Cyber Security Incident Response Team Lead

4 days ago


Canada CyberClan Full time

CyberClan Overview

CyberClan is a leading cybersecurity company established in 2006, with a team of expert professionals skilled in solving complex cyber security challenges. Our goal is to provide top-notch incident response services and ensure business continuity for our clients.

Job Summary

We are seeking an experienced Cyber Security Incident Response Team Lead to join our team. As a key member of our DFIR department, you will be responsible for leading our incident response efforts, developing IR initiatives, and managing the team's performance. You will work closely with our clients, sales, and marketing teams to ensure a swift and effective response to security breaches.

Responsibilities

  • Lead security incidents in a cross-functional environment, targeting incident resolution
  • Develop IR initiatives to improve our capabilities to respond and remediate security events
  • IDentify, develop, and articulate missions of highest importance for your teams
  • Report on security incident performance and risk indicator metrics
  • IDentify and track key performance metrics for the team; utilize metrics to find new ways to improve sustainability for your team and improve security incident response and remediation closure rates
  • Lead and foster innovation within the Security Incident Response team, driving key decisions and focus on client outcomes
  • Create a culture of accountability, quality, agility, and high performance that will foster the attraction, development, and retention of security analysts
  • Mentor and coach team members to continue to scale in our high-growth environment
  • Responsible for being a focal incident response point for all within the organization (Incident Response/Post Breach Remediation/RMS Advisory/MSSP Advisory)
  • Oversee Incident Response Plans: Design, implement, and manage the client's incident response policies and procedures to ensure preparedness
  • Coordinate Incident Response Teams: Lead cross-functional teams during security incidents, ensuring an organised and timely response
  • Triage and Prioritise Incidents: Assess incidents for severity and potential impact, assigning appropriate resources and setting response priorities
  • Communication: Serve as technical point of contact during an incident, providing updates to internal and external stakeholders
  • Serve as an incident manager, reporting key findings, barriers, escalations, and concerns to the Head of DFIR, while liaising with Legal, Director of Sales, and IRC team
  • Support the Global Head of DFIR with Project-based work that advances the output and productivity of the department and organisation
  • Maintain and prepare departmental reports for Key Performance Indicators (KPIs) to be presented to the Global Head of DFIR and EVP Sales & Revenue as needed
  • Provide leadership and support to the CERT team, acting as a backup for the Global Head of DFIR during vacations or time-off
  • Responsible for supporting a wide number of technologies and being able to proficiently perform advanced troubleshooting on the fly (packet captures, debugs, traffic analysis)
  • Work on the continued development of DFIR/CERT and Machine investigation lifecycles as part of the ongoing process to enhance IR capabilities; also provided significant contribution to the revision of Incident Response and Post Breach Remediation policies, procedures, and process
  • Responsible for developing and documenting Incident Response methods and guidelines for the organisations
  • Develop a detailed Incident Response run book of tools, techniques, and forensic methods for personnel to utilise during investigations
  • Support in the departments DFIR tooling selection process and any proof of concept projects
  • Chain of Custody: Ensure that evidence is collected, handled, and preserved in a legally defensible manner, maintaining the chain of custody for potential litigation
  • Perform live-endpoint investigation, including the identification and gathering of key forensic artifacts, offline investigation as needed, and providing remediation actions as needed
  • Implements and deploys an Incident Response focused ticketing system to improve incident tracking, remediation, and metrics for incidents worked
  • Post-incident Analysis: Conduct root cause analysis after incidents to identify vulnerabilities and develop strategies to prevent recurrence
  • Recovery Support: Work closely with IT and cybersecurity teams to guide recovery efforts, including system restoration and remediation
  • Responsible for working with 3rd parties in order to assist with incident response, business email compromise, security breach, improve overall security, investigations, recommendations, and remediation
  • Responsible for reporting of security metrics related to the Incident Response team
  • Provides mentoring to team members of incident response techniques and methodologies
  • Assists Sales and SOC in the successful conversion from incident response, PBR, RMS, eDiscovery to SOC; including process and procedure build-out
  • Developing and providing high-level technical reports in response to clients
  • Developing and providing high-level business unit specific KPIs to senior management
  • Developing and providing metrics surrounding the departments utilisation, engagement timelines, profitability, and billing
  • Supporting Incident Response Coordinator (IRC) workflows
  • Incident Response Metrics and Reporting: Track and report key performance indicators (KPIs) and metrics related to incident response and digital forensics to senior leadership
  • Budget and Resource Management: Oversee the allocation of resources, including personnel, tools, and budgets, to effectively manage incident response and forensics operations
  • Understand the process for time tracking and auditing to ensure Budget and Resource Management: Oversee the allocation of resources, including personnel, tools, and budgets, to effectively manage incident response and forensics operations
  • Monitor and Manage Regional profit & loss metrics and requirements
  • Create and maintain and enhanced onboarding program that is concise and repeatable, effectively covering all aspects of the CERT role
  • Serve as a member of a 24x7/365 service delivery team that handles incident response, post breach remediation, escalation, required to perform complex investigations and/or troubleshooting and driving root cause to resolution
  • Incident Response Training: Organise and lead training sessions and simulations (e.g., tabletop exercises) for CERT staff to improve readiness and response capabilities
  • Client Education: Raise awareness across external organisations about digital forensics, incident response protocols, and security best practices
  • All activities and responsibilities will be required to provide support to the Global CERT team and are not limited to one region
  • Maintain and manage AWS instances to ensure timely deletion and removal of data to minimise company and customer fees/overages

