Overview
In this senior role, you lead incident response across international regions, shaping detection and response capabilities to protect enterprise data. You work within the Information Security group to triage, investigate, and contain security events, aligning with business needs in a fast-paced, collaborative environment. You’ll mentor IR teams, develop runbooks, and drive measurable improvements in security controls. This position offers a chance to influence CAA’s global security posture while working at the forefront of threat detection.
Responsibilities
- Act as the executive point of contact during major international security incidents
- Define and execute the global incident response strategy for international operations
- Lead and mentor incident response teams to foster high performance and collaboration
- Coordinate with technical and business stakeholders through the incident lifecycle
- Perform day-to-day incident response activities and SOC-related detection/response in a global context
- Monitor Threat Intelligence to guide threat hunting and identify anomalous activity
- Design, engineer, and implement runbooks and playbooks for incident response
- Develop containment strategies to limit incident impact
- Conduct host, cloud, network, memory, and log analysis to support investigations
- Contribute to security incident response efforts by identifying threats and mitigating controls
- Review security logs and reports to derive findings and logging improvements
- Develop end-to-end security monitoring and reporting; ensure controls are effective and aligned with objectives
- Evaluate emerging threats against existing controls and adapt defenses accordingly
- Create searches and detections for anomalous user, network, host, and cloud activity
- Build visualisations, dashboards, and reporting to contextualise security data
- Drive continual improvement of technical controls using IRM leadership input and metrics
- Other projects or duties as assigned
Key requirements
- 8+ years in IT with at least 5 years hands-on incident response, threat hunting, or forensics
- Bachelor’s or Master’s degree in a relevant field or equivalent experience
- Ability to mentor and train junior Security/IR Analysts
- Expertise in Cloud-based incident response and log analysis in a hybrid cloud environment
- Experience developing scripts, tools, and methodologies to enhance investigations
- Strong technical background across at least three areas (e.g., identity forensics, Windows/Linux forensics, network analysis, malware analysis)
- Solid understanding of servers, operating systems, networks, firewalls, and cloud apps/infrastructure
- Experience building workflows and playbooks for IR processes
- Proficiency with the NIST framework and continuous improvement loops
- Proven track record building/testing frameworks to validate security control effectiveness
- Mentoring and leadership
- Cross-functional collaboration
- Proactive problem solving
- Cloud-based incident response
- Log analysis (hybrid cloud)
- Threat hunting and threat intelligence
…
