Cyber Incident Response Lead
DTCCAbout the role
Are you ready to make an impact at DTCC?
Do you want to work on innovative projects, collaborate with a dynamic and encouraging team, and receive investment in your professional development? At DTCC, we are at the forefront of innovation in the financial markets. We're committed to helping our employees grow and succeed. We believe that you have the skills and drive to make a real impact. We foster a thriving internal community and are committed to crafting a workplace that looks like the world that we serve.
Pay and Benefits:
- Competitive compensation, including base pay and annual incentive
- Comprehensive health and life insurance and well-being benefits, based on location
- Pension / Retirement benefits
- Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
- DTCC offers a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee).
The Impact you will have in this role:
As a member of the Cyber Blue Team at DTCC, you directly contribute to the security and stability of the global financial system. The mission of the Cyber Blue Team is to protect the organization from external cyber threats and to respond to and manage cyber incidents. Through multiple teams located in different geographic locations, the blue team performs round-the-clock monitoring and leads cyber incident response, digital forensics, and eDiscovery functions. As a critical component of the risk organization, the blue team’s performance and initiatives are scrutinized directly by the board and industry regulators. As a result, we maintain an aggressive exercise tempo including weekly, monthly, and quarterly exercises as well as numerous drills and assessments.
Reporting to the Cyber Blue Team Director, you are responsible for managing the firm’s response to cyber security incidents, conducting post-incident activities such as Root Cause Analysis, and preparing the Cyber Blue Team to respond to incidents through trainings, exercises, and drills. As a senior member of the Cyber Blue Team, you are a subject matter expert in cybersecurity helping to prepare the firm to withstand the impacts of cyber-attacks as well as providing key tactical leadership during major incidents. During a cyber incident, you will be responsible for assembling and leading a cross-functional team of technical experts from throughout the organization to respond to, contain, and recover from cyber incidents.
Your Primary Responsibilities
- Assemble and lead the Cyber Security Incident Response Team as Incident Commander or Operations Section Chief during critical cyber incidents.
- Provide technical leadership throughout including the post-incident phase of cyber incidents.
- Support post-incident activities such as Root Cause Analysis, After-Action Reviews, and walkthroughs of the incident with regulators and senior leaders.
- Produce written reports including detailed analysis, timelines, recommendations, and lessons learned.
- Plan and facilitate exercises, drills, and simulations to prepare the Cyber Blue Team to respond to incidents.
- Use lessons learned from exercises and actual events to enhance plans, policies, and procedures.
- Conduct training for the Cyber Blue Team and response partners around incident response, incident management, and the Incident Command System.
- Participate in on-call rotation and occasional after-hours work.
**NOTE: The Primary Responsibilities of this role are not limited to the details above. **
Qualifications:
- Have at least five (5) years of previous experience in cybersecurity, preferably in security operations, investigations, or incident response.
Talents Needed for Success:
- Have previous experience leading in high-stress scenarios.
- Understand and have previous experience utilizing the Incident Command System.
- Demonstrate superior tactical leadership of teams to accomplish sophisticated technical tasks.
- Demonstrate the ability to produce high quality written products including detailed analysis and recommendations.
- Demonstrate high-quality public speaking and presentation skills.
- Demonstrate the ability to identify the appropriate audience and convey complex technical concepts to both technical and non-technical audiences at the appropriate level.
Bonus points if you have:
- Certifications such as ECIH or GCIH.
- Formal training in NIMS/ICS.
- Previous experience developing exercises with a methodology such as HSEEP.
The salary range is
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s