All jobs
A

Cyber Defence Expert - Incident Management & Response

Aktiebolaget Electrolux
Sweden· IT-säkerhetsansvarig August 19, 2026
Browse all Sweden jobs
Applying to this role?

Tailor your resume to this exact posting and check it against the ATS — free.

Key skills & keywords for this role

These are the terms most likely to matter to the ATS for this Cyber Defence Expert - Incident Management & Response role at Aktiebolaget Electrolux. Mirror the ones that match your real experience on your resume to improve your match score.

IncidentResponseCyberSecuritydetectionSOCManagementoperationalincidentscloudtriageescalation

About the role

Solve complex problems. Decode the future. At Electrolux Group, as a leading global appliance company, we strive every day to shape living for the better for our consumers, our people and our planet. We share ideas and collaborate so that together, we can develop solutions that deliver enjoyable and sustainable living. Come join us as you are. We believe diverse perspectives make us stronger and more innovative. In our global community of people from 100+ countries, we listen to each other, actively contribute, and grow together. Join us in our exciting quest to build the future home. All about the role: We are looking for a highly experienced Cyber Defense Expert to act as a Incident Management and Response subject matter expert while leading the operational maturity and effectiveness of the Security Operations Center. The role is accountable for driving strong incident lifecycle management, from detection, triage, escalation and containment through eradication, recovery, executive communication and lessons learned. What you'll do: Incident Management & Response Leadership Lead end-to-end cyber incident response activities across detection, triage, analysis, containment, eradication, recovery and closure. Act as incident commander or senior response lead for high-severity cyber incidents, ensuring clear ownership, decision-making, escalation and communication. Design, maintain and continuously improve incident response frameworks, playbooks, severity models, escalation paths and operating procedures. Coordinate technical investigations across SOC, infrastructure, cloud, endpoint, identity, network, application and third-party teams. Drive post-incident reviews, root cause analysis, corrective actions and measurable improvements to reduce recurrence and improve response effectiveness. SOC Leadership & Operational Excellence Lead and mature SOC operations, including alert triage quality, investigation standards, escalation discipline, response workflows and service performance. Define and track SOC metrics, SLAs, KPIs and executive reporting related to detection, response, backlog, false positives, incident trends and operational effectiveness. Provide operational governance for managed SOC providers, ensuring clear accountability, quality assurance, continuous improvement and alignment with cyber defence objectives. Improve detection-to-response processes by strengthening SIEM, SOAR, EDR, NDR, XDR, identity and cloud security workflows. Support analyst enablement through guidance, process clarity, knowledge sharing, playbook adoption and lessons learned from real incidents. Detection Engineering & Automation Own and mature detection engineering capabilities across SIEM, SOAR, EDR, NDR, XDR, identity, cloud, SaaS and other critical security telemetry sources. Translate threat intelligence, incident lessons learned, threat hunting outcomes and MITRE ATT&CK techniques into actionable detection use cases and response logic. Lead the detection lifecycle, including use case design, prioritization, validation, tuning, false-positive reduction, coverage assessment and retirement of ineffective detections. Drive SOC automation through SOAR playbooks, automated enrichment, triage support, case management workflows, containment actions and repeatable response processes. Identify telemetry and logging gaps, prioritize onboarding of critical data sources and improve visibility across enterprise, cloud and identity environments. Partner with SOC analysts, incident responders, threat hunters, platform owners and managed service providers to continuously improve detection coverage, response speed and operational efficiency. Crisis Readiness, Communication & Stakeholder Coordination Lead cyber crisis coordination during major incidents, ensuring timely updates, clear business impact assessment and effective engagement with senior stakeholders. Prepare and deliver incident briefings, executive summaries, situation reports and post-incident reports for technical and non-technical audiences. Partner with legal, privacy, communications, risk, compliance and business continuity teams when incidents require broader enterprise coordination. Plan and support cyber incident exercises, tabletop simulations and readiness assessments to validate response capabilities and decision-making. Ensure incident response activities are aligned with internal governance, regulatory expectations and established security policies. Qualifications: Minimum 8 years of experience in security operations, cyber defence, incident response or related cybersecurity roles. Strong hands-on experience leading or coordinating high-severity cyber incidents in complex enterprise environments. Deep understanding of SOC operations, alert triage, escalation management, incident handling, threat detection and response workflows. Experience with SIEM, SOAR, EDR, NDR, XDR, identity security, cloud security monitoring and managed security service providers. Strong understanding of incident response frameworks and methodologies such as NIST, ISO 27035, SANS/PICERL and MITRE ATT&CK. Ability to communicate clearly during incidents, including concise executive updates, technical coordination and post-incident reporting. Proven ability to drive continuous improvement across people, process, tooling, governance and operational performance. Relevant bachelor’s or master’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or equivalent practical experience. Relevant certifications are considered an advantage, such as CISSP, GCIH, GCIA, GCFA, GSEC, OSCP, CEH, Microsoft Security certifications or cloud security certifications. Where you'll be: This is a position based at our Global Headquarters in Stockholm (Sweden). We work in a hybrid set up that gives everyone up to 20% flexibiltiy to work remotely, while boosting creatvity and collaboration through regular office presence. Our recruitment process may include interviews, a
Apply on jobtechse Posting aggregated by WeZoom · applications happen on the source site.