Requirements/Must Haves

  • Minimum 3 years of Management/Leadership experience
  • Minimum 3 years of client-facing experience in technical situations
  • Minimum 6 years of experience in Incident Response
  • Bachelor's degree or matched work experience
  • 5+ years of information security experience as well as leading teams with a deep passion for cybersecurity and incident response
  • Experience in the Cyber Insurance and Legal markets
  • Successful track record of helping to implement security initiatives and frameworks in a flexible and innovative manner
  • Ability to understand technical issues teams face day-to-day and act as a player/coach for blocker removal
  • A collaborative approach to decision-making and the ability to influence with minimal guidance
  • Experience in conducting Tabletop Exercises in Incident Response
  • Experience in the deployment and management of EDR Technology
  • Experience with Security Technologies and NIST Framework
  • Developing, documenting, and implementing incident response methods, process
  • Perform live endpoint investigations
  • Experience in forensic investigations both on-premise and cloud
  • Experience in mentoring, developing, and delivering in-house training
  • Must be available to provide coverage to meet business requirements in 3 regions
  • Strong knowledge of DFIR Tools
  • Strong knowledge of Virtualization Technologies, Operating Systems, Firewalls, VPN's, SIEM, Enterprise Gateway Technologies, Networking Devices, Security Technologies, etc.

Estimated Salary

$120,000 - $180,000 per year, depending on location and experience.



  • Canada CyberClan Full time

    Job Title: Cyber Security Incident Response Lead About UsCyberClan is a leading cybersecurity firm that has been providing expert incident response services to organizations since 2006. Our team of experts is dedicated to helping businesses protect their data and systems from cyber threats. Estimated Salary Range: $120,000 - $180,000 per year (dependent on...


  • Canada CyberClan Full time

    Job Summary: We are seeking a highly skilled Cyber Security Incident Response Manager to join our team at CyberClan. The successful candidate will be responsible for leading our incident response efforts, ensuring swift and effective resolution of security breaches, and maintaining the highest standards of security best practices.About Us: Established in...


  • Canada CyberClan Full time

    CyberClan is a team of cyber security experts dedicated to solving complex challenges and keeping data secure. Our 24/7/365 Incident Response Teams respond to cyber-attacks using proven defensive methodologies.Key Responsibilities:Investigate and assist clients with various types of security breaches, insider threats, unauthorized access, and malicious...


  • Canada CyberClan Full time

    Job OverviewCyberClan, a leading cybersecurity firm, is seeking an experienced Cyber Security Operations Lead to join our team. In this role, you will play a critical part in protecting our clients' digital assets and ensuring a swift and effective response to security breaches.About the RoleWe are looking for a skilled professional with a strong background...


  • Canada CyberClan Full time

    Job OverviewCyberClan is a leading cybersecurity services provider, established in 2006. We specialize in solving complex security challenges and providing expert incident response solutions.


  • Canada CyberClan Full time

    About CyberClanCyberClan is a leading cybersecurity company established in 2006. Our team of experts specializes in solving complex security challenges, ensuring data protection and business continuity. We offer 24/7 global incident response services to combat cyber threats.


  • Canada CyberClan Full time

    CyberClan OverviewWe are CyberClan, a leading cybersecurity firm established in 2006. Our expert team is dedicated to resolving complex security challenges and protecting our clients' data. With a 24/7 global incident response team, we provide immediate action against cyber threats.Role SummaryThis role is responsible for leading our incident response...


