Cyber Incident Response Team Lead (CSIRT)
Role details
Job location
Tech stack
Job description
Blends hands-on incident command and digital forensics with programmatic capability building. Establishes the CSIRT operating model, creates scenario playbooks (ransomware, exfiltration) from scratch, and leads technical containment/recovery during active security events., My client is a well established business, looking for a hands-on CSIRT Lead to establish and run the cyber incident response capability across a complex, multi-site industrial and corporate estate. The role blends hands-on incident command and digital forensics coordination with the programmatic build-out of incident playbooks and operational runbooks from scratch., * Lead end-to-end response during active security events, coordinating technical triage, containment, forensic investigation, and recovery.
- Build out the internal CSIRT operating model, defining runbooks for high-impact scenarios (e.g., ransomware, supply chain compromise, data exfiltration).
- Coordinate crisis response communications across internal business functions, legal counsel, PR, and external regulatory bodies.
- Conduct thorough post-incident reviews (PIRs) to extract root cause lessons and drive continuous security control improvements.
Requirements
- Proven background in incident command, digital forensics, or high-pressure incident triage.
- Experience building or maturing incident response frameworks and runbooks.
- Incident response designations such as GCIH, GCFA, GNFA, or CREST qualifications are highly desirable.