Leave us your email address and we'll send you all the new jobs according to your preferences.
Consulting X-Force Incident Response Consultant Professional Warwick, GB
Posted 8 hours 11 minutes ago by International Business Machines Corporation
Information and Data are some of the most important organizational assets intoday's businesses. As an IR Consultant, you will be a key advisor for IBM's clients,delivering proactive services and responding to major incidents for organizations.
You will be part of a high-performing team and will apply your technical skills to improve clients' security posture through a combination of proactive and reactive cybersecurity incident response services.
Your role and responsibilities
As an IR Consultant for the IBM Security X-Force Incident Response (X-Force IR) team, you will be responding to high profile cybersecurity incidents within our clients' enterprise networks. You will work with our clients to proactively prevent and detect future cybersecurity incidents. You will serve as a trusted advisor to our clients, helping to shape their cybersecurity program. You will collaborate with internal IBM stakeholders to provide integrated solutions to our clients' most challenging problems.
In this role you will have demonstrated skills in various elements of Incident Response, conducting computer intrusion investigations, and have a strong foundation in cyber security policy, operations and best practices; ideally in large enterprise environments. Ideally, you will have proficiency with EDR tools such as Cortex, CrowdStrike and Defender as well as familiarity with forensic analysis tools such as X-Ways, EnCase Forensic or FTK and live response analysis. Furthermore, familiarity with Windows and Linux enterprise environments and systems such as Active Directory, Office 365, FWs, IPS/IDS, SIEMs, etc. is required. Excellent written and verbal communication skills are required. When not responding to breaches, you will conduct enterprise threat hunting, help clients develop incident response plans, facilitate tabletop and purple team exercises as well as provide other tactical security services related to incident response. As part of this role you may be required to travel, either within the country or internationally.
Required education
None
Preferred education
None
Required technical and professional expertise
• Hands-on experience with hardware/software tools used in incident response,computer forensics, network security assessments, and/or application security.
• Understanding of enterprise-wide policies and procedures for IT risk mitigationand incident response.
• Experience within incident response teams and handling tasks across all phases ofan engagement.
• Capable of working independently as well as a part of a larger team within internal projects and client engagements.
Forensic Analysis & Incident Response Skills:
• Ability to forensically analyse Windows for evidence of compromise. Knowledge of Unix systems forensics will be considered an advantage.
• Familiarity with industry standard forensic tools such as EnCase, FTK, X-Ways,Sleuthkit.
• Experience performing log analysis locally and via SIEM/log aggregation tool.
• Experience hunting threat actors in enterprise networks and cloud environments.
• Experience with using Endpoint Detection & Response (EDR) tools.
• Demonstrate an understanding of the behaviour, security risks and controls ofcommon network protocols.
• Demonstrate an understanding of common applications used in Windows andLinux enterprise environment. Familiarity with Active Directory, Exchange andMicrosoft 365 applications and logs.
• Familiarity with the tools and techniques required to analyze data traversing anetwork environment.
• Familiarity with cloud computing platforms like IBM Cloud, AWS, GCP or Azure.
• Experience in writing cohesive reports for a technical and non-technical audience.
Assessment Expertise:
• Examine and analyse available client internal processes, and procedures to determine patterns and gaps at a tactical level. Recommend appropriate course of action to support maturing the client's incident response program and cyber security posture.
• Familiarity with various security frameworks and standards such as ISO 27001/2,PCI DSS, NIST800-53, 800-171, and applicable data privacy laws and regulations.
• Experience with Incident Response tabletop exercises, with a focus on eithertactical or strategic incident response processes.
Preferred technical and professional experience
• Diverse understanding of cyber security related vulnerabilities, common attackvectors, and mitigations.
• Understanding of strategic level incident response plans as well as tactical-focused playbooks.
• Ability to complete individual tasks and coordinate with other work streams during incident response investigations.
ABOUT BUSINESS UNITIBM Consulting is IBM's consulting and global professional services business, with market leading capabilities in business and technology transformation. With deep expertise in many industries, we offer strategy, experience, technology, and operations services to many of the most innovative and valuable companies in the world. Our people are focused on accelerating our clients' businesses through the power of collaboration. We believe in the power of technology responsibly used to help people, partners and the planet.
YOURIn a world where technology never stands still, we understand that, dedication to our clients success, innovation that matters, and trust and personal responsibility in all our relationships, lives in what we do as IBMers as we strive to be the catalyst that makes the world work better.
Being an IBMer means you'll be able to learn and develop yourself and your career, you'll be encouraged to be courageous and experiment everyday, all whilst having continuous trust and support in an environment where everyone can thrive whatever their personal or professional background.
Our IBMers are growth minded, always staying curious, open to feedback and learning new information and skills to constantly transform themselves and our company. They are trusted to provide on-going feedback to help other IBMers grow, as well as collaborate with colleagues keeping in mind a team focused approach to include different perspectives to drive exceptional outcomes for our customers. The courage our IBMers have to make critical decisions everyday is essential to IBM becoming the catalyst for progress, always embracing challenges with resources they have to hand, a can-do attitude and always striving for an outcome focused approach within everything that they do.
Are you ready to be an IBMer?
ABOUT IBMIBM's greatest invention is the IBMer. We believe that through the application of intelligence, reason and science, we can improve business, society and the human condition, bringing the power of an open hybrid cloud and AI strategy to life for our clients and partners around the world.
Restlessly reinventing since 1911, we are not only one of the largest corporate organizations in the world, we're also one of the biggest technology and consulting employers, with many of the Fortune 50 companies relying on the IBM Cloud to run their business.
At IBM, we pride ourselves on being an early adopter of artificial intelligence, quantum computing and blockchain. Now it's time for you to join us on our journey to being a responsible technology innovator and a force for good in the world.
IBM is proud to be an equal-opportunity employer. All qualifiedapplicants will receive consideration for employment without regard to race,color, religion, sex, gender, gender identity or expression, sexualorientation, national origin, caste, genetics, pregnancy, disability,neurodivergence, age, veteran status, or other characteristics. IBM is alsocommitted to compliance with all fair employment practices regardingcitizenship and immigration status.
OTHER RELEVANT JOB DETAILSIBM wants you to bring your whole self to work and for you this might mean the ability to work flexibly. If you are interested in a flexible working pattern, please talk to our recruitment team to find out if this is possible in the current working environment.
Job Title
Cybersecurity Incident Response Consultant
Job ID
51430
City / Township / Village
Warwick
State / Province
Warwickshire
Country
United Kingdom
Work arrangement
Remote
Area of work
Consulting
Employment type
Regular
Position type
Professional
Up to 40% or 2 days a week (home on weekends- based on project requirements)
Company
(8660) IBM United Kingdom Limited
Shift
General (daytime)
Is this role a commissionable/sales incentive based position?
International Business Machines Corporation
Related Jobs
Vietnamese freelance Interpreter & Translator
- London, United Kingdom
Hungarian Interpreter
- £15 Hourly
- Devon, Exeter, United Kingdom, EX1 1
Russian Interpreter
- Hertfordshire, Much Hadham, United Kingdom, SG106
Senior Structural Engineer
- £65,000 Annual
- Surrey, Weybridge, United Kingdom, KT130
Nuclear Safety Case Engineer
- £65,000 Annual
- Somerset, Bristol, United Kingdom, BS483