Lead Threat Response Operations Analyst in England

Lead Threat Response Operations Analyst in England

England Full-Time 63000 - 77000 £ / year (est.) Home office (partial)
P

At a Glance

  • Tasks: Lead investigations into cyber threats and coordinate global incident responses.
  • Company: Join Pfizer's Global Cyber Defense team, dedicated to safeguarding digital assets.
  • Benefits: Enjoy a flexible work culture, competitive salary, and opportunities for professional growth.
  • Other info: Be part of a diverse team committed to innovation and excellence.
  • Why this job: Make a real impact in cyber security while working with cutting-edge technologies.
  • Qualifications: Experience in cyber security operations and strong analytical skills required.

The predicted salary is between 63000 - 77000 £ per year.

Job Description

ROLE SUMMARY

Our Global Cyber Defense team is responsible for safeguarding Pfizer's digital assets and infrastructure through proactive threat detection, incident response, and risk mitigation across on-premises, cloud, and hybrid environments.

As a Lead Threat Response Operations Analyst within Pfizers Global Cyber Defense organization, you will serve as a senior individual contributor, providing technical leadership for the investigation and response to sophisticated cyber threats.

While this is not a people-management role, you will lead complex investigations, coordinate the response to security incidents on a global scale, and provide technical guidance to analysts and partner teams.

You will bring deep expertise in cyber threat analysis, incident response, malware investigations and adversary tradecraft, with the ability to operate confidently across complex business and technical environments.

Working alongside Threat Detection, Digital Forensics, Security Engineering and other partner teams, you will identify, contain and eradicate threats while providing strategic recommendations to strengthen Pfizers cyber resilience.

  • ROLE RESPONSIBILITIES
  • Correlate and analyse security telemetry from endpoint, identity, network, cloud, email and threat intelligence sources to identify, investigate and respond to malicious activity.
  • Apply knowledge of adversary tactics, techniques and procedures (TTPs) to reconstruct attack lifecycles, determine attack pathways, identify root cause and develop strategic detection and mitigation recommendations.
  • Lead the assessment of cyber security incidents, determining severity, business impact, threat scope, and appropriate response and escalation actions.
  • Apply advanced knowledge of networking, operating systems and security architectures to analyse technical evidence, identify attack vectors and guide effective containment, eradication and remediation actions.
  • Communicate complex technical findings, incident impacts, response decisions and remediation recommendations clearly to technical teams, business stakeholders and senior leadership.
  • Drive continuous improvement of Threat Response processes, investigation methodologies, operational procedures, reporting standards, and playbooks to enhance the effectiveness and maturity of the cyber incident response capability
  • Co-ordinate effectively across technical and business teams to coordinate cyber incident response activities, maintaining professionalism and sound judgement during high-pressure situations.
  • Lead complex cyber security projects and cross-functional workstreams, ensuring timely delivery of objectives and operational improvements.

Support the triage of cyber security tickets, providing technical guidance on priority, scope, investigation, escalation and appropriate response actions.

