Senior Manager, Global Cyber Incident Response
This job is brought to you by Jobs/Redefined, the UK's leading over-50s age inclusive jobs board.
Job description
Connect to your Industry
Deloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world. In this truly global environment, we operate not in "what is" but rather "what can be" to help Deloitte deliver and connect with its clients, its communities, and one another in ways not previously conceived.
Connect to your career at Deloitte
Deloitte drives progress. Using our vast range of expertise, we help our clients' become leaders wherever they choose to compete. To do this, we invest in outstanding people. We build teams of future thinkers, with diverse talents and backgrounds, and empower them all to reach for and achieve more.
What brings us all together at Deloitte? It's how we approach the thousands of decisions we make every day. How we behave, our beliefs and our attitudes. In other words: our values. Whatever we do, wherever we are in the world, we lead the way, serve with integrity, take care of each other , foster inclusion, and collaborate for measurable impact. These five shared values lead every decision we make and action we take, guiding us to deliver impact how and where it matters most .
Connect to your opportunity
Global Cyber Incident Response (GCIR) establishes the structure by which the collective Deloitte network responds to cybersecurity incidents as a cohesive global response team. This Senior Manager role will lead the Malware Reverse Engineering capability within GCIR. This role requires a proven track record of building and scaling high-performing security teams while delivering cutting-edge threat analysis capabilities. The ideal candidate will combine strategic leadership acumen with hands-on technical mastery, capable of translating complex threat landscapes into actionable business intelligence for C-suite executives while advancing malware research and incident response capabilities.
Key Responsibilities
- Team Leadership & Strategy
- Lead and expand a global team of malware reverse engineers, software developers and cloud security architects
- Implement operational models to provide 24/7 threat analysis and incident response capabilities
- Develop comprehensive professional development programs and advanced training curricula for team skill enhancement
- Drive strategic planning for malware research initiatives and threat intelligence operations
- Present threat landscape assessments and security recommendations to executive leadership and client C-suites
Technical Leadership & Innovation
- Architect and implement next-generation malware analysis automation pipelines integrated with EDR platforms
- Lead development of Infrastructure as Code (IaC) solutions for scalable security operations across AWS, Azure, and Google Cloud
- Oversee advanced malware reverse engineering projects targeting APT campaigns, novel threats, and zero-day exploits
- Direct software development initiatives creating state-of-the-art detection tools using AI/ML and transformer models
- Design and deploy sophisticated sandbox environments and deception frameworks for threat research
Client Engagement & Incident Response
- Lead complex incident response engagements for high-profile clients experiencing advanced persistent threats
- Develop automated incident response playbooks and security orchestration workflows
- Produce executive-level threat intelligence reports on emerging malware families and APT campaigns
- Collaborate with detection engineering teams to enhance EDR capabilities and close security gaps
- Support large-scale digital forensics investigations and breach response activities
Connect to your skills and professional experience
Education & Certifications
- Bachelor's degree, or equivalent, in relevant technical field (Master's degree preferred)
- Professional security management certification strongly desirable, such as the Certified Information Systems Security Professional (CISSP)
- Advanced malware analysis certifications (Hex-Rays IDA Pro, SANS SEC595 or equivalent)
Technical Expertise
- Malware Analysis Mastery: Expert-level proficiency in x86-64 & ARM64 assembly, reverse engineering across PE, ELF, Mach-O formats
- Advanced Tooling: Deep expertise with IDA Pro, Hex-Rays, Ghidra, x64dbg, WinDbg, GDB, and Time Travel Debugging
- Evasion Techniques: Proven ability to defeat anti-debugging, anti-VM, and advanced evasion mechanisms
- Development Skills: Strong programming capabilities in C/C++ and Python for tool development and automation
- Cloud Architecture: Hands-on experience with AWS services (EC2, S3, Lambda, VPC, SQS, SNS, DynamoDB)
- DevOps & Automation: Proficiency in CI/CD pipelines, Docker, Terraform, CloudFormation, and infrastructure automation
Leadership Experience
- Relevant experience in cybersecurity with including experience in leadership roles
- Demonstrated success managing technical teams with multiple direct reports
- Experience performing cyber incident response and reverse engineering in large enterprise environments
- Proven track record in both on-premises and cloud security operations
Specialized Skills
- Advanced knowledge of APT tactics, techniques, and procedures (TTPs)
- Experience with rootkit and bootkit analysis, kernel-mode debugging
- Proficiency in YARA rule development and automated IOC extraction
- Understanding of banking malware, ransomware, and targeted attack methodologies
- Experience with threat intelligence platforms and information sharing protocols
Preferred Qualifications
- Experience with SMT-based binary program analysis and advanced static analysis techniques
- Background in Windows kernel internals and rootkit detection mechanisms
- Familiarity with ARM64 architecture and mobile malware analysis
- Experience with threat hunting and proactive security operations
- Previous consulting experience with Fortune 500 clients
- Publications or speaking engagements in cybersecurity conferences
Connect to your business - Enabling Functions
Collaboration is central to everything we do at Deloitte. From IT to HR, marketing and more, our teams help to support the wider business in everything they do. Bringing your individual skills and specialist knowledge, you can make a far-reaching impact. Come join us.
Personal independence
Regulation and controls are standard practice in our industry and Deloitte is no exception. These controls provide important legal protection for both you and the firm. We are subject to a number of audit regulations, one of which requires that certain colleagues abide by specific personal independence constraints (e.g., in relation to any financial interests and employment relationships). This can mean that you and your "Immediate Family Members" are not permitted to hold certain financial interests (shares, funds, bonds etc.) with audit clients of the firm, and also prohibitions on certain employment relationships (e.g., you are not permitted to hold a secondary employment role with SEC audit clients of the firm whilst being employed by the firm). The recruitment team will provide further detail as you progress through the recruitment process or you can contact the Independence team upon request.
Connect with your colleagues
"Everyone at Deloitte builds relationships with their peers and puts in effort to get to know one another, making the work more enjoyable."
Our hybrid working policy
You'll be based in one of our UK locations with hybrid working.
At Deloitte we understand the importance of balancing your career alongside your home life. That's why we'll support you to work flexibly through our hybrid working policy. Depending on the requirements of your role, you'll have the opportunity to work in your local office, virtual collaboration spaces, client sites and remotely. You'll get the chance to meet face to face when needed, while you collaborate and learn from colleagues, share your experiences, and build the relationships that will fuel your career and prioritise your wellbeing. Please check with your recruiter for the specific working requirements that may apply for your role.
Our commitment to you
Making an impact is more than just what we do: it's why we're here. So we work hard to create an environment where you can experience a purpose you believe in, the freedom to be you, and the capacity to go further than ever before.
We want you. The true you. Your own strengths, perspective and personality. So we're nurturing a culture where everyone belongs, feels supported and heard, and is empowered to make a valuable, personal contribution. You can be sure we'll take your wellbeing seriously, too. Because it's only when you're comfortable and at your best that you can make the kind of impact you, and we, live for.
Your expertise is our capability, so we'll make sure it never stops growing. Whether it's from the complex work you do, or the people you collaborate with, you'll learn every day. Through world-class development, you'll gain invaluable technical and personal skills. Whatever your level, you'll learn how to lead.
Connect to your next step
A career at Deloitte is an opportunity to develop in any direction you choose. Join us and you'll experience a purpose you can believe in and an impact you can see. You'll be free to bring your true self to work every day. And you'll never stop growing, whatever your level .
Discover more reasons to connect with us, our people and purpose-driven culture at deloitte.co.uk/careers
WPFULL SLICSS BAGLOB LOCOFFICE