Senior Security Consultant (Incident Response)

Senior Security Consultant (Incident Response)

Vollzeit 63000 - 77000 € / Jahr (geschätzt) Homeoffice (teilweise)
L

Auf einen Blick

  • Aufgaben: Leite Cyber-Incident-Response-Teams und reagiere auf komplexe Sicherheitsvorfälle.
  • Unternehmen: LRQA, ein führendes Unternehmen für Cybersicherheit mit globaler Reichweite.
  • Vorteile: Hybrid-Arbeitsmodell, attraktive Vergütung und Unterstützung bei der beruflichen Weiterbildung.
  • Weitere Informationen: Dynamisches Team mit Möglichkeiten zur persönlichen und beruflichen Weiterentwicklung.
  • Warum dieser Job: Gestalte die Zukunft der Cybersicherheit und arbeite an spannenden Herausforderungen.
  • Qualifikationen: Erfahrung im IT-Sicherheitsbereich und starke analytische Fähigkeiten.

Das prognostizierte Gehalt liegt zwischen 63000 - 77000 € pro Jahr.

This is a new, exciting opportunity for a Senior Security Consultant to join LRQA's existing dynamic Cyber Incident Response Team., This role follows a hybrid working arrangement and will involve working on client sites and from the office from time to time.

We support remote work across the UK; however, the main office is in Birmingham.

Applicants are required to be resident in the UK.

What You'll Be Doing The successful candidate will be responsible for responding to and leading cyber incidents within LRQA Group and LRQA's professional service and Defensive Security Service (DSS) customers, providing education (internally and externally) and improving the team's capability, in line with managerial direction.

The role will lead a team of responders, as well as conduct solo incident investigations, where the actor operates with a high level of sophistication (Organised Crime or above) using agreed mitigation, preparedness, and response and recovery approaches, as needed, to minimise the impact of a cyber-incident.

They will design and execute training engagements that will prepare all levels of stakeholders for a cyber-incident, and keep up to date with the latest CTI industry developments, security developments, vulnerabilities, attacks, news and techniques aligned to Mitre ATT&CK and use this to further the team's capability.

They are expected to operate autonomously using judgement to elevate issues to senior management when appropriate.

They must continue to maintain a relevant industry level certification preferably the CREST CCIM and at least one other CREST Certified level certification in the Incident Response field, for which LRQA will provide support.

  • Key Role Responsibilities
  • The following list is indicative of the overall expectations of the role (not exhaustive):
  • In conjunction with the Customer Engagement Manager and Cyber Incident Manager, manage the collective technical response to customer cyber incidents.
  • In conjunction with the DSS leadership, develop and drive the IR strategy.
  • In conjunction with the DSS leadership, develop, refine and monitor IR policies, procedures and technical capability.
  • Conduct analysis and investigation of cyber security events across Windows, Linux, Cloud and Hybrid environments.
  • Conduct digital imaging and forensic investigation tasks on Windows and Linux hosts.
  • Conduct initial triage on suspicious artefacts using both commercial and bespoke tools
  • Provide customer training engagements to develop internal and external stakeholder preparedness for dealing with cyber incidents.
  • Provide written and verbal reports to the wider IR team, senior business partners (internal and external).
  • Conduct ongoing research around the threat landscape, including threat actors, TTPs and develop IR actions, investigation strategies and tooling.
  • A team-first, collaborative approach working across all relevant technical teams to identify opportunity for improvement in detection sets.
  • Excellent problem-solving skills and self-motivated to learn and upskill regularly.
  • A strong desire to continually challenge and develop yourself as part of a fast-paced, high-performing team., If you are successful in securing a role with us, we will carry out preemployment checks in accordance with what is permitted under local law.

These checks may include, where legally allowed: right to work, identification, verification of employment history, education, and criminal record checks.

We will engage our thirdparty background screening provider, Cfirst to conduct these checks on our behalf.

Cfirst performs all processing in full compliance with applicable data protection laws and adheres to strict legal, regulatory, and ethical obligations in handling personal data.

Any personal information collected for the purpose of these checks will be used solely for evaluating your suitability for employment and will be retained only for as long as necessary to fulfil these purposes and meet legal requirements.

Your data will be stored securely and managed in accordance with all relevant privacy legislation.

