At a Glance
- Tasks: Lead incident response and security monitoring to protect our digital assets.
- Company: Join Mizuho, a forward-thinking company committed to diversity and inclusion.
- Benefits: Enjoy a flexible work environment and a strong focus on work-life balance.
- Other info: We welcome diverse applicants and are committed to equal opportunities.
- Why this job: Make a real impact in cyber security while developing your skills in a supportive culture.
- Qualifications: 3+ years in incident response leadership with expertise in security frameworks and tools.
The predicted salary is between 72000 - 108000 Β£ per year.
We are looking for a VP to join our Cyber Security Team in London.
Duties & Responsibilities
Incident Response and Security Monitoring:
- Analyse, develop and refine security monitoring controls, practices and use-cases to detect anomalies and incidents across the applications and infrastructure estate.
- Monitor activity upon specified information systems and devices. Identify and report suspicious, improper, malicious or harmful activity. To include regular and ad-hoc reporting.
- Undertake complex IR investigations into specific threats or security incidents both internal and external.
- Identification, escalation and reporting of security incidents and breaches. Co-ordination of responses to these breaches, assess the impact and improving the overall Incident Response process.
- Experience in incident investigation, and analytics of network and host-based artifacts.
- Experience with IR and Forensics tools, packet inspection tools
- Work alongside the company\'s independent penetration testing program.
- Work closely with other technical and business departments to mitigate security/cyber risk:
- Implement SOPs and refine processes.
- Identify potential security threats and risks that may need review.
- Assist in risk assessment/acceptance/remediation processes
- Develop and mature the Incident Response and Threat hunting capabilities.
- Implementation of Incident Response frameworks/methodologies such as Kill Chain, MITRE, Threat Modelling, Diamond Model.
- Development of Threat Intelligence capabilities and integration of such controls with the security monitoring framework.
- Development of Security monitoring use cases and implementing custom IOC within the controls to detect suspicious and unusual traffic.
- Development of Vulnerability Management program within the organisation.
- Provide support to the IR practises such as IR investigations, and forensics procedures/processes.
- Providing subject matter expertise in Cyber Security as needed.
- Contribute to the design and delivery of security monitoring and control effectiveness reporting measures.
- Availability to cover anywhere from 7am to 7pm on all business days noting that ad-hoc cover outside of the normal work day may sometimes be needed.
- Incident Response Leadership skills. Relevant experience in managing and oversee/coordinate Incident Response and Security Monitoring;
- Relevant experience in working with threat modelling frameworks.
- Experience in finding, analysing, and extracting attack related payload from packet captures and host forensics images.
- Experience in a banking, investment banking or investment management environment;
- Exp in leading the team of DFIR analysts.
- Experience working with Cyber Security and Incident Response frameworks such as NIST, Kill Chain, Attack life Cycle, & MITRE).
- Relevant experience with MITRE Att&Ck alignment with security monitoring use cases.
- Relevant experience with cloud security assessments aligning it to industry standard benchmarking such as CIS.
- Minimum of 3 years of experience in managing and leading DFIR team.
- Proven track record for managing high impact cyber security incidents.
- In depth knowledge of a broad spectrum of security technologies incorporating network, operating system and application security;
- Working knowledge over a range of operating systems and platforms including: Windows Server, Windows XP, UNIX (Solaris, Linux), Stratus;
- Working knowledge of networks: LAN, WAN, routers (Cisco), switches (Cisco), Firewalls, remote access solutions, VPNs;
- Coordinate with other security functions (SOC, Threat Intelligence and Red/Blue team)
- Experience in managing and running Threat hunting initiatives including developing Threat intelligence governance framework.
- In-depth experience with SIEM tools with a strategic oversight on appropriate use case methodologies. Implementation of robust security monitoring use cases and Threat hunting capabilities.
- Incident Response experience with forensics capabilities. Experience with packet analysis on wireshark or any other network protocol analyser including hands on exp with IR tools.
- Experience with Advance threat detection, IAM solutions and DLP is preferred.
