Associate Director, Incident Response and Forensics

CSL

King of Prussia (PA)

On-site

USD 180,000 - 260,000

Full time

11 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

CSL invites a highly technical leader to guide a global Digital Forensics, Incident Response and eDiscovery team. You will own strategy, people, processes, and tech, collaborating with Security Operations, DLP, and Threat Intelligence to defend CSL.

You will direct adoption of new tools, lead cross-functional teams, and develop incident handling across the lifecycle to protect CSL systems and data.

Qualifications

  • College degree, preferably in a related technical subject; advanced degree preferred.
  • MS in a relevant discipline (cybersecurity, MIS, or related).
  • Project management certification or training desirable.
  • CISSP, CISM, CISO, GIAC certifications preferred.

Responsibilities

  • Lead a global DFIR/incident response team and mentor staff.
  • Develop threat analysis structure with Security Operations.
  • Identify tools and defenses for incident response and threat detection.
  • Derive IOCs from malicious activity to strengthen defenses.
  • Conduct in-depth forensic analysis of operating systems.
  • Partner with Compliance, Legal, Privacy, and others for investigations.

Skills

Leadership
Incident response
Digital forensics
Threat hunting
Training & mentoring

Education

Bachelor's degree
MS in a relevant discipline

Tools

CISSP
CISM
GIAC-GCED
GIAC-GCIH
GIAC-CFE

Job description

CSL is looking for a highly technical and detail-oriented leader in the DFIR space that specializes in digital forensics, malware analysis, threat detection, and the fast-paced excitement of supporting incident response activities.

As the leader of our Digital Forensics and eDiscovery team, you will be responsible to support and grow a global team, own the strategy and direction for the people, processes, and technology to fulfill your mission, and partner deeply with our Security Operations, Data Loss Prevention, and Threat Intelligence teams to help CSL defend itself from cyber attacks. You will direct the adoption of new tools and technologies to further your goals.

The Position Holder

Leads a global team to apply security incident handling processes for CSL to successfully support the cybersecurity and information security incident response process to:

  • Prepare for
  • Identify
  • Contain
  • Eradicate
  • Recover

from cybersecurity events

The role will lead a global team of digital forensics, incident response and eDiscovery analysts that will:

  • Work closely with the Director, Security Operations to develop and implement a cybersecurity threat analysis structure of common attack techniques to evaluate an attacker's spread through a CSL system, platform and or network.
  • Develop and maintain a continuous upskilling program for your team to increase skills and overall capability maturity
  • Identify and implement tools to determine attack types and choose appropriate defenses and response tactics for each
  • Derive Indicators of Compromise (IOCs) from malicious activity to strengthen incident response, threat detection, and intelligence efforts
  • Conduct in-depth forensic analysis of various operating systems
  • Examine traffic using common network protocols to identify patterns of activity or specific actions that warrant further investigation
  • Detect and hunt for adversary tools, tactics, and procedures (TTPs) across an enterprise environment
  • Partner with Compliance, Legal, Privacy, and other teams to perform internal investigations pertaining to eDiscovery matters

Demonstrates thought leader-level abilities with, and/or a proven record of success directing efforts in the following areas: Network Analysis Computer Memory Analysis Endpoint Analysis Cyber Incident Lifecycle NIST 800-61 Lead and supervise teams to create an atmosphere of trust and seek diverse views to encourage improvement and innovation, answer questions and provide direction to less-experienced staff, coach staff including providing timely meaningful written and verbal feedback

Reports to Executive Director, Enterprise Monitoring & Cyber Resilience

Direct Reports – This role will manage a team of Forensics, eDiscovery, Incident Response and Threat Hunting SME’s and may have Project Managers, Project Coordinators, Security Architects, and vendors or managed service providers as direct and indirect reports based on security project portfolio.

