Cyber Incident Response Manager

Nottingham Trent House (95002), United Kingdom, Nottingham, Nottinghamshire

At Capital One, we're building a leading information-based technology company. Still founder-led by Chairman and Chief Executive Officer Richard Fairbank, Capital One is on a mission to help our customers succeed by bringing ingenuity, simplicity, and humanity to banking. We measure our efforts by the success our customers enjoy and the advocacy they exhibit. We are succeeding because they are succeeding.

Guided by our shared values, we thrive in an environment where collaboration and openness are valued. We believe that innovation is powered by perspective and that teamwork and respect for each other lead to superior results. We elevate each other and obsess about doing the right thing. Our associates serve with humility and a deep respect for their responsibility in helping our customers achieve their goals and realize their dreams. Together, we are on a quest to change banking for good.

Cyber Incident Response Manager

Capital One is committed to diversity in the workplace.

Capital One is hiring for a seasoned Cyber Security professional to respond to cybersecurity incidents which have the potential to impact the confidentiality, integrity, or availability of Capital One information assets.

Your mission is to investigate, scope, contain and remediate any malicious activity that makes it past our defences, and recommend solutions that increase the ability to automatically detect or respond to malicious events. You will be expected to identify and investigate compromise across multiple platforms and technologies, including on premise and cloud environments. You will be required to provide regular communication across the Cybersecurity division, to include the CISO and CIO.

In addition to the technical skills, you will need to be a leader, someone who enjoys training and mentoring teammates, and a person who can encourage and elevate the team.

You will be responsible for driving escalated investigations to conclusion, for initiating your own investigations to locate malicious activity, and for delivering improvements to the defensive posture of the organisation.

The Cyber Incident Response Manager ensures effective investigation of cybersecurity incidents through the following:

  • Proactively investigate active intrusions in the Capital One environment, recognising potential, successful, and unsuccessful intrusion attempts and compromises
  • Respond to escalated security threats from Cybersecurity Operations Centre (CSOC)
  • Support day-to-day cybersecurity threat detection and incident response operations
  • Identify and contribute to continual improvements in incident response processess
  • Collaborate with, and act as technical escalation point for, CSOC and Cyber Threat Intelligence (CTI) teams
  • Communicate deep technical security threat & operations awareness across the Cybersecurity division, to include the CISO and CIO
  • Benchmark Incident Response (IR) processes and technology against industry
  • Maintain detailed documentation to support IR processes, tools and functions
  • Support the Cybersecurity Incident Management team in developing key performance indicators to measure success of the IR team
  • Coordinate with all Information Security Officer teams in clarifying security risks, and roles and responsibilities related to ongoing Incident Response cases
  • Provide support to operational & cybersecurity strategy development
  • Identify and recommend new technologies and/or processes to enhance Cybersecurity and IR operations
  • Utilize industry recognized frameworks such as NIST 800-61 to perform and document work activities
  • Develop and maintain 'playbooks' for operational Incident Response workflows
  • Identify opportunities where automation has the potential to improve operations
  • Perform root cause analysis and identify appropriate measures to minimise future impact

Basic Qualifications:
  • Extensive technical experience in a Security Operations Centre or supporting an IR team, ideally in a global enterprise organisation, including hands-on experience in:
  • Conducting Cybersecurity investigations into network and application activity
  • Analysing common application and network-based attacks
  • Working with *nix and Windows operating systems
  • Interpreting, and identifying abuse in, routed and routing protocols and application traffic
  • Coordinating and supporting incident handling and remediation
  • Leveraging core security and infrastructure technologies during investigations (e.g. firewall logs, network security tools, malware detonation devices, proxies, IPS/IDS)
  • Carrying out PCAP analysis, including extracting files and content from PCAPs, identifying gzipped content, and base64 detection
  • Network Management and Monitoring Tools and Utilities
  • Enterprise Network Security / Security Perimeters
  • TCP/IP protocols
  • Packet capture devices, syslog, netflow, application performance Management
  • Cyber threat analysis and mitigations
  • Very strong technical skills using a variety of security tools (i.e. argus, wireshark, tcpdump, snort, helix, encase, volatility, powershell, python, etc)
  • Ability to manage multiple simultaneous responsibilities
  • Strong ability to analyse information and data
  • Excellent problem-solving and conceptual thinking abilities, especially with technical troubleshooting
  • Very strong ability to develop and communicate recommendations to non-technical associates in business areas
  • Very strong and effective process management skills
  • At least 2 of the following recognized industry certifications (or equivalent); CEH, CISSP, GCFA, GCFE, GCIA, GCIH, GISP, GNFA, GREM, Security+

Preferred Qualifications:
  • Bachelors/Masters Degree in fields such as Computer Science, Information Systems, and Engineering or equivalent experience
  • Very strong communication skills with the ability to manage responsibilities across multiple areas and projects
  • Very strong collaborative partnership skills for working with various points of contacts internal and external to Capital One
  • Proven experience conducting Cyber Security investigations in Cloud environments

Capital One is committed to diversity in the workplace.

If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1-800-304-9102 or via email at All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.

For technical support or questions about Capital One's recruiting process, please send an email to

Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.

Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).

Meet Some of Capital One's Employees

Ryan P.

Head Of Design

Ryan and his team of designers and developers work at The Shop, a combined technology workshop and retail hub, to create meaningful financial products and services.

Erika D.

Information Security Officer

Erika monitors and upholds Capital One’s strong security requirements across technical operations—and teaches employees risk management methods to protect its financial products and projects.

Back to top