Manager, Incident Response (remote, Gbr)

CrowdStrike CrowdStrike · Enterprise · United Kingdom · Remote

CrowdStrike is seeking an Incident Response Manager to lead investigations, triage, and provide strategic recommendations to clients. The role involves leading teams, performing forensic analysis, and mentoring junior analysts. Requires strong leadership, incident response, and communication skills, with experience in cybersecurity and threat hunting.

What you'd actually do

  1. Lead incident response engagements
  2. Perform initial triage and scoping for prospective clients to understand the client objectives and level of effort involved to complete objectives.
  3. Effectively communicate with executives on the topics of forensics and malware analysis
  4. Develop and use new methods to hunt for bad actors across large sets of data.
  5. Work under the direction of outside counsel to conduct intrusion investigations

Skills

Required

  • Team leadership experience in a matrixed consulting environment
  • Incident Response experience conducting or managing incident response investigations for organisations, investigating targeted threats such as the Advanced Persistent Threat, Organised Crime, and Hactivists.
  • Computer Forensic Analysis background using a variety of forensic analysis tools in incident response investigations to determine the extent and scope of compromise.
  • Network Forensic Analysis strong knowledge of network protocols, network analysis tools like Bro/Zeek or Suricata, and ability to perform analysis of associated network logs.
  • Reverse Engineering ability to understand the capabilities of static and dynamic malware analysis.
  • Incident Remediation strong understanding of targeted attacks and able to create customised tactical and strategic remediation plans for compromised organisations.
  • Network Operations and Architecture/Engineering strong understanding of secure network architecture and strong background in performing network operations.
  • Cloud Incident Response knowledge in any of the following areas: AWS, Azure, GCP incident response methodologies.
  • Capable of completing technical tasks without supervision.
  • Strong project management skills.

Nice to have

  • Desire to grow and expand both technical and soft skills.
  • Contributing thought leader within the incident response industry.
  • Ability to foster a positive work environment and attitude.
  • Ability to travel on short notice, up to 30% of the time.

What the JD emphasized

  • Incident Response
  • Computer Forensic Analysis
  • Network Forensic Analysis
  • Reverse Engineering
  • Incident Remediation
  • Network Operations and Architecture/Engineering
  • Cloud Incident Response