Cyber Incident Handling
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Expertise to analyse, manage and investigate cyber incidents. Handle and respond to cyber security incidents to ensure comprehensive and cohesive world class response: first triage activities, analyse incidents and determine their impacts, notification and escalation of incidents according to their impacts, participate in the containment, eradication, and recovery of major incidents, document and keep track of every activity related with the incident response process. Develop a post-mortem analysis of systems and networks.
Manage complex cyber security incidents globally across the group. Become part of a world-class capability that will own, respond and coordinate significant incidents ensuring successful resolution and adopting lessons-learnt to increase cyber resilience. Orchestrate the necessary human and technical resources for the resolution of high-impact cyber incidents. Design and supervise an organised approach to address and manage the aftermath of a security breach or cyberattack in order to limit damage on internal systems, data, and networks and reduce recovery time and costs. Drive continuous improvement in Santander´s cyber response capability through your involvement in the cyber readiness programme across the Global Cyber Respond Team. Review and coordinate projects related to the development and improvement of Incident Response plans, policies, and procedures ensuring a consistent, professional and disciplined approach.
Participate in the cyber exercises programme to develop capabilities globally: design and execute focused development plans for entities and internal teams, addressing gaps in capability through innovative training solutions and cyber exercises, such as live simulation/tabletop to test processes including critical business and technical playbooks. Technical simulations such as Cyber Ranges skills labs on the use of cyber incident orchestration tools and threat intelligence platforms. Preparation and final QA of incident reports and minutes oriented to senior management audience. Contribute to the establishment of a strong and collaborative Global Community between Cyber Threat Units.
Collaborate with key stakeholders within the bank, such as Global Forensics, Global Security Operations Centre, Corporate Security & Intelligence, Global Cyber Fraud, and the Secure User Experience team, among others. Be available to participate in the incident response procedure on a 24x7 basis, 8-hour shifts, and on-call scheme.
Requirements
1+ years of experience in cyber security with a broad understanding of information security and previous experience as part of a CIRT, CSIRT or similar response team., Degree such as computer science, engineering or similar., * Knowledge of Incident Response and Handling methodologies - Experienced level.
- Knowledge of cyber incident categories, incident response, and timelines.
- Knowledge of cyber defence and information security procedures and regulations.
- Knowledge of cyber attack stages (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks).
- Knowledge of risk management processes (e.g., methods for assessing and mitigating risk).
- High level of English.
Desired Certifications
- CISSP
- CISA
- CISM
- CEH
- OSCP
- GCIH, Experience in the financial/banking industry.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.jobleads.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Spanish Business Culture and Etiquette
Data Analyst Salary in the UK
Top 6 Hackathons for Developers in 2023
Average Salary in Spain