The Incident Response team is seeking a T&M resource who shall serve as a first-line responder for security events and alerts, with a primary focus on DWS-specific cyber security monitoring and incident triage activities. The role ensures timely identification, assessment, escalation, and response to potential security incidents.
Experience in a Security Operations Center (SOC), Incident Response, Cyber Defense, or Security Monitoring environment.
Knowledge of security incident triage, investigation, and escalation processes.
Understanding of common cyber threats, attack techniques, indicators of compromise, and security controls.
Experience: 7+ years in cybersecurity incident response or SOC operations.
Proficiency in leading containment and remediation during critical incidents.
Strong knowledge of incident response playbooks and runbooks maintenance.
Ability to conduct root cause analysis and post-incident reviews.
Familiarity with regulatory and compliance requirements related to incident handling.
On-Call readiness for 24/7 SOC coverage and shift-based responsibilities.
Experience with phishing simulations, security awareness training, and user education.
Proven track record of cross-team collaboration (IT, Engineering, Governance).
Experience in documenting incidents for audit trails and security metrics reporting.
Strong analytical and problem-solving skills.
Ability to work effectively in a fast-paced operational environment and manage multiple activities simultaneously.
Excellent communication and stakeholder management skills.
Experience working within global teams and shift-based operational environments.