Responsibilities
This position is critical to protecting Haleon’s corporate assets and managing its day-to-day operational cyber security defences. It involves the proactive, in-depth analysis of sophisticated threat actors in order to develop and implement countermeasures. It requires an understanding of the adversary’s tactics, techniques and procedures at a deep, technical level, moving beyond traditional security monitoring. The primary goal is to shift the company’s security posture from reactive defence to proactive, adversary‑centric operations.
- Define and execute threat hunts to search for undetected malicious activity within the organisation’s IT and OT environments.
- Develop hypotheses, methodologies and tooling to proactively search for indicators of compromise (IOCs) and indicators of attack (IOAs) that evade automated defences.
- Support Red team activities that simulate realistic, multi‑layered attacks against the organisation’s people, processes and technology, thereby rigorously testing the effectiveness of the Security Operations / Cyber Incident Response Teams.
- Detect and neutralise advanced threats in the early stages of the kill chain, minimising breach impact and improving overall organisational resilience.
- Support the tuning of all security tooling and the development of bespoke correlation rules / use cases aligned to business operations, internal risk profiles and current threat intelligence. Define high‑fidelity detection signatures, behavioural analytics, and security control policies to specifically counter known and emerging adversary tactics.
- Be a key member of the Cyber Incident Response Team (CIRT) during major cyber incidents.
- Establish and maintain relationships with other investigation and remediation teams within the company, working closely with them to address the full spectrum of security issues.
- Undertake efforts in developing security awareness training for the broader organisation.
- Tackle complex, evolving cybersecurity challenges requiring innovation and adaptability.
- Make high‑stakes decisions under pressure, balancing rapid response with thorough investigation.
- Collaborate with Threat Intelligence to groom threat feeds and help translate findings.
Required Skills and Experience
- Three years in cybersecurity, with some experience of responding to significant cyber incidents involving Organised Crime and Nation State threat actors.
Preferred Skills and Experience
- Bachelor’s degree in Computer Science, Cyber Security or related field (or equivalent experience).
- Experience of working in a Cyber Security Operations Centre.
- Experience working across international manufacturing.
- Understanding of security controls and how they are used to detect and respond.
- Knowledge of common network protocols, edge routing technologies, firewall/IDS/IPS, SIEM, EDR/XDR.
- Ability to communicate complex problems succinctly.
- Ability to work within a team environment, sharing workload and responsibility.
- CISSP, GCIA, GCDA, GSOC, GCIH.
Equal Opportunities
Haleon are committed to mobilising our purpose in a way that represents the diverse consumers and communities who rely on our brands every day. It guides us in creating an inclusive culture, where different backgrounds and views are valued and respected – all in support of understanding and best serving the needs of our consumers and unleashing the full potential of our people. It’s important to us that Haleon is a place where all our employees feel they truly belong.
During the application process, we may ask you to share some personal information, which is entirely voluntary. This information ensures we meet certain regulatory and reporting obligations and supports the development, refinement, and execution of our inclusion and belonging programmes that are open to all Haleon employees.
The personal information you provide will be kept confidential, used only for legitimate business purposes, and will never be used in making any employment decisions, including hiring decisions.
#J-18808-Ljbffr…
