Apply Edge Start your job search

Cyber Defense Security Manager

JD.COM · London Area, United Kingdom

Apply & track with Apply Edge

About the RoleYou will lead high-impact incidents and investigations, drive continuous improvements in defense, detection and response capabilities, and help scale security operations through automation and intelligent workflows. Operating within a 24/7 global environment (follow the sun model), you will own the full incident lifecycle end-to-end - from detection and triage through containment, eradication, and recovery - while partnering cross-functionally to strengthen Joybuy's overall security posture. A key aspect of this role is leveraging automation and AI-driven approaches to improve detection fidelity, accelerate investigations, and reduce response times. You will help shape how modern tooling and data are applied to stay ahead of evolving adversary tactics. This role is ideal for someone who thrives in high-tempo environments, brings strong Digital Forensics and Incident Response (DFIR) expertise, and is equally passionate about operational excellence and building scalable detection and response systems and workflows.ResponsibilitiesLead and coordinate end-to-end incident response for high-severity security events within a 24/7 global on-call model, with this role operating during EMEA business hoursPrepare clear executive communications that keep stakeholders informed during incidentsInvestigate complex security incidents across cloud environments, applying strong DFIR methodologiesBuild and enhance automation and AI-assisted workflows to improve triage, investigation speed, and response consistencyPartner with Threat Intelligence to contextualize threats and improve detection coverageConduct root cause analysis (RCA) and lead post-incident reviews to drive continuous improvement and risk reductionDevelop and maintain runbooks, playbooks, and operational documentationMentor other engineers and help elevate the team’s overall incident response maturityQualificationsStrong experience in security incident response and investigations in cloud-first environmentsHands-on experience with SIEM, EDR, and/or detection engineeringExperience with cloud platforms (AWS & GCP)Familiarity with threat intelligence and adversary tactics (e.g., MITRE ATT&CK)Experience building or working with automation (e.g., Python, scripting, SOAR platforms)Ability to operate effectively during high-severity incidentsExcellent written communication skills with a passion for clear, actionable documentationGrowth mindset with a proactive approach to identifying and mitigating security risksRequired SkillsStrong experience in security incident response and investigations in cloud-first environmentsHands-on experience with SIEM, EDR, and/or detection engineeringExperience with cloud platforms (AWS & GCP)Familiarity with threat intelligence and adversary tactics (e.g., MITRE ATT&CK)Experience building or working with automation (e.g., Python, scripting, SOAR platforms)Ability to operate effectively during high-severity incidentsExcellent written communication skills with a passion for clear, actionable documentationGrowth mindset with a proactive approach to identifying and mitigating security risksPreferred SkillsPreferred qualificationsCertifications in offensive security, security engineering, cyber defense, or cloud platformsDemonstrable experience building and deploying agentic AI workflows to support detection, response, and remediationExperience in security competitions, Capture the Flags (CTFs) or testing platforms such as Hack The Box, TryHackMe, Overthewire, JD SRC