Hiring.Camp

Incident Response Lead

The Magnum Ice Cream Company Careers

·

3 days ago

Location
Pune Ice Cream Office, India
Type
Full-time
Seniority
Lead
Experience
8+ years
Closing date
Today
Source
Workday

Description

Life tastes better with ice cream

With 19.000 expert ice cream colleagues and iconic brands like Wall’s, Cornetto and Ben & Jerry’s, loved in 76 countries, we are the world’s largest Ice Cream company leading the industry.
 
We create iconic ice cream brands that are part of everyday life, bringing moments of joy to millions of people around the world. Everybody loves ice cream. And as the world’s biggest pure‑play ice cream company, we have the scale and ambition to make a real difference. 

What truly sets us apart is how we work. 

We move fast and keep things simple. We turn ideas into action, trust people to take ownership, and work as one team to win together with integrity. Our culture is high‑performance, collaborative and focused on getting things done. 

We’re curious and ready for what’s next. We embrace digital, use data to make better decisions, and keep learning, including how AI can help us work smarter and serve consumers better.  

The role

As part of our growth strategy, we are seeking a highly skilled and hands-on Incident Response Lead who will be responsible for leading TMICC's cyber incident response capability, driving continuous improvement of detection and response processes, and supporting the maturity of TMICC's Security Operations function. This role focuses on tactical security operations leadership, digital forensics and incident response (DFIR), threat detection, threat hunting, SOC optimization, malware analysis, network forensics, and operational management of TMICC's MSSP and security service providers. The successful candidate will act as the primary technical lead for cyber incident investigations and will play a key role in developing and operationalizing TMICC's global incident response and security operations capabilities. You will report directly to the Head of Security Operations and collaborate with Security Engineering, Infrastructure, Cloud Engineering, Network Services, IAM, Workplace Technology, Manufacturing Technology, MSSPs, MDR providers, and third-party service providers.

What you'll be responsible for

• Lead technical investigations of cyber security incidents across cloud, endpoint, identity, network, email, application, and OT environments.

• Coordinate containment, eradication, and recovery activities during security incidents.

• Act as incident commander for priority cyber incidents and security investigations.

• Lead digital forensic investigations across endpoints, identities, cloud environments, OT environments, and network infrastructure.

• Conduct forensic acquisition and analysis of host, network, cloud, and security telemetry evidence.

• Drive development and continuous improvement of security monitoring use cases.

• Develop, tune, and optimize detection logic across SIEM, EDR, NDR, XDR, and cloud security platforms.

• Manage operational relationships with MSSPs, MDR providers, and incident response partners.

• Monitor service performance against SLAs, KPIs, investigation quality standards, and response timelines.

• Refine and optimize SOC operating procedures, runbooks, playbooks, escalation processes, and investigation workflows.

• Conduct proactive threat hunting activities across endpoint, identity, cloud, network, email, and OT environments.

• Perform static and dynamic malware analysis and support reverse engineering activities.

• Conduct network traffic analysis, packet analysis, and network forensic investigations.

• Support development and maturation of TMICC's Operational Technology (OT) security monitoring and incident response capabilities.

• Support onboarding and operationalization of CrowdStrike, Claroty, and OT telemetry sources into global monitoring platforms.

• Develop OT-specific detection use cases, investigation procedures, and incident response playbooks.

• Coordinate cross-functional response activities involving Infrastructure, Cloud, Network, IAM, Workplace Technology, Manufacturing Technology, and third-party providers.

• Support Major Incident Management (MIM) processes during cyber security incidents.

• Conduct post-incident reviews and drive remediation of identified gaps.

We're looking for someone who

Rather than an exhaustive check list, focus on what really matters.

Education and Experience

• 8-12 years of experience in Security Operations, Incident Response, Digital Forensics, Threat Hunting, or Cyber Defense roles. • Proven experience leading complex cyber incident investigations within enterprise environments. • Strong hands-on experience with Microsoft Sentinel, Defender XDR, Defender for Endpoint, Defender for Identity, and cloud-native security tooling. • Experience managing MSSP, MDR, SOC, or incident response service providers. • Experience conducting digital forensic investigations across endpoint, cloud, identity, network, and OT environments. • Experience developing detection content, use cases, and threat hunting methodologies. • Experience with malware analysis and reverse engineering techniques. • Experience supporting OT security monitoring, OT incident response, or industrial cyber security initiatives is highly desirable. • Experience with CrowdStrike, Claroty, and enterprise detection platforms is highly desirable.

Skills and Competencies

• Deep understanding of incident response methodologies and DFIR best practices. • Strong expertise in SIEM, EDR, NDR, SOAR, XDR, and cloud security monitoring technologies. • Strong understanding of attacker tactics, techniques, and procedures (TTPs). • Experience mapping detections to MITRE ATT&CK. Strong network forensic analysis and packet analysis capabilities. • Strong stakeholder management and vendor management capabilities. • Ability to influence technical teams and drive action during high-pressure situations. • Strong communication and facilitation skills across technical and non-technical audiences. • Ability to manage competing priorities during complex security incidents. • Strong service management and operational governance capabilities. • Ability to build effective working relationships across security, infrastructure, cloud, network, manufacturing, and business teams. • Strong decision-making skills under pressure and during crisis situations.

