Lead Threat Response Operations Analyst

United Kingdom - Sandwich Posted 2h Leaves the board in 7 days
ATS Keyword Match See which key terms from this posting your resume already has. Free.

ROLE SUMMARY

Our Global Cyber Defense team is responsible for safeguarding Pfizer's digital assets and infrastructure through proactive threat detection, incident response, and risk mitigation across on-premises, cloud, and hybrid environments.

As a Lead Threat Response Operations Analyst within Pfizer’s Global Cyber Defense organization, you will serve as a senior individual contributor, providing technical leadership for the investigation and response to sophisticated cyber threats. While this is not a people-management role, you will lead complex investigations, coordinate the response to security incidents on a global scale, and provide technical guidance to analysts and partner teams. You will bring deep expertise in cyber threat analysis, incident response, malware investigations and adversary tradecraft, with the ability to operate confidently across complex business and technical environments.

Working alongside Threat Detection, Digital Forensics, Security Engineering and other partner teams, you will identify, contain and eradicate threats while providing strategic recommendations to strengthen Pfizer’s cyber resilience.

ROLE RESPONSIBILITIES

  • Correlate and analyse security telemetry from endpoint, identity, network, cloud, email and threat intelligence sources to identify, investigate and respond to malicious activity.
  • Apply knowledge of adversary tactics, techniques and procedures (TTPs) to reconstruct attack lifecycles, determine attack pathways, identify root cause and develop strategic detection and mitigation recommendations.
  • Lead the assessment of cyber security incidents, determining severity, business impact, threat scope, and appropriate response and escalation actions.
  • Apply advanced knowledge of networking, operating systems and security architectures to analyse technical evidence, identify attack vectors and guide effective containment, eradication and remediation actions.
  • Communicate complex technical findings, incident impacts, response decisions and remediation recommendations clearly to technical teams, business stakeholders and senior leadership.
  • Drive continuous improvement of Threat Response processes, investigation methodologies, operational procedures, reporting standards, and playbooks to enhance the effectiveness and maturity of the cyber incident response capability
  • Co-ordinate effectively across technical and business teams to coordinate cyber incident response activities, maintaining professionalism and sound judgement during high-pressure situations.
  • Lead complex cyber security projects and cross-functional workstreams, ensuring timely delivery of objectives and operational improvements.
    Support the triage of cyber security tickets, providing technical guidance on priority, scope, investigation, escalation and appropriate response actions.
  • Provide technical guidance, coaching and knowledge sharing to analysts and partner teams to strengthen investigation quality and Threat Response capability.
  • Participate in a scheduled on-call rotation, including weekends, providing timely response, investigation, escalation, and coordination of cyber security incidents.
  • Maintain and continuously develop technical expertise in cyber security, threat response, and emerging attack techniques through ongoing training, research, and professional development.

 

BASIC QUALIFICATIONS

  • Bachelor’s degree in cyber security, computer forensics, computer science, Information Security, Information Systems, Engineering, Sciences or related field.
  • Some relevant experience in cyber security operations, incident response or threat investigation, with demonstrated experience leading complex investigations.
  • Advanced understanding of TCP/IP, network protocols and traffic flows, operating systems, cloud and identity technologies, enterprise security architectures and defence-in-depth principles.
  • Advanced knowledge of Windows operating systems, system administration, security controls, native utilities and investigative artefacts.
  • Demonstrated ability to analyse and correlate large volumes of security log data using security information and event management (SIEM) platforms, such as CrowdStrike Falcon Next-Gen SIEM, Splunk, Google SecOps and draw accurate, evidence-based conclusions.
  • Experience using endpoint detection and response (EDR) platforms, such as CrowdStrike Falcon, Microsoft Defender for Endpoint or VMware Carbon Black, to investigate malicious activity, analyse endpoint telemetry and support incidentcontainment and remediation.
  • Experience using security analysis and investigation tools such as Wireshark, Snort, Splunk, Kali Linux, SIFT Workstation, REMnux and Volatility or comparable commercial and open-source technologies, including tools used for memory forensics and malware analysis.
  • Advanced understanding of the life cycle of network threats, attacks, attack vectors and methods of exploitation with an understanding of intrusion set tactics, techniques and procedures (TTPs)
  • Demonstrated ability to analyse and resolve complex technical problems, working independently and collaboratively within cross-functional teams.
  • Maintain and continuously develop technical expertise in cyber security, threat response and emerging attack techniques through ongoing training, research and professional development.
  • Strong written, verbal and interpersonal communication skills, together with demonstrated organisational and planning abilities and the capacity to coordinate multiple complex investigations and workstreams simultaneously.
  • Excellent communication and presentation skills with the ability to present to a variety of internal audiences including senior executives.
  • Demonstrated experience leading and delivering complex cyber security projects and cross-functional workstreams, achieving both short-term objectives and longer-term operational improvements.
  • Practical experience using the Linux command line to support security investigations, data analysis and the operation of cyber security tools.

Preferred qualification:

  • Participation in practical cyber security exercises, such as red team and blue team simulations, capture-the-flag challenges, cyber ranges or incident response exercises.
  • Experience using scripting or programming languages, such as Python or PowerShell, to support security investigations, analyse security data and automate repetitive tasks.

 

 


 
Work Location Assignment: Hybrid

Purpose 

Breakthroughs that change patients' lives... At Pfizer we are a patient centric company, guided by our four values: courage, joy, equity and excellence. Our breakthrough culture lends itself to our dedication to transforming millions of lives.  

Digital Transformation Strategy

One bold way we are achieving our purpose is through our company wide digital transformation strategy. We are leading the way in adopting new data, modelling and automated solutions to further digitize and accelerate drug discovery and development with the aim of enhancing health outcomes and the patient experience.

Flexibility  

We aim to create a trusting, flexible workplace culture which encourages employees to achieve work life harmony, attracts talent and enables everyone to be their best working self. Let’s start the conversation!  

Equal Employment Opportunity 

We believe that a diverse and inclusive workforce is crucial to building a successful business. As an employer, Pfizer is committed to celebrating this, in all its forms – allowing for us to be as diverse as the patients and communities we serve. Together, we continue to build a culture that encourages, supports and empowers our employees.

DisAbility Confident

We are proud to be a Disability Confident Employer and we encourage you to put your best self forward with the knowledge and trust that we will make any reasonable adjustments necessary to support your application and future career. Our mission is unleashing the power of our people, especially those with unique superpowers. Your journey with Pfizer starts here!

To learn more about acceptable and prohibited uses of AI during the recruitment process, please review our candidate AI-use guidelines available on Pfizer Careers.

 

 

Information & Business Tech

Share your thoughts