The following list of requirements are pre-requisites for the role

  • Demonstrably strong incident management and analytical skills.
  • Demonstrably strong written and speaking English skills.
  • Demonstrably strong understanding of Threat Actor TTP's.
  • Demonstrably strong commercial awareness.
  • Demonstrable ability to work on own projects and within a team.
  • At least 36 months of relevant IT Security industry experience in past 4 years.
  • An ability to lead, teach, present and inspire customers and the wider team.
  • Ability to travel to UK customer locations where requested and non-UK customer locations where mutually agreed.
  • Ability to join 24/7 on-call rota.

We value capability over credentials. We're not looking for badge collectors. That said, one or more of the following will serve as a distinct advantage:

  • CREST CCIM / CRIA
  • GIAC GCFA / GCIH / GNFA
  • UKSC Chartered / Principal Professional in IR
  • Similar

At LRQA our focus has always been on excellence in cyber security.

We have teams that offer world class services in red teaming, penetration testing, threat intelligence, research and development, detection and response, governance, risk, and compliance, and plenty more.

Our business is global and so are our clients.

We work closely with central banks, central and local government, critical national infrastructure, large retailers, and plenty more besides!

We're an award-winning provider of cyber security services and we're at a very exciting stage of development.

We are looking for the right people to join us as we embrace the challenges thrown up by the advancements within the IT industry and within the threats faced.

LRQA will be at the forefront of this arena and we want to seek the right people to join the team and make it happen.

At LRQA, we belive that as a leading Global Leading Assurance and Risk Management Service provider, our talented people are our risk management advantage.

We belive the best outcomes come from diverse perspectives, shared ambition and working together with integrity.

That's how we buid a workplace where everyone can contribute, grow and thrive.

Guided by Vision and powered by Expertise, we're united by a shared purpose.

If you're driven to make a difference, you'll belong here.

We offer you an exciting working environment with intellectual challenges, high levels of responsibility and client exposure and a collaborative team with strong technical depth.

An attractive package is available for the right candidates.

#J-18808-Ljbffr

Senior Security Consultant (Incident Response) Arbeitgeber: LRQA Group Limited 2021

LRQA ist ein hervorragender Arbeitgeber, der seinen Mitarbeitern die Möglichkeit bietet, in einem dynamischen und unterstützenden Umfeld zu wachsen. Mit einem starken Fokus auf Weiterbildung und Entwicklung, einschließlich der Qualifikation zum Lead Auditor, fördern wir eine Kultur der Zusammenarbeit und des Engagements, die es jedem ermöglicht, einen bedeutenden Beitrag zu leisten. Unsere flexible Arbeitsweise und die internationale Reichweite bieten einzigartige Vorteile, um eine nachhaltige Zukunft in der Luft- und Raumfahrtbranche zu gestalten.

L

Kontaktdaten:

LRQA Group Limited 2021 Recruiting-Team

StudySmarter Expertenrat🤫

Wir sind der Meinung, dass du so Senior Security Consultant (Incident Response) erhalten könntest

Werde sichtbar in der IT-Sicherheits-Community

In der IT-Sicherheit gibt’s eine Menge Fachkreise und Konferenzen, die super für Networking sind. Schau dir Events wie die "IT-Security Convention" oder regionale Meetups an, um Gleichgesinnte und potenzielle Arbeitgeber wie LRQA Group Limited 2021 kennenzulernen!

Kollaboriere an Open-Source-Projekten

Zeig dein Können und engagiere dich in Open-Source-Projekten, die auf IT-Sicherheit abzielen. Das ist nicht nur eine tolle Möglichkeit, praktische Erfahrungen zu sammeln, sondern auch, um dein Portfolio zu erweitern und Sichtbarkeit in der Branche zu gewinnen.

Nutze spezielle Jobportale für IT-Sicherheit

Schau auf spezialisierten Jobportalen wie "heise jobs" oder "StepStone" nach offenen Stellen in der IT-Sicherheit. Hier findest du viele Angebote, die nicht immer auf den großen Plattformen gelistet sind. Vergiss nicht, dich direkt auf der Website von LRQA Group Limited 2021 zu bewerben!

Halte deine Skills up-to-date

In der IT-Sicherheit bleibt nichts stehen, also bleib am Ball! Investiere Zeit in Weiterbildung und besuche Online-Kurse oder Webinare zu aktuellen Sicherheitsthemen. Das zeigt nicht nur dein Engagement, sondern stärkt auch dein Profil bei LRQA Group Limited 2021.

