Security Services Incident Manager

Introduction
Information and Data are some of the most important organizational assets in today’s businesses. As a Security Consultant, you will be a key advisor for IBM’s clients, analyzing business requirements to design and implement the best security solutions for their needs. You will apply your technical skills to find the balance between enabling and securing the client’s organization with the cognitive solutions that are making IBM the fastest growing enterprise security business in the world.

Your Role and Responsibilities
Security Incident Manager will be overall responsible for accountability and contribution for the design, improve and execution of the Incident process and procedures;
Validating classification of an incident as an Incident against Incident Criteria;
Determining the scope of the Incident;
Managing/Performing all internal notification, executive alerts, and escalation activities through service recovery of an Incident according to Incident Notification Timeframe;
Assembling an Incident Team consisting of technical support people (other levels of support, across domains/competencies as required), management, and key stakeholders to develop, execute, monitor, and track an integrated resolution plan through service recovery of the Incident;
Making service restoration/recovery decisions, engaging the management team as required;
Ensuring that the progress of the Incident recovery and all relevant times are documented in the associated Incident Record(s);
Initiating and facilitating the Incident bridge;
Obtaining and providing status on Incident recovery progress;
Ensuring that the customer is contacted to confirm that the incident has been resolved to the customer’s satisfaction.

Required Technical and Professional Expertise

  • Hunting for suspicious anomalous activity based on data alerts or data outputs from SIEM and several other IT security tools
  • Drives containment strategy during data loss or breach events
  • Triage and resolve advanced vector attacks such as botnets and advanced persistent threats (APTs)
  • Recommend incident containment and remediation actions to the resolver groups
  • Check for incident remediation actions completeness on a regular basis, and perform occasional vulnerability assessment and penetration tests to validate the effectiveness of such remediations
  • Provide use case creation/tuning recommendations to SIEM administrators based on findings during investigations or threat information reviews
  • Develop and deliver incident reporting for executives and managers
  • Create and maintain daily activity

Preferred Technical and Professional Expertise

  • continuous improvement of processes and cooperation with other teams to improve alerts and rules in the incident monitoring systems
  • handling presentations, trainings, etc

About Business UnitIBM’s Cloud and Cognitive software business is committed to bringing the power of IBM’s Cloud and Watson/AI technologies to life for our clients and ecosystem partners around the world. IBM provides you with the most comprehensive and consistent approach to development, security and operations across hybrid environments—with complete software solutions for business and IT operations, development, data science, security, and management. Our experts and software capabilities help organizations develop applications once and deploy them anywhere, integrate security across the breadth of their IT estate, and automate operations with management visibility. With IBM, you also have access to new skills and methods, governance and management approaches, and a deep ecosystem of industry experts and partners.

Your Life @ IBMAre you craving to learn more? Prepared to solve some of the world’s most unique challenges? And ready to shape the future for millions of people? If so, then it’s time to join us, express your individuality, unleash your curiosity and discover new possibilities.

Every IBMer, and potential ones like yourself, has a voice, carves their own path, and uses their expertise to help co-create and add to our story. Together, we have the power to make meaningful change – to alter the fabric of our clients, of society and IBM itself, to create a truly positive impact and make the world work better for everyone.

It’s time to define your career.

About IBMIBM’s greatest invention is the IBMer. We believe that through the application of intelligence, reason and science, we can improve business, society and the human condition, bringing the power of an open hybrid cloud and AI strategy to life for our clients and partners around the world.Restlessly reinventing since 1911, we are not only one of the largest corporate organizations in the world, we’re also one of the biggest technology and consulting employers, with many of the Fortune 50 companies relying on the IBM Cloud to run their business. At IBM, we pride ourselves on being an early adopter of artificial intelligence, quantum computing and blockchain. Now it’s time for you to join us on our journey to being a responsible technology innovator and a force for good in the world.

Location StatementFor additional information about location requirements, please discuss with the recruiter following submission of your application.

Being You @ IBMIBM is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, pregnancy, disability, age, veteran status, or other characteristics. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status.