Main Responsibilities And Accountabilities

Participates in the hiring, growth, and development of junior incident response staff in the areas of threat hunting, forensic analysis, eDiscovery, litigation hold, incident resolution and return to operations. Mentors and directs specially assigned incident response project managers and their teams and program management staff, and actively role models expected project management and leadership behaviors and processes designed to improve project results and the performance of the team.

Position Qualifications And Experience Requirements

Required: College degree, preferably in a related technical subject; or advanced degree in business or industry-related subject or equivalent related work experience in cybersecurity and manufacturing.

Preferred: An advanced degree (MS) in a relevant discipline (or equivalent) including cybersecurity, management information systems, and related technologies related to manufacturing cybersecurity.

Project management certification / training desirable / CISSP, CISM, CISO, GIAC-GCED, GIAC-GCIH, and/or GIAC-CFE certification preferred.

Essential Experience
  • 8+ years demonstrated experience leading global, multi-functional Digital Forensics/Cybersecurity Incident Response teams (bio-pharma manufacturing environment preferred but not mandatory)
  • Strong leadership, consultative, communication, and conflict management skills to influence project leaders and stakeholders, including non-specialists, at all levels in the organization and achieve team objectives while maintaining a positive team environment.
  • The ability to train, mentor, and develop project managers in project management methodologies and their application; the ability to manage in a matrix environment.
  • The ability to work on complex problems where analysis of situation or data requires an in-depth evaluation of various factors to achieve best results.
  • The ability to clearly communicate complex issues to senior management so that critical issues are understood quickly and can be addressed immediately.
  • Strong strategic planning, quantitative, and decision analysis capabilities.
  • Strong project management and integration skills; ability to coordinate all aspects of a project or program.
  • Demonstrated experience in developing, managing, and controlling cross functional project budgets.
  • 8+ years’ experience using a formal project management methodology, techniques and tools.
  • Proficiency and use of enterprise computer applications including the Microsoft suite of products and project management software.
Desired Experience
  • Experience in biopharmaceutical industry
  • Experience in crafting enterprise incident response programs for a global company – process and technical definition.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Associate Director, Incident Response and Forensics
Associate Director, Incident Response and Forensics

CSL Plasma Inc. • King of Prussia (PA)

Hybrid
USD 190,000 - 270,000
Director, Global Digital Forensics & Incident Response
Director, Global Digital Forensics & Incident Response

CSL Plasma Inc. • King of Prussia (PA)

Hybrid
USD 190,000 - 270,000
Global Director of Digital Forensics & Incident Response
Global Director of Digital Forensics & Incident Response

CSL • King of Prussia (PA)

On-site
USD 180,000 - 260,000
Associate Director, Incident Response and Forensics
Associate Director, Incident Response and Forensics

CSL Behring • False Pass (AK)

On-site
USD 140,000 - 190,000
Global Lead, Incident Response & Forensics
Global Lead, Incident Response & Forensics

CSL Behring • False Pass (AK)

On-site
USD 140,000 - 190,000
Senior Incident Response Lead & Forensics Expert
Senior Incident Response Lead & Forensics Expert

Compunnel, Inc. • Jersey City (NJ)

On-site
USD 100,000 - 130,000
Cyber Defense Incident Responder - Associate Director
Cyber Defense Incident Responder - Associate Director

Ernst & Young Advisory Services Sdn Bhd • Hoboken (NJ)

On-site
USD 140,000 - 210,000
Incident Response Analyst - Americas
Incident Response Analyst - Americas

The Carlyle Group • Washington

On-site
USD 120,000 - 180,000
Senior Cyber Forensic Analyst
Senior Cyber Forensic Analyst

ShorePoint, LLC • Albuquerque (NM)

On-site
USD 120,000 - 180,000
144 hours PTO
11 holidays
Health insurance coverage 85%
+3
Sr. Digital Media Forensics Team Support (Computer Forensic Specialist)
Sr. Digital Media Forensics Team Support (Computer Forensic Specialist)

Prescient Edge • Linthicum (MD)

On-site
USD 100,000 - 132,000