CrawlJobs Logo

Incident Response Lead Analyst

https://www.hsbc.com Logo

HSBC

Location Icon

Location:
Poland

Category Icon
Category:
IT - Administration

Job Type Icon

Contract Type:
Employment contract

Salary Icon

Salary:

Not provided

Job Description:

As the Incident Response Lead Analyst, you'll perform technical and forensic investigations into cybersecurity events globally, carry out post-incident reviews, develop processes to manage cybersecurity incidents, collaborate across teams, and support the continual enhancement of security platforms and processes.

Job Responsibility:

  • Performing the technical and forensic investigations into cyber security events across the globe, taking responsibility for the timely identification of cyber-threats and where possible, minimising further risk to HSBC’s information assets and services
  • carrying out post-incident reviews, assessing the effectiveness of controls, detection and response capability and supporting the required improvements with the responsible owners
  • performing the forensic services for the collection, processing, preservation, analysis, and presentation of evidence in support of vulnerability mitigation and information security incident investigations
  • maintaining a strong awareness of technology trends and industry best practice, to enable the provision of informed advice and guidance to HSBC Business functions and HSBC IT
  • collaboration with the wider GCO teams (and wider business/function teams where applicable) in the production and maintenance of efficient and effective incident response playbooks
  • supporting the identification, development and implementation of new detections (Use cases)
  • developing and defining detailed processes and procedures to manage the response to cyber security events
  • directly contributing to the continued technical enhancement of the security platforms
  • supporting the continued evolution of incident response and forensic capabilities and processes, including automation and orchestration
  • training and developing other members of the Incident Management and Response team as well as other members of the Global Cybersecurity Operations function
  • supporting a 'self-critical' culture whereby identification of weaknesses in the bank’s control plane (people, process and technology) are brought to light in an effective manner and addressed
  • supporting a culture of individual self-improvement whereby staff are expected to maintain subject matter expertise within their area of focus and within the realm of cybersecurity more broadly
  • supporting engagement of Global Businesses and Functions everywhere HSBC does business that drives a global up-lift in cybersecurity awareness helping to 'tell the story' of HSBC Cybersecurity efforts
  • production of Management Information related to the CSIRT mission that is appropriate to the target audience, supported by data and experienced analysis enabling informed decisions.

Requirements:

  • An understanding of business needs and commitment to delivering high-quality, prompt and efficient service to the business
  • an understanding of organisational mission, values and goals and consistent application of this knowledge
  • strong decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate one
  • an ability to perform independent analysis of complex problems and distill relevant findings and root causes
  • an ability to communicate complex and technical issues to diverse audiences, orally and in writing, in an easily-understood, authoritative and actionable manner
  • a team-focused mentality with the proven ability to work effectively with diverse stakeholders
  • self-motivated and possessing of a high sense of urgency and personal integrity
  • highest ethical standards and values
  • good understanding of HSBC cyber security principles, global financial services business models, regional compliance regulations and applicable laws
  • good understanding and knowledge of common industry cyber security frameworks, standards and methodologies, including OWASP, ISO2700x series, PCI DSS, GLBA, EU data security and privacy acts, FFIEC guidelines, CIS and NIST standards
  • proven ability and experience of working in a high-pressure, fast-paced environment where bold, time-critical decision making is essential
  • proven experience in identifying and responding to advanced attacker methodologies both within the corporate environment as well as external attack infrastructures, ideally with offensive experience and/or deception environment development (tripwire systems, honeypots, honey-token/accounts, etc.) using open source, vendor purchased and bespoke/in-house developed solutions
  • proven experience in crisis management, crisis response frameworks and communications
  • ability to produce complex reports containing technical information, communicating this clearly to a non-technical audience
  • experience producing forensic analysis reports, detailing findings of the analysis and clearly documenting processes and techniques employed
  • ability to speak, read and write in English.
What we offer:
  • Competitive salary
  • annual performance-based bonus
  • additional bonuses for recognition awards
  • Multisport card
  • private medical care
  • life insurance
  • one-time reimbursement of home office set-up (up to 800 PLN)
  • corporate parties & events
  • CSR initiatives
  • nursery and kindergarten discounts
  • financial support with trainings and education
  • social fund
  • flexible working hours
  • free parking.

Additional Information:

Job Posted:
May 07, 2025

Expiration:
June 08, 2025

Employment Type:
Fulltime
Work Type:
Hybrid work
Job Link Share:
Welcome to CrawlJobs.com
Your Global Job Discovery Platform
At CrawlJobs.com, we simplify finding your next career opportunity by bringing job listings directly to you from all corners of the web. Using cutting-edge AI and web-crawling technologies, we gather and curate job offers from various sources across the globe, ensuring you have access to the most up-to-date job listings in one place.