Grant Thornton's Cyber Fusion Centre (CFC) is looking for an experienced CSIRT Incident Responder / Threat Hunter to protect enterprise systems and information by promptly responding to security threats and incidents — working both independently and as part of a team to resolve issues and maintain the organization's overall security posture.
This role covers incident response, threat hunting, data analysis, incident orchestration, stakeholder coordination, and post-incident improvement. It receives major incident escalations from detection operations and supports real-time response and reporting.
The CSIRT Incident Responder works closely with the SOC, platform engineering, IT infrastructure, IAM, network security, email security, legal/privacy, communications, and business stakeholders. For qualified incidents, this person acts as the incident response orchestrator, ensuring response actions are coordinated, documented, and tracked end to end.
The successful candidate will be confident investigating detections, reviewing endpoint telemetry, validating indicators of compromise, threat hunting, coordinating containment actions, and collaborating across business and technical stakeholders.
Incident Response, Threat Hunting & Escalation
· Protect enterprise systems and information by promptly responding to security threats and incidents, individually and as part of a team.
· Receive major incident escalations from SOC detection operations and support response and reporting.
· Proactively hunt for threats and support containment, eradication, and recovery efforts.
· Analyze security incidents to identify rootcause, determine impact, and improve incident handling procedures.
· Act as a subject matter expert, providing insight and guidance to technical teams on prevention, detection, and response.
· Research current methods, tools, and trends in incident response, threat hunting, and digital forensics.
CSIRT Incident Intake & Validation
· Monitor designated CSIRT trigger channels for qualified potential incidents escalated by the SOC.
· Validate severity, business impact, affected assets, impacted users, attack scope, and urgency.
· Ensure incidents are responded to, recorded, tracked, and updated in line with the IR Runbook.
Major Incident Handling
· Determine whether major incident criteria are met and launch the Major Incident Management (MIM) bridge or call per the Communication Plan.
· Initiate communications, maintain the incident timeline and summary, and brief stakeholders on MIM calls.
· Establish and maintain the agreed update cadence throughout the incident.
· Act as the incident response orchestrator during active security incidents.
· Proactively coordinate with relevant departments — management, legal, security, operations, infrastructure, privacy, communications, and business stakeholders.
· Mobilize incident responders across SOC, platform engineering, endpoint security, IAM, network security, email security, infrastructure, vulnerability management, and IT teams.
· Assign containment, investigation, eradication, recovery, and evidence preservation actions to the correct teams.
· Track execution of the incident response playbook.
· Oversee short-term containment actions per approved IR playbooks, and initiate approval for long-term containment where required.
· Coordinate with InfoSec and business leads on business context, asset criticality, containment approval, and BCP/DR triggers.
· Guide evidence preservation for forensic purposes in line with the IR Runbook and defined storage locations.
· Produce thorough incident reports and documentation, presenting findings to the team and leadership on a routine basis.
· Identify and manage lessons learned and corrective action plans.
Other Activities
· Identify and help mitigate vulnerabilities and potential attack paths across the organization.
· Recommend SIEM detection enhancements, alert tuning, and response playbook improvements to engineering teams.
· Support deep-dive log analysis where root cause, attack path, or impact is unclear.
· Support the SOC team as needed.
· Conduct threat hunting activities across cross-platform security tooling.
Shift & Operational Requirements
· Operate within 24x7 security operations and incident response environment.
· Participate in major incident bridges, MIM calls, and technical response calls.
· Communicate clearly with technical teams, business teams, management stakeholders, and legal/privacy and communications teams.
· Follow structured incident response, evidence handling, reporting, and documentation practices.
Required Qualifications
Experience
· English Level B2+
· 6+ years of experience in cybersecurity, SOC, or threat hunting.
· 2+ years of experience in major incident management.
· Experience working in a 24x7 SOC, CSIRT, MDR, MSSP, or enterprise security operations environment.
· Experience handling endpoint security incidents, including malware infections, suspicious process execution, credential theft, lateral movement, persistence, and unauthorized access.
· Experience preparing incident timelines, technical findings, RCA inputs, management summaries, and post-incident reports.
Education
· Bachelor's degree in Computer Science, Information Security, Cybersecurity, or a related discipline preferred.
· Equivalent practical experience in cybersecurity operations, incident response, threat hunting, or digital forensics will also be considered.
Certifications (Preferred)
· GIAC Certified Incident Handler (GCIH)
· CrowdStrike Certified Falcon Responder (CCFR)
· CrowdStrike Certified Falcon Hunter (CCFH)
Core Competencies
· Ownership mindset with strong attention to detail
· Solid understanding of MITRE ATT&CK and the incident response lifecycle
· Excellent written and verbal communication skills
· Ability to brief both technical and non-technical stakeholders
· Strong organization, time management, and attention to detail
· Calm, structured decision-making under high-pressure incidents
· Ability to work independently and as part of a team
Software Powered by ICIMS
www.icims.com