Team Lead - Cyber Security Incident Response @MMCTech

Cluj-Napoca - Decembrie, Romania

Marsh McLennan

Marsh McLennan is the world’s leading professional services firm in risk, strategy and people. We bring together experts from across our four global businesses — Marsh, Guy Carpenter, Mercer and Oliver Wyman — to help make organizations more...

View all jobs at Marsh McLennan

Apply now Apply later

Company:

MMC Corporate

Description:

We are seeking a talented individual to join our Global Cyber Defense team.
This role will be based in our Security Operations Center (SOC) as part of Cluj-Napoca Tech Hub.

As a Team Lead - Cyber Security Incident Response you will play a crucial role in analyzing security event data and managing a team of analysts while contributing to the overall security posture of the organization.  
 

Marsh McLennan (MMC) has established its EMEA Technology Hub in Cluj, Romania, reflecting our commitment to innovation and excellence. This hub is central to our digital strategy, addressing emerging challenges and enhancing service delivery through advanced technology solutions that empower our clients and promote sustainable growth.

We will count on you to:

  • Act as the reporting manager for the Tier1 and Tier2 analysts in your geographic region

  • Provide technical and professional guidance for analysts on your team

  • Analyzing network traffic, endpoint security events, and other various log sources to identify threats, assess potential impact, and recommend mitigations

  • Supporting other security functions and teams to ensure the holistic implementation of security controls, technologies, practices, and programs

  • Contributing to the development and improvement of response processes, documentation, tool configurations, and detection logic 

  • Assisting in additional Security Operation Center initiatives, including playbook development and documentation, new rule creation, and tool evaluations

  • Maintaining an operational knowledge of global threat trends, known threat actors, common tactics, techniques, and procedures (TTPs), and emerging security technologies

  • Collaborating on Security Operation Center team training opportunities and other cross training opportunities as well as operating as a subject matter expert on various security topics across multiple domains

  • Supporting 24x7 operations by participating in an on-call rotation and assisting in ongoing incidents during non-standard hours

​​​

What you need to have:

  • 2+ years of information security experience and/or 2-4 years of experience in security analysis in a non-security focused role

  • Undergraduate degree in Computer Science (CS), Computer Information Systems (CIS), other related degrees, or equivalent experience;

  • Excellent critical thinking skills, with proven analytical expertise and the ability to learn adaptively;

  • Demonstrated leadership ability of technical teams;

  • Demonstrated effective verbal, written and interpersonal communication skills with the ability to communicate security concepts to both technical and non-technical audiences;

  • Demonstrated experience with security technologies and alerts, such as intrusion prevention and detection systems, web proxies, SIEM, SOAR, EDR, firewalls, web application scanner, vulnerability scanners, forensics tools, open-source tools, or other security technologies;

  • Knowledge in one or more of the following domains: Network Operations and Architecture, Operating Systems, Identity and Access Management, Programming, Cloud Computing, Databases, or Cryptography;

What makes you stand out?

  • Ability to operate independently in a dynamic, evolving environment with multiple inputs and tasks simultaneously;

  • Knowledge of common attacks, current threats, threat actors, and industry trends;

  • Familiarity with common security frameworks and models, such as MITRE ATT&CK, Lockheed Martin Cyber Kill Chain, The Diamond Model of Intrusion Analysis and NIST Cybersecurity Framework;

  • Professional or technical certifications, such as Security+, GIAC Certified Incident Handler (GCIH), Certified Ethical Hacker (CEH), or other related certifications;

Why join our team:

  • We help you be your best through professional development opportunities, interesting work, and supportive leaders;

  • We foster a vibrant and inclusive culture where you can work with talented colleagues to create new solutions and have an impact for colleagues, clients, and communities;

  • Our scale enables us to provide a range of career opportunities, as well as benefits and rewards to enhance your well-being;

  • A yearly budget and the opportunity to build your flexible benefits package (up to 20% of your annual salary);

  • 30+ days off (25 legal days off, 1 extra day off on your birthday, public holiday replacement days, extra buy/sell from your benefits budget);

  • Performance Bonus scheme;

  • Matching charity contributions, charity days off, and the Pay it Forward charity challenge;

  • Core benefits - Pension, Life and Medical Insurance, Meal Vouchers, Travel Insurance;

  • We champion flexible working, and our mission is to help you find YOUR work-life balance, whether that is standard working, flextime working, or working from home;

Marsh McLennan (NYSE: MMC) is a global leader in risk, strategy and people, advising clients in 130 countries across four businesses: Marsh, Guy Carpenter, Mercer and Oliver Wyman. With annual revenue of $23 billion and more than 85,000 colleagues, Marsh McLennan helps build the confidence to thrive through the power of perspective. For more information, visit marshmclennan.com, or follow on LinkedIn and X.

Marsh McLennan is committed to creating a diverse, inclusive and flexible work environment. We aim to attract and retain the best people and embrace diversity of age, background, disability, ethnic origin, family duties, gender orientation or expression, marital status, nationality, parental status, personal or social status, political affiliation, race, religion and beliefs, sex/gender, sexual orientation or expression, skin color, or any other characteristic protected by applicable law.

Marsh McLennan is committed to hybrid work, which includes the flexibility of working remotely and the collaboration, connections and professional development benefits of working together in the office. All Marsh McLennan colleagues are expected to be in their local office or working onsite with clients at least three days per week. Office-based teams will identify at least one “anchor day” per week on which their full team will be together in person.

Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  0  0  0

Tags: CEH Cloud Computer Science Cryptography Cyber defense Cyber Kill Chain EDR Endpoint security Firewalls Forensics GCIH GIAC IAM Incident response Intrusion prevention MITRE ATT&CK NetOps NIST Security analysis SIEM SOAR SOC Strategy TTPs

Perks/benefits: Career development Flex hours Insurance Salary bonus Team events Travel

Regions: Remote/Anywhere Europe
Country: Romania

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.