  • Canada CyberClan Full time

    Job SummaryCyberClan seeks a seasoned Digital Forensics and Incident Response (DFIR) Manager to lead our global incident response efforts. As a key member of our team, you will be responsible for developing and implementing comprehensive incident response plans, managing security incidents, and providing technical expertise to our clients.About...


  • Canada CyberClan Full time

    At CyberClan, we're seeking a highly skilled Cyber Security Operations Lead to join our team. This role is perfect for individuals who thrive in fast-paced environments and are passionate about delivering exceptional results.Job Overview:We're an equal opportunities employer committed to fostering a diverse and inclusive culture. Our mission is to provide...


  • Canada CyberClan Full time

    Job Title: Cybersecurity Incident Response ManagerAbout Us:CyberClan is a leading cybersecurity company that provides expert services to the insurance, legal, and commercial sectors. Our team of experts is dedicated to solving complex cyber security challenges and keeping businesses safe.Job Description:The Incident Response Coordinator plays a crucial role...


  • Canada CyberClan Full time

    Job DescriptionWe are seeking a highly skilled Digital Forensics Team Lead to join our team at CyberClan. As a key member of our organization, you will be responsible for leading our digital forensics efforts and ensuring the swift and effective response to security breaches.About CyberClanCyberClan is a leading provider of cyber security solutions,...


  • Canada CyberClan Full time

    We are seeking a highly skilled Digital Forensics and Incident Response Leader to join our team at CyberClan. As a key member of our Cyber Security Operations team, you will play a crucial role in protecting our clients' digital assets and ensuring a swift and effective response to security breaches.The successful candidate will have extensive experience in...


  • Canada AGS Cyber Full time

    AGS Cyber, a global consultancy, is seeking a seasoned Senior Application Security Specialist to support their Canadian team. This highly sought-after role comes with an estimated salary of $120,000-$180,000 per annum.Job Description:This pivotal position involves leading penetration testing engagements focused on Web Application Pentesting and Source Code...


  • Canada CyberClan Full time

    About CyberClanCyberClan is a cybersecurity company that provides incident response services to the insurance, legal, and commercial markets. Our team of experts is dedicated to helping businesses respond to and recover from cyber attacks.


  • Canada CyberClan Full time

    At CyberClan, we are dedicated to protecting our clients' digital assets from cyber threats. As a key member of our team, you will play a crucial role in leading our Digital Forensics and Incident Response efforts.Job Summary:We are seeking an experienced Digital Forensics and Incident Response Leader to join our team. In this role, you will be responsible...


  • Canada National Consultants Professionals Ltd Full time

    **Job Summary:**We are seeking a highly skilled Cyber Security Specialist to join our team at National Consultants Professionals Ltd. As a Senior CyberSecurity Engineer, you will be responsible for managing and maintaining information security systems, performing hands-on configuration, deployment, and troubleshooting of cyber security technologies, and...


  • Canada National Consultants Professionals Ltd Full time

    Cyber Security Specialist - Enterprise ProtectionWe are seeking a highly skilled Cyber Security Specialist to join our team at National Consultants Professionals Ltd. As a key member of our security team, you will play a crucial role in protecting our enterprise systems from cyber threats.Job Description:The ideal candidate will have a strong background in...


  • Canada AGS Cyber Full time

    AGS Cyber is a US-based global consultancy with a strong presence in Canada. We are seeking an experienced Principal Penetration Tester to join our Canadian team.Job SummaryWe are looking for a highly skilled cybersecurity expert to lead penetration testing engagements focused on web application security and source code review. The successful candidate will...


  • Canada National Consultants Professionals Ltd Full time

    Cyber Security Engineer WantedWe are seeking a highly skilled Cyber Security Engineer to join our team at National Consultants Professionals Ltd.About the JobThis is a 3-month contract with possible extension. The ideal candidate will have demonstrated expertise through certifications such as CISSP, OSCP, CCSP, SANS GIAC, CCSA, or CCSE.Direct experience with...

  • IT Security Specialist

    23 hours ago


    Canada LeverageTek Staffing Solutions Full time

    We are seeking a highly skilled IT Security Specialist - Cyber Compliance to join our team at LeverageTek Staffing Solutions in Ottawa, Canada.Estimated Salary: $90,000 - $110,000 per yearJob Description:The successful candidate will be responsible for ensuring the organization's information systems are protected through technical control reviews and...