Wir glauben, dass du diese Fähigkeiten brauchst, um Senior Security Consultant (Incident Response) mit Bravour zu bestehen

Incident Management
Analytische Fähigkeiten
Englischkenntnisse (schriftlich und mündlich)
Verständnis von Bedrohungsakteuren und deren TTPs
Kommerzielle Awareness
Fähigkeit zur Teamarbeit und eigenständigen Projektarbeit
Führungskompetenz

Einige Tipps für deine Bewerbung 🫡

Zeig deine technischen Skills!:Im Bereich IT-Sicherheit ist es wichtig, dass du deine technischen Fähigkeiten klar kommunizierst. Stelle sicher, dass dein Lebenslauf relevante Zertifikate (wie CEH oder CISSP) sowie praktische Erfahrungen bei Sicherheitsprojekten oder Penetrationstests zeigt. Dies wird uns helfen, einen besseren Eindruck von deinem Fachwissen zu bekommen.

Präsentiere dein Wissen über aktuelle Trends:Wir möchten sehen, dass du über die neuesten Entwicklungen im Bereich IT-Sicherheit informiert bist. In deinem Anschreiben kannst du beispielsweise auf ein aktuelles Sicherheitsproblem oder einen neuen Standard eingehen, den du für relevant hältst. Dadurch zeigst du uns, dass du dich aktiv mit dem Thema auseinandersetzt und für die Position brennst.

Mach deine Leidenschaft deutlich:Da es sich um eine Vollzeitposition handelt, ist es wichtig, dass du uns in deinem Anschreiben zeigst, warum du in der IT-Sicherheit arbeiten möchtest. Erzähl uns von deinen Erfahrungen, wie du zur Cyber-Security gekommen bist und was dich motiviert, in dieser Branche zu arbeiten. Deine Motivation spielt eine große Rolle bei der Auswahl!

Referenzen oder Projekte anfügen:Wenn du bereits an interessanten Projekten gearbeitet hast oder relevante Referenzen hast, die deine Fähigkeiten unterstreichen, füge diese in deine Bewerbung hinzu. Das gibt uns einen Einblick in deine praktische Erfahrung und zeigt, was du wirklich drauf hast. Ein Link zu einem GitHub-Profil oder Sicherheitsanalysen, die du durchgeführt hast, wäre hier super hilfreich!

Wie man sich auf ein Vorstellungsgespräch bei LRQA Group Limited 2021 vorbereitet

Sicherheitsprotokolle dominiert!

Mach dich mit den neuesten Sicherheitsprotokollen und -standards vertraut. Bei LRQA Group Limited 2021 könnte es sein, dass du in technisch anspruchsvollen Fragen zu Netzwerksicherheit und Schwachstellenmanagement gefordert wirst – zeig, dass du die Grundlagen und die aktuellen Trends im Bereich IT-Sicherheit beherrschst!

Praktische Erfahrung zählt!

Bereite dich darauf vor, über frühere Projekte oder Erfahrungen im Bereich IT-Sicherheit zu sprechen. Es ist wichtig, Beispiele zu haben, wie du Sicherheitslücken identifiziert und behoben hast oder welche Tools du verwendet hast, um Systeme abzusichern. LRQA Group Limited 2021 sucht nach jemandem, der die Theorie auch anwenden kann!

Teamarbeit nicht vergessen!

IT-Sicherheit ist oft Teamarbeit. Sei bereit, Fragen zu beantworten, wie du in einem Team umgehst, um Sicherheitsprobleme zu lösen. Denk auch an Beispiel-Situationen, in denen du optimal mit anderen zusammengearbeitet hast – das könnte einen großen Unterschied machen!

Motivation und Lernbereitschaft zeigen!

Da es sich um eine Vollzeitstelle handelt, wird LRQA Group Limited 2021 auch wissen wollen, wie motiviert du bist und welche Schritte du unternimmst, um dein Wissen in der sich ständig weiterentwickelnden Welt der IT-Sicherheit auf dem neuesten Stand zu halten. Das könnte in einem Gespräch über deine Weiterbildung oder zertifikatsbezogenen Pläne relevant sein!