Skip to main content

No jobs have been saved yet.

back to home

Job Details

Job ID R65268
Nottingham Trent House (95002), United Kingdom, Nottingham, Nottinghamshire

At Capital One, we’re building a leading information-based technology company. Still founder-led by Chairman and Chief Executive Officer Richard Fairbank, Capital One is on a mission to help our customers succeed by bringing ingenuity, simplicity, and humanity to banking. We measure our efforts by the success our customers enjoy and the advocacy they exhibit. We are succeeding because they are succeeding.                                               

Guided by our shared values, we thrive in an environment where collaboration and openness are valued. We believe that innovation is powered by perspective and that teamwork and respect for each other lead to superior results. We elevate each other and obsess about doing the right thing. Our associates serve with humility and a deep respect for their responsibility in helping our customers achieve their goals and realize their dreams. Together, we are on a quest to change banking for good.

Cyber Incident Response Specialist

What do we need?

We need a seasoned Cyber Security professional who’ll respond to cybersecurity incidents which have the potential to impact the confidentiality, integrity or availability of our information assets.

Your mission is to investigate, scope, contain and remediate any malicious activity that makes it past our defences. Done that? Now recommend solutions that increase our ability to automatically detect or respond to malicious events.  You’ll identify and investigate compromise across multiple platforms and technologies, including on premise and cloud environments, and it’s up to you to communicate technical security threat and operations awareness across the Cybersecurity division, the CISO and CIO.

You’re the one who’ll drive escalated investigations to conclusion, initiate your own investigations to locate malicious activity and deliver improvements to the defensive posture of our organisation. You’ll be calling on your technical skills using a variety of security tools (i.e. argus, wireshark, tcpdump, snort, helix, encase, volatility, powershell, python, etc).

But we’re not just after you for your technical skills. You’ll be a leader;  you’ll thrive on mentoring and motivating the team - pushing them to be the best cyber professionals they can be.   You’ll have excellent problem-solving and conceptual thinking abilities, especially when it comes to technical troubleshooting. Analysing data and information is right up your street. You’ll get the importance of strong and effective process management and although you’re deeply technical, you’ll know how to develop and communicate your recommendations to not-so-technical teams across the business. You’ll get stuff done by collaborating and partnering with people and teams inside and outside the business. Oh, and you’ll be a bit of a juggler - managing multiple responsibilities across multiple areas and projects.

Who are we looking for?

If you’re right for this job, you’ll have extensive technical experience in a Security Operations Centre or supporting an IR team (ideally in a global enterprise organisation). This experience will mean you’ll be able to tell us about how you’ve:

  • Conducted Cybersecurity investigations into network and application activity

  • Analysed common application and network-based attacks

  • Worked with *nix and Windows operating systems

  • Interpreted and identified abuse in, routed and routing protocols and application traffic

  • Coordinated and supported incident handling and remediation

  • Leveraged core security and infrastructure technologies during investigations (e.g. firewall logs, network security tools, malware detonation devices, proxies, IPS/IDS)

  • Carried out PCAP analysis, including extracting files and content from PCAPs, identifying gzipped content, and base64 detection

and how familiar you are with:

  • Network Management and Monitoring Tools and Utilities

  • Enterprise Network Security / Security Perimeters

  • TCP/IP protocols

  • packet capture devices, syslog, netflow, application performance management

  • cyber threat analysis and mitigations

On top of all this, you’ll have:

  • At least 2 of the following recognized industry certifications (or equivalent); CEH, CISSP, GCFA, GCFE, GCIA, GCIH, GISP, GNFA, GREM, Security+

And finally (these aren’t critical but it’ll make us very happy if you have):

  • Bachelors/Masters Degree in fields such as Computer Science, Information Systems, and Engineering or equivalent experience

  • Proven experience conducting Cyber Security investigations in Cloud environments

If you get the job, what will you be doing?

You may already be in a job that’s pretty similar to this but here’s the lowdown on what you’ll be doing (and we can talk to you in more detail about the job spec if you apply);

  • Proactively investigating active intrusions in the Capital One environment, recognising potential, successful, and unsuccessful intrusion attempts and compromises

  • Responding to escalated security threats from Cybersecurity Operations Centre (CSOC)

  • Supporting day-to-day cybersecurity threat detection and incident response operations

  • Identifying and contributing to continual improvements in incident response processes

  • Collaborating with, and acting as technical escalation point for, CSOC and Cyber Threat Intelligence (CTI) teams

  • Communicating deep technical security threat & operations awareness across the Cybersecurity division, the CISO and CIO

  • Benchmarking Incident Response (IR) processes and technology against industry

  • Maintaining detailed documentation to support IR processes, tools and functions

  • Supporting the Cybersecurity Incident Management team in developing key performance indicators to measure success of the IR team

  • Coordinating with all Information Security Officer teams in clarifying security risks, and roles and responsibilities related to ongoing Incident Response cases

  • Providing support to operational & cybersecurity strategy development

  • Identifying and recommending new technologies and/or processes to enhance Cybersecurity and IR operations

  • Utilizing industry recognized frameworks such as NIST 800-61 to perform and document work activities

  • Developing and maintaining ‘playbooks’ for operational Incident Response workflows

  • Identifying opportunities where automation has the potential to improve operations

  • Performing root cause analysis and identifying appropriate measures to minimise future impact

What’s in it for you:

  • We are continuing our journey into the public cloud and have problems of scale, security, availability and performance for you to help solve.

  • We love continuous learning and that’s why we give you 10% of your time to work on cutting edge innovative projects that shape the way we will work in the future

  • We offer high performers strong and diverse career progression, investing heavily in developing great people through our Capital One University training programmes (and appropriate external providers)

  • Immediate access to our core benefits including pension scheme, bonus, generous holiday entitlement and private medical insurance – with flexible benefits available including season-ticket loans, cycle to work scheme and enhanced parental leave

  • Open-plan workspaces and facilities designed to inspire and support you. Our Nottingham head-office has a fully-serviced gym, subsidised restaurant, mindfulness and music rooms. In London, you can heighten your mood with a run on our rooftop running track or an espresso at the Workshop Coffee café

  • Find out more through our UK careers site ( or by exploring the @IAmCapitalOne Twitter tag.

Capital One is committed to diversity in the workplace.


Capital One is committed to diversity in the workplace.

If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1-800-304-9102 or via email at All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.

For technical support or questions about Capital One's recruiting process, please send an email to

Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.

Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).


Don’t see a role that’s right for you? Don’t fret. You can sign up for our job alerts and we’ll make sure to let you know when the right one comes up.

Interested In

  • Engineering, Nottingham, England, United KingdomRemove
  • Engineering, London, England, United KingdomRemove
  • Cyber Security & Technology Risk Management, Nottingham, England, United KingdomRemove
  • Cyber Security & Technology Risk Management, London, England, United KingdomRemove
  • Technology Explorers, Nottingham, England, United KingdomRemove
  • Technology Explorers, London, England, United KingdomRemove


No jobs have been saved yet.