Overview
In this role, you lead the Tier 2 Incident Response function within Operational Security to manage escalated cyber incidents. You will blend people leadership with hands-on technical direction, coordinating across security teams and stakeholders to strengthen resilience. You’ll drive improvements to detection, triage, and incident handling while guiding post-incident analysis and playbook development. This position offers cross-UK/Switzerland security impact and on-call escalation leadership for high-priority events.
Responsibilities
- Lead and develop Tier 2 Incident Response Analysts with clear standards and technical guidance
- Direct complex investigations across endpoints, identity, email, cloud and network environments from escalation to recovery
- Provide technical and operational leadership during major incidents for coordinated action
- Collaborate with Security Operations Centre to improve triage, escalation, and response
- Coordinate with Threat Intelligence, Detection Engineering, Vulnerability Management and Security Engineering to enhance visibility and response capability
- Lead post-incident reviews and root cause analysis to drive practical resilience improvements
- Develop and maintain incident response playbooks, procedures, and readiness exercises
- Influence UK and Switzerland Security Operations strategy and engage senior stakeholders across technology, risk, legal and privacy; provide senior on-call coverage
Key requirements
- Experience leading complex cyber security incident investigations within a Security Operations Centre, incident response or cyber defence environment
- Experience managing and developing technical security teams through coaching and leadership
- Practical experience investigating threats across endpoint, identity, email, cloud and network technologies
- Experience coordinating major incidents and communicating with senior decision-makers
- Experience improving incident response services via playbooks, post-incident reviews, RCA, exercises or process development
- Experience in large, complex or regulated organisations with evidence-based decision making; familiarity with Microsoft Sentinel, Defender, Purview, digital forensics and incident response tools, SOAR, threat hunting or detection engineering is advantageous
- Certifications such as GCIH, GCFA, CISSP or equivalent are desirable
- Clear communication with technical and non-technical stakeholders
- Leadership and coaching abilities
- Decision-making under pressure
- Microsoft Sentinel
- Microsoft Defender technologies
- Microsoft Purview
…
