to their inclusive culture. Share your thoughts on hybrid working and how you manage your own work-life balance. This will help you connect with the interviewers on a personal level and show that you fit into their company ethos.