- Location
- SE-STO-001, Sweden
- Type
- Full-time
- Department
- Management
- Experience
- 8+ years
- Closing date
- Today
- Source
- Workday
Description
Job Description
Solve complex problems. Decode the future.
At Electrolux Group, as a leading global appliance company, we strive every day to shape living for the better for our consumers, our people and our planet. We share ideas and collaborate so that together, we can develop solutions that deliver enjoyable and sustainable living.
Come join us as you are. We believe diverse perspectives make us stronger and more innovative. In our global community of people from 100+ countries, we listen to each other, actively contribute, and grow together.
Join us in our exciting quest to build the future home.
All about the role:
We are looking for a highly experienced Cyber Defense Expert to act as a Incident Management and Response subject matter expert while leading the operational maturity and effectiveness of the Security Operations Center. The role is accountable for driving strong incident lifecycle management, from detection, triage, escalation and containment through eradication, recovery, executive communication and lessons learned.
You will play a central role in protecting the organization by leading cyber incident response, strengthening SOC effectiveness and improving operational resilience across a global environment. This is an opportunity to make a direct impact on how cyber threats are detected, managed, contained and learned from, while helping mature people, processes and technologies that underpin modern cyber defense.
What you'll do:
Incident Management & Response Leadership
Lead end-to-end cyber incident response activities across detection, triage, analysis, containment, eradication, recovery and closure.
Act as incident commander or senior response lead for high-severity cyber incidents, ensuring clear ownership, decision-making, escalation and communication.
Design, maintain and continuously improve incident response frameworks, playbooks, severity models, escalation paths and operating procedures.
Coordinate technical investigations across SOC, infrastructure, cloud, endpoint, identity, network, application and third-party teams.
Drive post-incident reviews, root cause analysis, corrective actions and measurable improvements to reduce recurrence and improve response effectiveness.
SOC Leadership & Operational Excellence
Lead and mature SOC operations, including alert triage quality, investigation standards, escalation discipline, response workflows and service performance.
Define and track SOC metrics, SLAs, KPIs and executive reporting related to detection, response, backlog, false positives, incident trends and operational effectiveness.
Provide operational governance for managed SOC providers, ensuring clear accountability, quality assurance, continuous improvement and alignment with cyber defence objectives.
Improve detection-to-response processes by strengthening SIEM, SOAR, EDR, NDR, XDR, identity and cloud security workflows.
Support analyst enablement through guidance, process clarity, knowledge sharing, playbook adoption and lessons learned from real incidents.
Detection Engineering & Automation
Own and mature detection engineering capabilities across SIEM, SOAR, EDR, NDR, XDR, identity, cloud, SaaS and other critical security telemetry sources.
Translate threat intelligence, incident lessons learned, threat hunting outcomes and MITRE ATT&CK techniques into actionable detection use cases and response logic.
Lead the detection lifecycle, including use case design, prioritization, validation, tuning, false-positive reduction, coverage assessment and retirement of ineffective detections.
Drive SOC automation through SOAR playbooks, automated enrichment, triage support, case management workflows, containment actions and repeatable response processes.
Identify telemetry and logging gaps, prioritize onboarding of critical data sources and improve visibility across enterprise, cloud and identity environments.
Partner with SOC analysts, incident responders, threat hunters, platform owners and managed service providers to continuously improve detection coverage, response speed and operational efficiency.
Crisis Readiness, Communication & Stakeholder Coordination
Lead cyber crisis coordination during major incidents, ensuring timely updates, clear business impact assessment and effective engagement with senior stakeholders.
Prepare and deliver incident briefings, executive summaries, situation reports and post-incident reports for technical and non-technical audiences.
Partner with legal, privacy, communications, risk, compliance and business continuity teams when incidents require broader enterprise coordination.
Plan and support cyber incident exercises, tabletop simulations and readiness assessments to validate response capabilities and decision-making.
Ensure incident response activities are aligned with internal governance, regulatory expectations and established security policies.
Qualifications:
Minimum 8 years of experience in security operations, cyber defence, incident response or related cybersecurity roles.
Strong hands-on experience leading or coordinating high-severity cyber incidents in complex enterprise environments.
Deep understanding of SOC operations, alert triage, escalation management, incident handling, threat detection and response workflows.
Experience with SIEM, SOAR, EDR, NDR, XDR, identity security, cloud security monitoring and managed security service providers.
Strong understanding of incident response frameworks and methodologies such as NIST, ISO 27035, SANS/PICERL and MITRE ATT&CK.
Ability to communicate clearly during incidents, including concise executive updates, technical coordination and post-incident reporting.
Proven ability to drive continuous improvement across people, process, tooling, governance and operational performance.
Relevant bachelor’s or master’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or equivalent practical experience.
Relevant certifications are considered an advantage, such as CISSP, GCIH, GCIA, GCFA, GSEC, OSCP, CEH, Microsoft Security certifications or cloud security certifications.
Where you'll be:
This is a position based at our Global Headquarters in Stockholm (Sweden).
We are proud of our culture of inclusivity and diversity. At our Global Headquarters we have 60+ nationalities working together for our common goals. You will be part of this dynamic international team where English is the natural language.
We work in a hybrid set up that gives everyone up to 20% flexibiltiy to work remotely, while boosting creatvity and collaboration through regular office presence.
Our recruitment process may include interviews, assessments, and reference checks. As part of our recruitment process, a background check may be conducted on the final candidate(s). Any checks will be carried out in accordance with applicable laws and with the candidate's knowledge and consent.
We look forward to receiving your application!
As part of Electrolux, we will continuously invest in you and your development. There are no barriers to where your career could take you.