The Cybersecurity Incident Response Lead Analyst is accountable for
Performing the technical and forensic investigations into cyber security events across the globe taking responsibility for the timely identification of cyberthreats and where possible minimising further risk to information assets and services.
Carrying out postincident reviews assessing the effectiveness of controls detection and response capability and supporting the required improvements with the responsible owners
Performing the forensic services for the collection processing preservation analysis and presentation of evidence in support of vulnerability mitigation and information security incident investigations
Maintaining a strong awareness of technology trends and industry best practice to enable the provision of informed advice and guidance to Business functions and IT.
Collaboration with the wider GCO teams and wider businessfunction teams where applicable in the production and maintenance of efficient and effective incident response playbooks
Supporting the Identification development and implementation of new detections Use cases
Developing and defining detailed processes and procedures to manage the response to cyber security events
Directly contributing to the continued technical enhancement of the security platforms
Supporting the continued evolution of incident response and forensic capabilities and processes including automation and orchestration
Training and developing other members of the Incident Management and Response team as well as other members of the Global Cybersecurity Operations function
Supporting a selfcritical culture whereby identification of weaknesses in the banks control plane people process and technology are brought to light in an effective manner and addressed
Supporting a culture of individual selfimprovement whereby staff are expected to maintain subject matter expertise within their area of focus and within the realm of cybersecurity more broadly
Supporting engagement of Global Businesses and Functions everywhere HSBC does business that drives a global uplift in cybersecurity awareness helping to tell the story of Cybersecurity efforts
Production of Management Information related to the CSIRT mission that is appropriate to the target audience supported by data and experienced analysis enabling informed decisions
Skills
An understanding of business needs and commitment to delivering highquality prompt and efficient service to the business
An understanding of organisational mission values and goals and consistent application of this knowledge
Strong decisionmaking capabilities with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate one
An ability to perform independent analysis of complex problems and distill relevant findings and root causes
An ability to communicate complex and technical issues to diverse audiences orally and in writing in an easilyunderstood authoritative and actionable manner
A teamfocused mentality with the proven ability to work effectively with diverse stakeholders
Selfmotivated and possessing of a high sense of urgency and personal integrity
Highest ethical standards and values
Good understanding of cyber security principles global financial services business models regional compliance regulations and applicable laws
Good understanding and knowledge of common industry cyber security frameworks standards and methodologies including OWASP ISO2700x series PCI DSS GLBA EU data security and privacy acts FFIEC guidelines CIS and NIST standards
Proven ability and experience of working in a highpressure fast paced environment where bold time critical decision making is essential
Proven experience in identifying and responding to advanced attacker methodologies both within the corporate environment as well as external attack infrastructures ideally with offensive experience and or deception environment development tripwire systems honeypots honeytokenaccounts etc using open source vendor purchased and bespokeinhouse developed solutions
Excellent knowledge and demonstrated experience of common cybersecurity technologies such as IDS IPS HIPS Advanced Antimalware prevention and analysis Firewalls Proxies MSS etc
Excellent knowledge of common network protocols such as TCP UDP DNS DHCP IPSEC HTTP etc and network protocol analysis suits
Excellent knowledge of common enterprise technology infrastructure platforms and tooling including Windows Linux infrastructure management and networking hardware
Industry Experience and Qualifications
5 years of experience in incident response andor computer forensics
Extensive experience within an enterprise scale organisation including handson experience of complex data centre enviro