Jobs and Careers
MS

Global Technical Lead - Incident Response

MSD
Czechiafull_timeVerifiedPosted 21 Feb 2025

About the role

<p>Job Description</p><p></p><p><b>Global Technical Lead - Incident Response</b></p><p></p><p>At our company, we are dedicated to advancing the prevention and treatment of diseases in people and animals through innovative health solutions. We are seeking a highly skilled and motivated Global Technical Lead for Incident Response to join our team. This role offers the opportunity to lead and enhance our cybersecurity incident response efforts, ensuring the protection of our critical assets and data. If you are passionate about cybersecurity and thrive in a dynamic environment, we invite you to apply.</p><p></p><p><b>Responsibilities</b></p><ul><li>Facilitate and oversee the entire incident response lifecycle for cybersecurity incidents across multiple geographical regions, ensuring that all teams adhere to established protocols and practices throughout all phases, including Preparation, Detection &amp; Analysis, Containment, Eradication&amp; Recovery, and Post-Incident Activity</li><li>Coordinate and implement technical decisions across the IR teams as the global tech lead.</li><li>Perform in-depth analysis of escalations from SOC and IR analysts, offering constructive feedback during case reviews to improve response strategies.</li><li>Provide expert technical advice to SOC and IR analysts, enhancing their effectiveness in managing cybersecurity incidents.</li><li>Recommend and implement improvements to facilitate better collaboration between SOC and IR teams, aiming to reduce response times and streamline incident escalation processes.</li><li>Analyze the potential impact of new threats detected during IR workflow and drive new technical solutions to address newly detected risks to the company.</li><li>Ensure that comprehensive technical incident <span>documentation—analysis</span> findings, containment actions, and root cause analysis—is accurately maintained for each incident.</li><li>Assist in interpreting logs from various devices and applications to identify root causes and determine actionable next steps in the containment, eradication, and recovery phases.</li><li>Validate and provide inputs to incident response plans and processes, adapting them to address emerging threats effectively.</li><li>Identify opportunities for workflow automation within incident analysis procedures to reduce response times and eliminate unnecessary manual steps.</li><li>Develop specialized expertise to discern patterns of complex threat actor behavior and communicate insights regarding current and evolving cyber threats.</li><li>Maintain an extensive understanding of common operating systems (Windows, Linux, Mac OS), security technologies (e.g., EDR, XDR, intrusion prevention system), and networking components (e.g., firewalls, proxies).</li></ul><p></p><p><b>Qualifications</b></p><p><b>Required</b></p><ul><li><b>Demonstrated leadership skills</b>: Ability to effectively lead technical teams, fostering collaboration and innovation within incident response functions.</li><li><b>Extensive incident response experience</b>: A robust background in incident response and cybersecurity, with hands-on experience in real-world scenarios.</li><li><b>Crisis management experience</b>: Proven ability to lead effectively during high-pressure situations, managing crises and coordinating response efforts.</li><li><b>Cross-team coordination</b>: Experience in coordinating and implementing technical decisions across diverse teams.</li><li><b>Expert technical advisor</b>: Proven ability to provide expert technical advice and constructive feedback to SOC and IR analysts.</li><li><b>Familiarity with industry standards</b>: Knowledge of frameworks such as NIST, SANS, and MITRE ATT&amp;CK to guide incident response best practices.</li><li><b>Log analysis proficiency</b>: Skilled in analyzing and interpreting logs from a variety of devices and application.</li><li><b>Presentation and training skills</b>: Experience presenting incident response findings and conducting training sessions for SOC and IR teams to enhance their capabilities.</li><li><b>Leveraging cyber threat intelligence</b>: Proficient in utilizing threat intelligence sources to inform incident response strategies and drive operational improvements.</li><li><b>Technical understanding</b>: Strong grasp of common operating systems (Windows, Linux, macOS), security technologies (e.g., EDR, XDR, Intrusion Prevention Systems), and networking components (e.g., firewalls, proxies).</li><li><b>Documentation excellence</b>: Exceptional documentation skills for maintaining comprehensive records of incidents, including actions taken and outcomes.</li></ul><p><b>Preferred</b></p><ul><li><b>Advanced cybersecurity certifications</b>: Possession of advanced certifications (e.g., CISSP, DFIR, CEH, OSCP).</li><li><b>Digital forensics expertise</b>: Skills in digital forensics techniques for analyzing incidents and supporting investigations.</li><li><b>Scripting and automation proficiency</b>: Knowledg

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

MSD

View company profile →