  • Provide technical guidance, coaching and knowledge sharing to analysts and partner teams to strengthen investigation quality and Threat Response capability.
  • Participate in a scheduled on-call rotation, including weekends, providing timely response, investigation, escalation, and coordination of cyber security incidents.
  • Maintain and continuously develop technical expertise in cyber security, threat response, and emerging attack techniques through ongoing training, research, and professional development.
  • BASIC QUALIFICATIONS
  • Bachelors degree in cyber security, computer forensics, computer science, Information Security, Information Systems, Engineering, Sciences or related field.
  • Some relevant experience in cyber security operations, incident response or threat investigation, with demonstrated experience leading complex investigations.
  • Advanced understanding of TCP/IP, network protocols and traffic flows, operating systems, cloud and identity technologies, enterprise security architectures and defence-in-depth principles.
  • Advanced knowledge of Windows operating systems, system administration, security controls, native utilities and investigative artefacts.
  • Demonstrated ability to analyse and correlate large volumes of security log data using security information and event management (SIEM) platforms, such as Crowd Strike Falcon Next-Gen SIEM, Splunk, Google Sec Ops and draw accurate, evidence-based conclusions.
  • Experience using endpoint detection and response (EDR) platforms, such as Crowd Strike Falcon, Microsoft Defender for Endpoint or VMware Carbon Black, to investigate malicious activity, analyse endpoint telemetry and support incidentcontainment and remediation.
  • Experience using security analysis and investigation tools such as Wireshark, Snort, Splunk, Kali Linux, SIFT Workstation, REMnux and Volatility or comparable commercial and open-source technologies, including tools used for memory forensics and malware analysis.
  • Advanced understanding of the life cycle of network threats, attacks, attack vectors and methods of exploitation with an understanding of intrusion set tactics, techniques and procedures (TTPs)
  • Demonstrated ability to analyse and resolve complex technical problems, working independently and collaboratively within cross-functional teams.
  • Maintain and continuously develop technical expertise in cyber security, threat response and emerging attack techniques through ongoing training, research and professional development.
  • Strong written, verbal and interpersonal communication skills, together with demonstrated organisational and planning abilities and the capacity to coordinate multiple complex investigations and workstreams simultaneously.
  • Excellent communication and presentation skills with the ability to present to a variety of internal audiences including senior executives.
  • Demonstrated experience leading and delivering complex cyber security projects and cross-functional workstreams, achieving both short-term objectives and longer-term operational improvements.
  • Practical experience using the Linux command line to support security investigations, data analysis and the operation of cyber security tools.

Preferred qualification

  • Participation in practical cyber security exercises, such as red team and blue team simulations, capture-the-flag challenges, cyber ranges or incident response exercises.
  • Experience using scripting or programming languages, such as Python or Power Shell, to support security investigations, analyse security data and automate repetitive tasks.
  • Work Location Assignment: Hybrid
  • Purpose

Breakthroughs that change patients' lives...

At Pfizer we are apatient centric company, guided by our four values: courage, joy, equity and excellence.

Our breakthrough culture lends itself to our dedication to transforming millions of lives.

Digital Transformation Strategy

One bold way we are achieving our purpose is through our company wide digital transformation strategy.

We are leading the way in adopting new data, modelling and automated solutions to further digitize and accelerate drug discovery and development with the aim of enhancing health outcomes and the patient experience.

Flexibility

We aim to create a trusting, flexible workplace culture which encourages employees to achieve work life harmony, attracts talent and enables everyone to be their best working self.

Lets start the conversation!

Equal Employment Opportunity

We believe that a diverse and inclusive workforce is crucial to building a successful business.

As an employer, Pfizer is committed to celebrating this, in all its forms allowing for us to be as diverse as the patients and communities we serve.

Together, we continue to build a culture that encourages, supports and empowers our employees.

Dis Ability Confident

We are proud to be a Disability Confident Employer and we encourage you to put your best self forward with the knowledge and trust that we will make any reasonable adjustments necessary to support your application and future career.

Our mission is unleashing the power of our people, especially those with unique superpowers.

Your journey with Pfizer starts here!

To learn more about acceptable and prohibited uses of AI during the recruitment process, please review our candidate AI-use guidelines available on Pfizer Careers.

Information & Business Tech

Lead Threat Response Operations Analyst in England employer: Pfizer

At Pfizer, we pride ourselves on being an exceptional employer, offering a dynamic and inclusive work culture that prioritises employee well-being and professional growth. Our hybrid work model fosters flexibility, allowing you to balance your personal and professional life while contributing to groundbreaking advancements in healthcare. With a commitment to diversity and a focus on empowering our employees, you'll find meaningful opportunities to make a real impact in the lives of patients around the world.

P

Contact Details:

Pfizer Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Lead Threat Response Operations Analyst in England

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Pfizer, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Pfizer

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Pfizer. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Lead Threat Response Operations Analyst in England

Cyber Threat Analysis
Incident Response
Malware Investigations
Adversary Tradecraft
Security Telemetry Analysis
Networking Knowledge
Operating Systems Expertise

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Pfizer insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Pfizer that you’re committed to staying ahead in the game.

How to prepare for a job interview at Pfizer

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Pfizer to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Pfizer.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.