verified listingSign up to apply with your verified profile — no re-entering experience or references.
source · wttj·req · jb_28f233768b·listed 1w ago

Head of Cyber Defence & Incident Response

Quadient·London, England, United Kingdom·Hybrid·Full-time
Sourced listing · wttjNo salary disclosed
Posted
18 August 2026
via wttj
Type
Full-time
Arrangement
Hybrid
United Kingdom
Deadline
19 September 2026
closes in 21d
compensation · estimating
Estimating…
Sign up to see our estimate based on role, location, and seniority.
source · estimate pending

Summary

the pitch

Join Quadient, a company dedicated to supporting businesses in their digital transformation and growth journey. As the Head of Cyber Defence and Incident Response, you will lead the organization's cyber defense operations and incident response efforts. You will optimize security tooling, manage the MSSP relationship, and drive vulnerability and threat management. This is a key leadership role that reports directly to the CISO and plays a crucial part in the organization's overall crisis management plan.

Role

posted by company

Company Description

At Quadient, we support businesses of all sizes in their digital transformation and growth journey, unlocking operational efficiency with reliable, secure, and sustainable automation processes.

Our success in delivering innovation and business growth is inspired by the connections our diverse teams create every day, with our clients and each other.

It’s these connections that make Quadient such an exceptional place to grow your career, develop your skills and make a real impact – help our future-focused business lead the way in powering secure and sustainable business connections through digital and physical channels.

Job Description

 

  • The Head of Cyber Defence and Incident Response owns the organisation’s cyber defence capability across a hybrid environment (mix of on‑prem and cloud platforms), ensuring effective monitoring, detection, response and recovery.
  • Reports directly to the CISO and leads cyber defence operations (including the MSSP) and cybersecurity incident response across the organisation. This fits within the context of the broader organizational Crisis Management plan owned outside Technology.
  • A key focus is optimising security tooling (e.g., SIEM, SOAR, EDR/XDR, NDR, email security, vulnerability scanning) and driving strong vulnerability and threat management, using threat intelligence to prioritise defensive improvements.

Key Responsibilities

  • Own the incident response lifecycle (prepare, detect, analyse, contain, eradicate, recover), ensuring playbooks, tooling, and decision-making processes are in place and exercised.
  • Lead and coordinate response to security incidents, acting as incident commander where required, including stakeholder communications, forensic triage, and recovery coordination.
  • Manage the MSSP relationship end‑to‑end: service definition, SLAs/KPIs, escalation paths, continuous improvement plans, quality assurance, and commercial governance.
  • Optimise security monitoring and response tooling working across technology teams  (e.g., SIEM, SOAR, EDR/XDR, NDR, email security) including use‑case coverage, alert quality, automation, logging strategy, and operational runbooks.
  • Own the vulnerability management programme (on‑prem and cloud), including scanning coverage, prioritisation, remediation SLAs, exception handling, verification, and executive reporting.
  • Drive threat management by operationalising threat intelligence (internal and external) into defensive priorities: detection use cases, hardening actions, control uplift and proactive hunting themes.
  • Lead continuous improvement of the defence stack: rationalise tools, tune detections, improve signal quality, reduce noise, and expand automation to accelerate triage and response.
  • Establish and run a threat hunting programme using hypothesis‑driven approaches, telemetry coverage mapping, and lessons learned from incidents and red-team activity.
  • Run regular tabletop exercises and simulations (including ransomware and cloud compromise scenarios), ensuring roles, escalation paths, and technical procedures are validated and improved.Own incident response governance: severity model, on‑call and escalation processes, evidence handling, case management, and alignment to legal/regulatory obligations.
  • Define and report cyber defence metrics (e.g., MTTD/MTTR, alert volumes and precision, incident trends, vuln remediation performance, control coverage), presenting insights and recommendations to senior leadership.
  • Lead post-incident reviews and root cause analysis, ensuring lessons learned translate into measurable improvements (detections, hardening, identity controls, backups, segmentation, and training).
  • Support business continuity and crisis management processes during cyber events, contributing to executive updates and coordinated communications with Legal/Privacy and other stakeholders.
  • Maintain and improve incident response documentation and readiness (playbooks, runbooks, contact trees), and ensure training is delivered for technical responders and business stakehol
  • Communicate cyber risk and active incidents clearly to technical and non‑technical audiences, including concise executive briefings and after‑action summaries.