91±¬ÁÏ

    Pour rester inform¨¦ sur nos opportunit¨¦s :
    Rejoignez notre communaut¨¦ de Talents

    Cyber Security Incident Response Principal Analyst

    Mumbai, Maharashtra, India

    Cyber Security Incident Response Principal Analyst

    • 202500506
    • Mumbai, Maharashtra, India
    • Fermeture le: Feb 7 2025

    Description

    Role:

    The Cyber Security Incident Response Principal Analyst will play a key role in managing and responding to security incidents within 91±¬ÁÏ¡¯s Cyber Security Incident Response Team. Responsibilities of this role will include:

    • Serve as the primary lead for significant security incidents, coordinating response efforts across technical and business teams to minimize impact and ensure timely resolution.
    • Establish, refine, and maintain incident response processes, playbooks, and workflows to align with industry best practices and 91±¬ÁÏ¡¯s organizational needs.
    • Act as the central point of contact for incident response activities, ensuring effective communication with internal and external stakeholders, including senior leadership, Legal, HR, and Compliance teams.
    • Lead the in-depth technical investigation of security incidents escalated from the SOC, ensuring timely containment, eradication, and recovery while identifying root causes and potential impact
    • Work closely with SOC, Threat Hunting, CTI, Insider Threat, and Vulnerability Management teams to ensure seamless coordination and information sharing during incidents.
    • Lead root cause analysis and post-incident reviews to identify gaps, implement lessons learned, and enhance the overall incident response program.
    • Provide mentorship and guidance to junior analysts and conduct tabletop exercises to improve team preparedness.
    • Stay informed about emerging threats, attack trends, and evolving threat actor tactics, techniques, and procedures (TTPs) to ensure proactive Defense.
    • Ensure incident handling complies with relevant regulations and prepare detailed reports for regulatory or internal purposes.
    • Evaluate and prioritize incidents based on potential impact and severity, escalating issues to higher levels of management or other teams as required.
    • Assist in developing and fine-tuning automation scripts and workflows to enhance incident detection and response efficiency.
    • Contribute to the development and maintenance of key performance indicators (KPIs) and metrics to measure the effectiveness of incident response processes.
    • Act as a liaison between technical teams and business stakeholders, ensuring clear communication during incidents and status updates.

    Maintain up-to-date records of all incident handling activities in incident management systems, ensuring alignment with internal policies and audit requirements.

    Qualifications

    Requirement:

    We are looking for a candidate for?Cyber Security Incident Response who has the following:

    • Minimum 5 years of experience in incident response, with a strong understanding of cybersecurity principles, frameworks, and tools.
    • Proficient in forensic analysis, malware analysis, and network traffic analysis. Experience with SIEM tools, EDR platforms, and threat intelligence integration is essential.
    • Proven ability to lead high-stakes security incidents and coordinate cross-functional teams effectively.
    • Deep understanding of MITRE ATT&CK, cyber kill chain, and incident response methodologies.
    • Exceptional verbal and written communication skills, with the ability to convey complex technical concepts to non-technical audiences, including executives.
    • Industry certifications such as CISSP, GCIH, GCFA, or CISM are highly preferred.
    • Experience with platforms like Sentinel, Splunk, Carbon Black, or similar technologies.
    • A proactive and decisive mindset with the ability to operate under pressure.
    • Strong analytical and problem-solving skills to make informed decisions in complex situations.

    Collaborative and adaptable, with a passion for mentoring and developing team members

    Apply Now

    Pas toi?

    Merci

    Contact non sollicit¨¦

    Tout curriculum vitae ou profil de candidat non sollicit¨¦ soumis via notre site web ou receptionn¨¦ sur les adresses emails ¨¦lectroniques des employ¨¦s de Willis Towers Watson est consid¨¦r¨¦ comme la propri¨¦t¨¦ de Willis Towers Watson et n¡¯est pas soumis au paiement de frais d¡¯agence.

    Pour ¨ºtre une agence / un cabinet de recrutement autoris¨¦ par Willis Towers Watson, cette agence / ce cabinet doit avoir un accord ¨¦crit formel existant sign¨¦ par un recruteur autoris¨¦ de Willis Towers Watson et ¨ºtre dans une relation de travail active avec l¡¯organisation.

    Les CV doivent ¨ºtre soumis conform¨¦ment ¨¤ notre processus de pr¨¦sentation de candidats, ce qui inclut le fait d¡¯¨ºtre activement engag¨¦ dans la recherche en question. De m¨ºme, pour nos agences de recrutement/firmes de recherche autoris¨¦es, si le processus de pr¨¦sentation de candidats n¡¯est pas respect¨¦, aucun frais d¡¯agence ne sera pay¨¦ par Willis Towers Watson.

    Willis Towers Watson est un employeur promouvant l¡¯¨¦galit¨¦ des chances. Si vous souhaitez que vos coordonn¨¦es soient sauvegard¨¦es en vue d¡¯un examen ult¨¦rieur, veuillez envoyer un courriel ¨¤?: Agency.inquiries@willistowerswatson.com .

    Nos bureaux

    Nos collaborateurs sont pr¨¦sents dans plus de 140 pays : de Mumbai ¨¤ Londres, en passant par Manille et New York, du Moyen-Orient ¨¤ l¡¯Am¨¦rique latine. Cette dimension internationale que nous retrouvons dans la plupart de nos projets est une source d¡¯opportunit¨¦s de collaboration et de croissance incroyables. Parcourez la carte ci-dessous pour voir jusqu¡¯o¨´ une carri¨¨re chez Willis Towers Watson pourrait vous mener.

    Rencontrez nos collaborateurs