Incident Management is part of the Incident Response and Management Global Team.
The role of the Incident Manager is to coordinate the response and recovery activities from information security incidents.
This includes collaboration with appropriate response partners, assist with determining the root cause of incidents and work with stakeholders and responsible parties to remediate any identified control gaps or failures;
Escalate issues to management in a timely manner with appropriate information regarding severity, exposure, and action items;
this role requires critical thinking and investigative mindset coupled effective written, and verbal communication skills
Requirements
Education: B.E. / B. Tech/M.E. /M. Tech/B.Sc./M.Sc./BCA/MCA (prefer IT/CS specialization)
Certifications, If Any: CEH, Security+, CCNA or any equivalent
Experience Range: 6-8+ years
Foundational skills: Experience in identifying threats and applying security controls
7 + years of experience with Information Security related activities.
7 + years of experience in an operations focused on information security role.
Experience conducting analysis/investigation and containment of potential data breaches or cyber security incidents.
Strong analytical, tactical, and critical thinking ability.
Ability to lead technical bridge lines to develop quick containment solutions to cyber-security incidents.
Ability to handle multiple competing priorities in a fast-paced environment.
Ability to communicate effectively across all levels of a global financial institution.
Familiarity with security vulnerabilities, exploits, malware, and digital forensics as they relate to Incident Response.
Security+ or equivalent certification required within 6 months of employment.
Experience and ability to quickly use open-source tools to gather information on a domain or subject
Self-motivated individual willing to learn new skills and accomplish goals within a short timeframe
Good understanding of Security Event Management tools, techniques, and processes
Ability to leverage technical skills to correlate data to streamline analysis process
Familiarity with and basic understanding of networking systems, firewalls, simple DNS & DHCP, security vulnerabilities, exploits, attacks, and malware
Ability to relate technical issues to non-technical associates / business owners understanding of vulnerabilities, exploitation, tools, and techniques especially ArcSight (SIEM tool)