- Working knowledge of security products: network based intrusion prevention systems, vulnerability assessment and compliance monitoring solutions, content management tools.
- Strong knowledge on Vulnerability Management, with proven record of Remediation plans to reduce the threats and risk to Information Assets.
- Understanding of VMware technology stack.
- Full understanding of CIS security standards, assessment of the builds to ensure the alignment with CIS benchmarking and working with business to achieve the target state.
- Knowledge of SSL inspection and encryption methods.
At Mizuho we are committed to supporting equality and diversity, and seek to create a workplace that is fully inclusive. We welcome applications from all sections of the community that we operate in and from all ethnic backgrounds, sexual orientation, beliefs, gender identities and disabilities.
If you require more information about our equal opportunities policy or wish to discuss any accessibility requirements or reasonable adjustments please contact the recruitment team - and we will be happy to help. #J-18808-Ljbffr
Vice President - Digital Forensics and Incident Response Manager in London employer: Mizuho International
Mizuho offers an exceptional work environment for the Vice President - Digital Forensics and Incident Response Manager role in London, fostering a culture of inclusivity and flexibility that prioritises work-life balance. Employees benefit from comprehensive professional development opportunities, collaborative teamwork across departments, and a commitment to cutting-edge security practices, making it an ideal place for those seeking meaningful and impactful careers in cyber security.
StudySmarter Expert Adviceπ€«
We think this is how you could land Vice President - Digital Forensics and Incident Response Manager in London
β¨Tip Number 1
Familiarise yourself with the latest incident response frameworks like MITRE and NIST. Being able to discuss these methodologies in detail during your interview will demonstrate your expertise and commitment to best practices in cyber security.
β¨Tip Number 2
Network with professionals in the cyber security field, especially those who have experience in incident response and digital forensics. Attend industry conferences or webinars to build connections and gain insights that could be beneficial during your application process.
β¨Tip Number 3
Stay updated on the latest trends and threats in cyber security. Being knowledgeable about recent incidents and how they were handled can provide you with valuable talking points in interviews and show that you are proactive in your field.
β¨Tip Number 4
Prepare to discuss your leadership experience in managing DFIR teams. Highlight specific examples of how you've successfully coordinated incident responses and improved processes, as this role requires strong leadership skills.
We think you need these skills to ace Vice President - Digital Forensics and Incident Response Manager in London
Some tips for your application π«‘
Tailor Your CV:Make sure your CV highlights relevant experience in incident response and security monitoring. Use specific examples that demonstrate your leadership skills and familiarity with frameworks like NIST and MITRE.
Craft a Compelling Cover Letter:In your cover letter, express your passion for cyber security and detail how your background aligns with the responsibilities outlined in the job description. Mention your experience with threat modelling and incident investigation to stand out.
Showcase Relevant Skills:Clearly list your technical skills related to digital forensics, packet analysis, and security technologies. Highlight any experience you have with SIEM tools and vulnerability management, as these are crucial for the role.
Prepare for Potential Questions:Anticipate questions related to your experience with incident response frameworks and your approach to managing high-impact cyber security incidents. Be ready to discuss specific scenarios where you've successfully led a team through a security breach.
How to prepare for a job interview at Mizuho International
β¨Showcase Your Incident Response Expertise
Be prepared to discuss your previous experience in incident response and how you've managed high-impact cyber security incidents. Highlight specific examples where you led investigations or coordinated responses to breaches, as this will demonstrate your capability for the role.
β¨Familiarise Yourself with Relevant Frameworks
Make sure you understand key incident response frameworks such as NIST, MITRE, and the Kill Chain. Be ready to explain how you've applied these methodologies in past roles, as this knowledge is crucial for the position.
β¨Demonstrate Technical Proficiency
Brush up on your technical skills related to packet analysis, SIEM tools, and various operating systems. You may be asked to solve a technical problem or discuss your experience with specific tools, so being well-versed will give you an edge.
β¨Emphasise Collaboration Skills
This role requires working closely with other departments to mitigate risks. Prepare to share examples of how you've successfully collaborated with teams in the past, particularly in a cyber security context, to show that you're a team player.