IBM X-Force - Senior Incident Response Consultant in Warwick
IBM X-Force - Senior Incident Response Consultant

IBM X-Force - Senior Incident Response Consultant in Warwick

Warwick Full-Time No home office possible
Go Premium
IBM

Join to apply for the IBM X-Force – Senior Incident Response Consultant role at IBM.

Information and Data are some of the most important organizational assets in today’s businesses. As a Security Consultant, you will be a key advisor for IBM’s clients, analysing business requirements to design and implement the best security solutions for their needs. You will apply your technical skills to find the balance between enabling and securing the client’s organization with the cognitive solutions that are making IBM the fastest growing enterprise security business in the world.

Your Role And Responsibilities

As a senior consultant for the IBM Security X-Force Incident Response (X-Force IR) team, you will be responsible for the growth and delivery of X‑Force IR services. You will lead a team of consultants who respond to high‑profile cybersecurity incidents within our clients’ enterprise networks. You will work with clients to proactively prevent and detect future incidents, serve as a trusted advisor, and shape their cybersecurity program. You will collaborate with internal IBM stakeholders to provide integrated solutions to clients’ most challenging problems.

In this role you will have demonstrated skills in various elements of incident response, conducting computer intrusion investigations, and a strong foundation in cyber security policy, operations, and best practices – ideally in large enterprise environments. You will be proficient with leading EDR tools and familiar with forensic analysis tools such as X‑Ways, EnCase Forensic, or FTK, as well as live‑response analysis. Familiarity with Windows and Linux enterprise environments, Active Directory, M365, firewalls, IPS/IDS, SIEMs, etc. is required. Excellent written and verbal communication skills are required.

When not responding to breaches, you will conduct enterprise threat hunting, help clients develop incident response plans, facilitate tabletop and purple team exercises, and provide other strategic security services related to incident response.

Preferred Education

None

Required Technical And Professional Expertise

  • 2 years of experience with assessing and developing enterprise‑wide policies and procedures for IT risk mitigation and incident response.
  • Experience leading incident response teams and managing tasks across all phases of an engagement.
  • Experience managing a team of consultants with similar skills.
  • Capable of working independently as well as providing leadership on internal projects and client engagements.

Forensic Analysis & Incident Response Skills

  • Ability to forensically analyze both Windows & Unix systems for evidence of compromise.
  • Proficiency with industry standard forensic tools such as EnCase, FTK, X‑Ways, Sleuthkit.
  • Experience performing log analysis locally and via SIEM/log aggregation tools.
  • Experience hunting threat actors in large enterprise networks and cloud environments.
  • Experience with using and configuring Endpoint Detection & Response (EDR) tools.
  • Demonstrate an understanding of the behaviour, security risks and controls of common network protocols.
  • Demonstrate an understanding of common applications used in Windows and Linux enterprise environments. Familiarity with Active Directory, Exchange and Office365 applications and logs.
  • Familiarity with the tools and techniques required to analyse & reverse diverse protocols and data traversing a network environment.
  • Familiarity with cloud computing platforms like IBM Cloud, AWS, GCP or Azure.
  • Proficient in writing cohesive reports for a technical and non‑technical audience.

Strategic Assessment Expertise

  • Examine and analyze available client internal policies, processes, and procedures to determine patterns and gaps at both strategic and tactical levels. Recommend appropriate course of action to support maturing the client’s incident response program and cyber security posture.
  • Strong familiarity with various security frameworks and standards such as ISO 27001/2, PCI DSS, NIST800‑53, 800‑171, and applicable data privacy laws and regulations.
  • Demonstrated experience with planning, scoping, and delivering technical and/or executive level tabletop exercises, with a focus on either tactical or strategic incident response processes.
  • Ability to incorporate current trends and develop custom scenarios applicable to a client.
  • Low-level operating system knowledge, including automation and performing administrative tasks.
  • Scripting or programming experience, preferably in a language commonly used for DFIR such as Python or PowerShell.
  • Ability to work with data at scale such as using Splunk / ELK.
  • Expertise in working with shell programs such as grep, sed and awk to process data quickly.
  • Working experience with virtualisation and cloud technology platforms like IBM Cloud, AWS, GCP & Azure.

Preferred Technical And Professional Experience

  • Diverse understanding of cyber security related vulnerabilities, common attack vectors, and mitigations.
  • Capable of developing strategic level incident response plans as well as tactical‑focused playbooks.
  • Ability to manage tasks and coordinate work streams during incident response investigations.

Seniority Level

Mid‑Senior level

Employment Type

Full‑time

Job Function

Other

Industries

IT Services and IT Consulting

#J-18808-Ljbffr

IBM

Contact Detail:

IBM Recruiting Team

IBM X-Force - Senior Incident Response Consultant in Warwick
IBM
Location: Warwick
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>