Security Incident Manager
[ad_1]
The Security Incident Manager will be accountable for the investigation and reporting of high priority incidents, of which he/she is the highest escalation point for review and sign off on incident data. Receives alerts from the Security Operations Centre (SOC)for incidents the SOC cannot remediate themselves, and furthermore receives notifications of incidents for which remediation is ongoing or has already been performed by the SOC.
The person will in the end become part of the standing security organization, reporting into the Service Manager Security. He or she will work in and with the SOC project in further setting up the internal security organization (following the Target Operating Model) and the Security Operations Center service.
The SOC will operate in a hybrid model, consisting of an in-house capability in combination with a capability that is outsourced to an external Service Provider.
- Investigating, managing and resolving cyber incidents through coordination between the business, IT and vendors (EcoSystem), specifically the central incident-response contact people
- Guaranteeing that systems/environments that were involved in an incident return again in a secure (uncompromised) status
- Escalating and notifying management, also to guarantee the involvement of OpCo’s, other business units, including legal, HR, communication and executive management
- Performing a root-cause analysis (RCA) and documenting lessons learned
- Where necessary, supporting a legal case with monitoring chain of custody of forensic evidence
[ad_2]
Source link