Professional Certifications

• GCIH (preferred) • GCFA (preferred) • GREM (highly desirable) • GNFA (highly desirable) • GRID (highly desirable) • GICSP (desirable) • CISSP • SC-200 • GCIA (desirable)

You Excel At

• Leading complex cyber investigations under pressure. • Identifying attacker activity through forensic and analytical techniques. • Building high-quality detection content and threat hunting capabilities. • Improving SOC effectiveness through practical operational enhancements. • Managing MSSP and security service provider relationships effectively. • Coordinating technical teams during major cyber incidents. • Solving difficult technical problems through structured investigation and analysis. • Balancing operational urgency with investigative rigor and accuracy.

What you'll get

Alongside meaningful work and strong development, we offer a reward package that typically includes

  • Market-competitive pay and performance related rewards
  • Flexible ways of working
  • Support for health, wellbeing and life outside of work
  • Time off to rest and recharge
  • Ongoing learning and development opportunities
  • Specific benefits vary by location

#TMICC

Why join us?

This is a place for people who are passionate about ice cream and are growth obsessed - both for the business and for themselves. People who act like an owner and drive our business end-to-end. People who are driven by success to deliver more than we ever thought we could! 

You’ll thrive here if you value an inclusive culture, with low ego and hierarchy - and if you’re excited to continuously learn and challenge how we work, using digital, data, and new thinking to push us forward.

- Roles with real accountability and visible impact
- Free to move fast, experiment and challenge how things are done
- Continuous learning and development as the business grows
- Reward linked to performance and contribution.

Your career here is shaped by what you deliver, as you work across functions and markets and grow with the business.

Ready to build the future of Ice Cream?

If this sounds like the place where you'd thrive, we'd love to hear from you. Apply online and share your CV. We'll review your application and be in touch with the next steps.

If you are an individual with a disability and require assistance at any time during our recruitment process, please let your Talent Acquisition Partner know.

Additional information

The Magnum Ice Cream Company is an Equal Opportunity Employer. We embrace diversity and are committed to creating an inclusive environment where everyone can do their best work regardless of age, disability, gender identity, race, religion, sexual orientation, or any other protected characteristic.

Skills

ExcelSIEMSOCCISSP

Similar Jobs

30

Incident Response Lead

Whoop · Boston, MA · Onsite

6 days ago

Incident Response, Lead

Cook Children's · Remote - TX, United States of America +1 · Remote

1 month ago

Incident Response Lead

Adobe · Bucharest, Romania

2 months ago

Incident Response Lead

Toyota · Plano, United States of America

2 months ago

Incident Response Lead

Whoop · Boston, MA · Onsite

4 months ago

Incident Response Lead

Urban Connect · New York

4 months ago

Incident Response Lead

Vanguard · USA - Neptune, United States of America +2 · Hybrid

4 months ago

Incident Response Lead

Vanguard · USA - Neptune, United States of America +2 · Hybrid

4 months ago

Incident Response Lead Specialist, Vice President

Mufgub · Watermark - 410 North Scottsdale Road, United States of America

1 week ago

Digital Forensics & Incident Response Lead

RSI Security · Remote

2 weeks ago

Cyber Operations and Incident Response Lead

CNI Careers · MD Home Office, United States of America · Remote

2 weeks ago

Release Control and Incident Response Lead

Nbn · VIC - Melbourne - 727 Collins Street - Level 12, Australia +1

2 weeks ago

SOC / Incident Response Lead

Development InfoStructure · Bethesda, MD

3 weeks ago

NIH - Incident Response Lead

cFocus Software Incorporated · Bethesda, MD · Remote

3 weeks ago

Incident Response Lead - Remote

Strada Careers · US-NY-New York-Virtual, United States of America · Remote

4 weeks ago

CyberSecurity Engineer, Incident Response Lead

Mistral · Paris · Onsite

1 month ago

Lead Incident Response Consultant

Fortinet · Saudi Arabia · Onsite

2 months ago

Cyber Security Incident Response Lead

Nbn · VIC - Melbourne - 727 Collins Street - Level 13, Australia

2 months ago

Cybersecurity Incident Response Lead

Caa · London, United Kingdom

2 months ago

Tech Lead Incident Response (CERT/CSIRT) (F/H)

Michelinhr · Clermont-Ferrand, France · Hybrid

2 months ago

IT Security Specialist (Pre-Incident Consulting & Incident Response Lead)

Mirazon · Louisville, Kentucky

5 months ago

Cyber Security Incident Response Lead

Livenation · Work From Home - UK, United Kingdom +1 · Remote

6 months ago

Lead Incident Response Consultant

Fortinet · Saudi Arabia · Onsite

6 months ago

Senior Information Security Incident Response Lead

Nttlimited · Petaling Jaya, Malaysia

7 months ago

Senior Information Security Incident Response Lead

Nttlimited · Jakarta, Indonesia · Onsite

10 months ago

Security Incident Response Orchestration Lead

Bank Of America · Chicago, United States of America +2 · Onsite

Yesterday

Security Incident Response Orchestration Lead

Bank Of America · Chicago, United States of America +2 · Onsite

Yesterday

Technology Support Lead - Incident Management & Response (IMR)

JPMorgan Chase · Seattle, WA, United States, US

1 month ago

Technology Support Lead - Incident Management & Response (IMR)

JP Morgan Chase · Seattle, WA, United States, US

1 month ago

Incident Response Manager & Lead Threat Hunter

Bullhorn · Remote NOAM - Massachusetts, United States of America · Remote

1 month ago