Full-Time Cyber Incident Response Lead

Experian is hiring a remote Full-Time Cyber Incident Response Lead. The career level for this job opening is Experienced and is accepting Ruddington, United Kingdom based applicants remotely. Read complete job description before applying.

This job was posted 5 months ago and is likely no longer active. We encourage you to explore more recent opportunities on our site. However, you may still try your luck using 'Apply Now' link below. We recommend focusing on newer listings available here.

Experian

Job Title

Cyber Incident Response Lead

Posted

Career Level

Full-Time

Career Level

Experienced

Locations Accepted

Ruddington, United Kingdom

Job Details

As a member of Experian's Global Security Office (EGSO) / Cyber Fusion Center (CFC), you will respond, contain, escalate, investigate, and coordinate mitigation of security events related to anomalies detected and escalated by the Cyber Fusion Center (CFC) according to Experian's Incident Response Plan.

This team member will join a growing team of specialized incident responders to support escalations of complex or prioritized matters from Experian's existing 24x7 security monitoring and response functions.

You will respond to and analyze security incidents involving threats targeting Experian information assets, including phishing, malware, network attacks, and suspicious activity. You will involve working with end-users, partners, technical support teams, and management to ensure remediation and recovery from these threats.

Use analytics & data collected from endpoints, environmental logging, and various sources to maximize containment and eradication of threats, while expediting business recovery.

Note: You will have a regular Monday-Friday schedule with expectations to participate in an on-call schedule or work outside of normal hours to manage cybersecurity incidents. You will report to the CFC Senior Director of Incident Management and Security Operations.

Main Responsibilities:

  1. Conduct advanced incident response activities to investigate and contain complex, large-scale cybersecurity matters (potential major severity incidents).
  2. In investigative matters requiring support, work with teams like Forensics and Cyber Threat Hunt, and express the CFC's overall understanding of attacker activity timelines to coordinate containment and remediation.
  3. Respond to security events and alerts associated with threats, intrusions, and compromises according to Service Level Objectives (SLOs).
  4. Manage multiple security incident cases throughout the incident response lifecycle (Analysis, Containment, Eradication, Recovery, and Lessons Learned).
  5. Maintain case documentation, including notes, analysis findings, containment steps, and cause for each assigned incident.
  6. Maintain understanding of common Operating Systems (Windows, Linux, Mac OS), Security Technologies (Anti-Virus, Intrusion Prevention), and Networking (Firewalls, Proxies).
  7. Interpret device and application logs from various sources (Firewalls, Proxies, Web Servers, System Logs, Splunk, Packet Captures) to identify causes and determine next steps for containment, eradication, and recovery.
  8. Provide advanced support to analysts (logs review, IP block questions) and mentor other analysts (process questions, tool usage).

Technical Skills:

  • Knowledge of network protocols (TCP/IP, UDP, ICMP), standard protocols (HTTP/S, DNS, SSH, SMTP, SMB), wireless networking, network infrastructure, and topologies (DMZ, VPN, WAN).
  • Understanding of network technologies (WAF, IPS, Routers, Firewalls).
  • Experience with commercial & open-source SIEMs, full packet capture tools, and network analysis tools (Splunk, Wireshark, SOF-ELK).
  • Knowledge of common intrusion methods and cyber-attack tactics, techniques, and procedures (TTPs).
  • Experience with common Incident Response and Security Monitoring applications (SIEM, EDR, WAF, IPS).

FAQs

What is the last date for applying to the job?

The deadline to apply for Full-Time Cyber Incident Response Lead at Experian is 17th of July 2025 . We consider jobs older than one month to have expired.

Which countries are accepted for this remote job?

This job accepts [ Ruddington, United Kingdom ] applicants. .

Related Jobs You May Like

Cortex Cloud Sales Specialist - Public Sector

Paris, France
1 day ago
Channel Partnerships
Cloud Solutions
Customer Relationship Management
Palo Alto Networks
Full-Time
Experienced

Senior Product Manager (Security Domain)

São Paulo, Brazil
1 day ago
Agile Methodologies
Product Management
Security Management
Sigma Software
Full-Time
Experienced

Senior Director, Technical Services (NAM)

Plano, TX
1 day ago
Customer Success
Cybersecurity
Stakeholder Management
Palo Alto Networks
Full-Time
Senior Manager
YEAR $270000 - $315000

Sr. Ethics & Compliance Manager- Global Public Sector

Ottawa, Canada
1 day ago
Canadian Contract Security
Government Contract Compliance
Policy Development
ServiceNow
Full-Time
Manager

Solutions Engineer, Identity

Santa Clara, CALIFORNIA
1 day ago
IAM
IGA
REST APIs
Cyberark
Full-Time
Experienced
YEAR $107000 - $158000

Principal Product Manager - Security Center

Santa Clara, CALIFORNIA
1 day ago
AI Integration
Cloud Security
Product Management
ServiceNow
Full-Time
Manager

Senior Safety & Security Officer

Austin, TX
1 day ago
FRA System Safety For Passenger Rail
FTA System Safety And Security Certification (SSC)
PTASP Development
AECOM
Full-Time
Experienced

Sr. Manager, Global Certifications (Federal)

Santa Clara, CA
1 day ago
Cloud Security
DoD SRG
FedRAMP
Palo Alto Networks
Full-Time
Senior Manager
YEAR $180000 - $220000

IAM Engineering Specialist

São Paulo, Brazil
1 day ago
Access Control
Identity Governance And Administration (IGA)
One Identity
Experian
Full-Time
Experienced

Accreditation Specialist Lead (Remote)

United States
1 day ago
HIPAA
ISO 27001
PCI
Experian
Full-Time
Experienced

Embedded Senior Analyst, Threats and Intelligence

Remote
1 day ago
Data Analysis
OSINT
Security Investigations
Sibylline Ltd
Full-Time
Experienced
YEAR $125000 - $125000

Embedded Intelligence Analyst

Remote
1 day ago
Intelligence Analysis
Risk Assessment
Security Investigations
Sibylline Ltd
Full-Time
Experienced
YEAR $76858 - $76858

Looking for a specific job?