Description
We are Starling, a financial services company that offers banking and software solutions through its various businesses. We are looking for an experienced SOC Team Lead with Incident Response experience to join our growing cyber security function.
As a member of the Starling Group’s SOC team, you will be working with the industry's brightest SecOps professionals to protect Starling Group’s customers, assets, and systems using the latest technologies.
Responsibilities:
- Lead a team of subject matter experts and analysts to ensure Information Security is managed and continuously improved in line with Bank policy and procedure.
- Support the development and progression of the Information Security Analyst team from both a technical and professional perspective.
- Conduct incident triage, response, and investigations based on alerts received from multiple sources.
- Interpret logs from a variety of sources to identify root cause and determine next steps for containment, eradication, and recovery.
- Work with other teams to analyse, contain, eradicate, and recover from cyber security incidents.
- Continuously develop and maintain incident handling, response, and readiness processes.
- Support the wider SecOps team with detection engineering and threat hunting.
- Document incidents and investigations, including analysis findings and containment steps.
- Plan and participate in Tabletop Exercises.
- Present investigation findings to technical and non-technical audiences.
Requirements:
- 5+ years experience in an in-house SOC role and team, including cyber incident response and digital forensics function.
- Experience in a similar role leading, developing, and motivating a team of subject matter experts and other managers in Information and Cyber Security.
- Understanding of AWS Security Solutions (or other Public Cloud Solutions).
- Analysis and Incident Response experience with Cloud systems (GCP, AWS).
- Experience working and supporting analytics/SIEM platforms.
- Experience supporting and conducting Incident Response engagements.
- Experience in endpoint-based investigations.
- Experience in cloud-based investigations.
- Experience with Incident Command and conducting Tabletop Exercises.
- Excellent communication skills and ability to communicate technical concepts to both technical and non-technical audiences.
Preferred:
- Experience in forensics: cloud (GCP, AWS); endpoint/server (Windows, MacOS, Linux); and/or network.
- Any experience of programming in Python, Go, and/or Java.
- A Cyber/Information Security-related degree and/or relevant cyber security qualification(s).
Benefits:
- 25 days holiday
- Birthday on us
- Option to opt-out of public holidays
- Option to buy/sell up to 5 days of annual leave a year
- 16 hours paid volunteering time a year
- Enhanced Pat & Mat leave
- Perkbox
- Length of service increased annual leave
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting:
https://apply.workable.com/j/C8DD3020FA