Cyber Security Incident Response (CSIRT) Specialist

bp


Date: 21 hours ago
City: Sunbury-on-Thames
Contract type: Full time
Our purpose is to deliver energy to the world, today and tomorrow. For over 100 years, bp has focused on discovering, developing, and producing oil and gas in the nations where we operate. We are one of the few companies globally that can provide governments and customers with an integrated energy offering. Delivering our strategy sustainably is fundamental to achieving our ambition to be a net zero company by 2050 or sooner!

The Cyber Security Incident Response Team (CSIRT), part of Counter Threat & Engineering (CT&E), responds to digital security threats and incidents globally from bp hubs in Houston, Sunbury, Kuala Lumpur, Pune, and Singapore. The Security Operations Center (SOC) raises incidents to CSIRT, which conducts long-term investigations using digital forensics, advanced techniques, and collaborating across bp. Team members must understand bp’s business segments and address a broad range of security-related questions. You will help ensure enterprise security, enabling safe and secure business operations as part of this global team.

Key Accountabilities

  • Support the bp SOC as an escalation point for security events and incidents.
  • Conduct digital forensic investigations on high-priority incidents to include functions such as host (disk and memory) forensics, network forensics and log analysis.
  • Work across Digital Security and the bp business functions to partner on incidents and to ensure all appropriate actions are being actioned and communicated
  • Conduct advanced threat hunting by using threat intelligence and the MITRE ATT&CK framework to proactively identify suspicious activity in the environment.
  • Ensure data accuracy within the case management system and others.
  • When not actively responding to incidents, other key responsibilities within the role include development of documentation and processes such as playbooks, refining your skills through training opportunities and identifying and enhancing the capabilities of the team by developing opportunities for automation (i.e., custom scripts and tool integration)

Essential Education

Bachelor's degree (e.g., Information Security, Network Security, Information Assurance, Information Technology, Computer Science) or equivalent experience and/or qualifications.

Essential Experience And Job Requirements

  • Experience with attacker tactics, techniques and procedures (TTP’s)
  • Knowledge of both Windows and Linux operating systems to conduct host-based forensics and analysis
  • Knowledge of cloud platforms such as AWS and Azure
  • Experience with many different types of log sources such as firewall, web and database to identify anomalous activity
  • Understand network communications and protocols
  • Knowledge of SIEM, EDR and other core cyber toolsets
  • Strong problem-solving skills as applied to technical solutions
  • Sound technical knowledge of security as applied to IT/OT networks, systems, and applications
  • Ability to communicate effectively and document investigative findings in a clear and concise manner

Leadership and EQ

  • You embrace a culture of change and agility, evolving continuously, adapting to our changing world.
  • You are an effective teammate, looking beyond your own area/organizational boundaries to consider the bigger picture and/or perspective of others, while understanding cultural differences
  • You continually enhance your self-awareness and seek input from others on your impact and effectiveness
  • Well organized, you balance proactive and reactive approaches and multiple priorities to complete tasks on time
  • You apply judgment and common sense – you use insight and good judgment to inform actions and respond to situations as they arise
  • You align with BP's Code of Conduct and demonstrate strong leadership through BP's Leadership Expectations and Values & Behaviours

Desirable criteria

  • COMPTIA Security+ / CYSA+ CASP+
  • SANS Certification GSOC; GCIH; GCFA; GCFE; GCFR
  • CISSP Certification and accreditation
  • Certified Ethical Hacker - CEH
  • Cisco Certifications (CCNA or similar)
  • Similar/ higher certifications

Additional Information

bp has embarked on an ambitious plan to modernize and transform as an integrated energy company, using digital technologies to drive efficiency, effectiveness, and new business models. The CSIRT is part of our wider CT&E team that is responsible for protecting bp against cyber threats. This post will be in Sunbury. This role requires 60% of the work week in our local bp offices while up to 40% can be remote. This role also requires the successful candidate be on an on-call Rota several times throughout the year. At bp, we support our people to learn and grow in a diverse and challenging environment.

We are an equal opportunity employer and value diversity at our company. We do not discriminate based on race, religion, colour, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, perform crucial job functions, and receive other benefits and privileges of employment. Don’t hesitate to get in touch with us to request any accommodations.

How to apply

To apply for this job you need to authorize on our website. If you don't have an account yet, please register.

Post a resume

Similar jobs

Cell Lead- Test and Shared Services

AMETEK, Sunbury-on-Thames
5 days ago
Scope Of RoleWorking closely with the Production Manager, Planners and Cell Leaders, to take ownership for scheduling work through the cell area of responsibility and provide leadership for the people in that area. To be responsible for monitoring manufacturing performance against agreed SQCDP metrics using best practice. To take responsibility for organising and providing where necessary all required training within...

Duty Manager

Places for People, Sunbury-on-Thames
2 weeks ago
We are Places for People Group, we're a social enterprise that believes it's people that make a community. That's why we build homes and deliver services for everyone in the community to thrive. At Places Leisure we are changing lives by creating active places and healthy people for communities to thrive, and we want to be the UK's leading health...

Network Services Engineer

Kinly, Sunbury-on-Thames
£35,000 - £45,000 per year
4 weeks ago
Role: AV IT Engineer / Integrated Network Services EngineerLocation: Sunbury-on-Thames, UK (Kinly operate a hybrid working policy allowing for a mix of home/office working)Salary: Negotiable (depending on experience), plus large company benefits and personal development opportunitiesInterview Process: 2 Stage; with one virtual and one face to faceHours: Monday – Friday: 9am – 5.30 pm (with some flexibility available)Kinly is a...