91±¬ÁÏ

    Pour rester inform¨¦ sur nos opportunit¨¦s :
    Rejoignez notre communaut¨¦ de Talents

    Cyber Security Incident Response Principal Analyst

    Mumbai, Maharashtra, India

    Cyber Security Incident Response Principal Analyst

    • 202500506
    • Mumbai, Maharashtra, India
    • Fermeture le: Feb 7 2025

    Description

    Role:

    The Cyber Security Incident Response Principal Analyst will play a key role in managing and responding to security incidents within 91±¬ÁÏ¡¯s Cyber Security Incident Response Team. Responsibilities of this role will include:

    • Serve as the primary lead for significant security incidents, coordinating response efforts across technical and business teams to minimize impact and ensure timely resolution.
    • Establish, refine, and maintain incident response processes, playbooks, and workflows to align with industry best practices and 91±¬ÁÏ¡¯s organizational needs.
    • Act as the central point of contact for incident response activities, ensuring effective communication with internal and external stakeholders, including senior leadership, Legal, HR, and Compliance teams.
    • Lead the in-depth technical investigation of security incidents escalated from the SOC, ensuring timely containment, eradication, and recovery while identifying root causes and potential impact
    • Work closely with SOC, Threat Hunting, CTI, Insider Threat, and Vulnerability Management teams to ensure seamless coordination and information sharing during incidents.
    • Lead root cause analysis and post-incident reviews to identify gaps, implement lessons learned, and enhance the overall incident response program.
    • Provide mentorship and guidance to junior analysts and conduct tabletop exercises to improve team preparedness.
    • Stay informed about emerging threats, attack trends, and evolving threat actor tactics, techniques, and procedures (TTPs) to ensure proactive Defense.
    • Ensure incident handling complies with relevant regulations and prepare detailed reports for regulatory or internal purposes.
    • Evaluate and prioritize incidents based on potential impact and severity, escalating issues to higher levels of management or other teams as required.
    • Assist in developing and fine-tuning automation scripts and workflows to enhance incident detection and response efficiency.
    • Contribute to the development and maintenance of key performance indicators (KPIs) and metrics to measure the effectiveness of incident response processes.
    • Act as a liaison between technical teams and business stakeholders, ensuring clear communication during incidents and status updates.

    Maintain up-to-date records of all incident handling activities in incident management systems, ensuring alignment with internal policies and audit requirements.

    Qualifications

    Requirement:

    We are looking for a candidate for?Cyber Security Incident Response who has the following:

    • Minimum 5 years of experience in incident response, with a strong understanding of cybersecurity principles, frameworks, and tools.
    • Proficient in forensic analysis, malware analysis, and network traffic analysis. Experience with SIEM tools, EDR platforms, and threat intelligence integration is essential.
    • Proven ability to lead high-stakes security incidents and coordinate cross-functional teams effectively.
    • Deep understanding of MITRE ATT&CK, cyber kill chain, and incident response methodologies.
    • Exceptional verbal and written communication skills, with the ability to convey complex technical concepts to non-technical audiences, including executives.
    • Industry certifications such as CISSP, GCIH, GCFA, or CISM are highly preferred.
    • Experience with platforms like Sentinel, Splunk, Carbon Black, or similar technologies.
    • A proactive and decisive mindset with the ability to operate under pressure.
    • Strong analytical and problem-solving skills to make informed decisions in complex situations.

    Collaborative and adaptable, with a passion for mentoring and developing team members

    Apply Now

    Pas toi?

    Merci

    Contact non sollicit¨¦

    Tous les profils de candidats / candidatures non sollicit¨¦s soumis via notre site Web ou des comptes de messagerie personnels d¡¯employ¨¦s de Willis Towers Watson sont consid¨¦r¨¦s comme la propri¨¦t¨¦ de Willis Towers Watson et ne sont pas soumis au paiement de frais d¡¯agence. Afin de devenir une agence de recrutement / un cabinet de recherche autoris¨¦ pour Willis Towers Watson, toute agence de ce type doit disposer d¡¯un contrat ¨¦crit en bonne et due forme, sign¨¦ par un recruteur autoris¨¦ Willis Towers Watson et entretenir une relation de travail active avec l¡¯organisation. Les curriculum vitae doivent ¨ºtre soumis conform¨¦ment ¨¤ notre processus de candidature, qui implique de participer activement ¨¤ la recherche. De m¨ºme, pour nos agences de recrutement / cabinets de recrutement autoris¨¦s, si le processus de candidature n¡¯est pas suivi, aucun frais d¡¯agence ne sera pay¨¦ par Willis Towers Watson. Si vous souhaitez que vos coordonn¨¦es soient sauvegard¨¦es en vue d¡¯un examen ult¨¦rieur, veuillez nous envoyer un courriel ¨¤ l¡¯adresse?Agency.inquiries@willistowerswatson.com .

    Nos bureaux

    Nos coll¨¨gues sont pr¨¦sents dans plus de 140 pays : de Mumbai ¨¤ Londres, en passant par Manille et New York, du Moyen-Orient ¨¤ l¡¯Am¨¦rique latine. Gr?ce ¨¤ notre pr¨¦sence internationale, tout ce que nous accomplissons prend une dimension mondiale et cr¨¦e des occasions de collaboration et de croissance pour vous. Parcourez la carte ci-dessous pour voir jusqu¡¯o¨´ votre carri¨¨re pourrait vous mener.

    Rencontrez nos collaborateurs