Senior Security Incident Responder
Core
Lead technical authority for handling complex, high-impact, business-critical security incidents across WPP, executing detection, analysis, containment, and recovery.
Role type
Senior Security Incident Responder (Lead IC)
Builds
Incident response outcomes, forensic evidence, audit-ready documentation, and improved response playbooks.
Domain
Cybersecurity / Incident Response / Forensics
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Advanced incident detection and analysis, deep technical expertise in SIEM/SOAR/EDR/XDR, forensic investigation and root cause analysis, incident command/escalation, MITRE ATT&CK familiarity, playbook maturity and continuous improvement
Preferred skills
Experience acting as incident commander, mentorship of responders, automation opportunity identification
Technologies
SIEM, SOAR, EDR/XDR, identity platforms, email security, cloud telemetry, MITRE ATT&CK
Responsibilities
Lead investigations for high-severity security incidents, execute containment/eradication/recovery actions, serve as primary escalation point, coordinate with Legal/Privacy/Risk/Operations, provide technical updates to stakeholders, lead forensic evidence collection, improve incident response playbooks, support post-incident reviews, mentor responders
Seniority
Senior, hands-on IC with mentorship responsibilities