
Cyber Incident Commander – Global CERT - Santander Digital Services
- Boadilla del Monte, Madrid
- Permanente
- Tiempo completo
- Be an active part of the Incident Coordinators team of Global CERT.
- Lead the response squad created to manage the incidents, made up of different roles: Incident coordinator, Incident Handlers, Forensic Analysts and Intelligence Analysts.
- Define the strategy and a tailored action plan to respond to each incident.
- Collaborate with the Local CERTs in the handling of the incidents.
- Coordinate and manage cybersecurity incidents impacting Third Party vendors and providers, mitigating the potential risk that may pose to the Group.
- Become part of a world class team that will own, respond and coordinate the most relevant and challenging cybersecurity incidents across the Group.
- Be available to participate in the incident response procedure with a On-Call scheme rotating among all the team members.
- Collaborate during the aftermath of a cybersecurity incident in the identification of Lesson Learnt that will shape and evolve the Group’s security posture.
- Collaborate with key stakeholders within the bank, such as Global Forensics, Global Security Operations Centre, Corporate Security & Intelligence, Global Cyber Fraud, Global Legal, Secure User Experience team, among others.
- Team up in projects related with the development and improvement of Incident Response plans, policies, and procedures.
- Enjoy being part of a strong and collaborative Cybersecurity Community across the world.
- 3+ years of experience in Cybersecurity Incident Response or similar responsibilities.
- Experience in crisis management is desirable.
- Technical degree or Computing Modules.
- Knowledge of Incident Response and Handling methodologies – Experienced level.
- Knowledge of cyber incident categories, incident response, and timelines for responses.
- Knowledge of cyber defense and information security procedures and regulations.
- Knowledge of cyber attack stages (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks).
- Knowledge of risk management processes (e.g., methods for assessing and mitigating risk).
- High level of English.
- Desired one or more of the following certifications (CISSP, CISA, CISM, CEH, OSCP, GCIH).
- Experience in the financial/banking industry.