Cyber Defence Expert - Incident Management & Response
Teknik, data och digitalt · IT-infrastruktur och säkerhet · Cybersäkerhet · DevOps
I korthet
Electrolux Group is seeking a highly experienced Cyber Defence Expert to lead incident management and response operations for their Security Operations Center. This role will drive the operational maturity, effectiveness, and resilience of cyber defense across a global environment, focusing on detection, triage, containment, and recovery from cyber threats.
Ansvarsområden
- Lead end-to-end cyber incident response activities.
- Act as incident commander for high-severity cyber incidents.
- Design, maintain, and improve incident response frameworks and playbooks.
- Coordinate technical investigations across various teams.
- Drive post-incident reviews and root cause analysis.
- Lead and mature SOC operations, including alert triage and investigation standards.
- Define and track SOC metrics, SLAs, and KPIs.
- Provide operational governance for managed SOC providers.
- Improve detection-to-response processes using SIEM, SOAR, EDR, NDR, XDR, etc.
- Support analyst enablement through guidance and knowledge sharing.
- Own and mature detection engineering capabilities.
- Translate threat intelligence into actionable detection use cases.
- Lead the detection lifecycle, including use case design and tuning.
- Drive SOC automation through SOAR playbooks and automated workflows.
- Identify telemetry and logging gaps and prioritize onboarding.
- Partner with various teams to improve detection coverage and response speed.
- Lead cyber crisis coordination during major incidents.
- Prepare and deliver incident briefings and executive summaries.
- Partner with legal, privacy, communications, and other teams during incidents.
- Plan and support cyber incident exercises and tabletop simulations.
- Ensure incident response activities align with governance and policies.
Krav
- Minimum 8 years of experience in security operations, cyber defence, incident response, or related cybersecurity roles.
- Strong hands-on experience leading or coordinating high-severity cyber incidents in complex enterprise environments.
- Deep understanding of SOC operations, alert triage, escalation management, incident handling, threat detection and response workflows.
- Experience with SIEM, SOAR, EDR, NDR, XDR, identity security, cloud security monitoring, and managed security service providers.
- Strong understanding of incident response frameworks and methodologies such as NIST, ISO 27035, SANS/PICERL, and MITRE ATT&CK.
- Ability to communicate clearly during incidents, including concise executive updates, technical coordination, and post-incident reporting.
- Proven ability to drive continuous improvement across people, process, tooling, governance, and operational performance.
- Relevant bachelor’s or master’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or equivalent practical experience.
Önskade kvalifikationer
- Relevant certifications are considered an advantage, such as CISSP, GCIH, GCIA, GCFA, GSEC, OSCP, CEH, Microsoft Security certifications, or cloud security certifications.
Förmåner
- Continuous investment in employee development.
- No barriers to where your career could take you.
#cyber defense#incident management#incident response#security operations#SOC#SIEM#SOAR#EDR#NDR#XDR#threat intelligence#automation#NIST#MITRE ATT&CK