About this role
Richemont, one of the world leaders in the luxury sector, has various Houses specializing in jewelry, watches and high-end accessories. Each Maison proudly embodies a tradition of style, quality and craftsmanship and Richemont strives to preserve the heritage and identity specific to each of them. At the same time, we are committed to innovating and designing new products in line with the values of our Houses, through a process of permanent creativity.
Take the lead on our most complex cyber incidents and help shape the next level of our detection and response capability.
HOW WILL YOU MAKE AN IMPACT?
As a Senior Associate / Technical Lead, Cybersecurity Incident Response, you will operate at the Level 3 (L3) layer of our Cybersecurity Incident Response function and act as a key technical escalation point for complex, high-impact, and unusual cybersecurity incidents affecting the Group and its Maisons.
You will lead advanced investigations across endpoint, network, identity, cloud, email, and application environments, working closely with Cyber Security, IT, Infrastructure, Cloud, Identity, Risk, Legal, and other relevant teams to understand the scope, root cause, attack techniques, and potential impact of cybersecurity incidents.
During significant incidents, you may act as the technical incident lead, providing direction on investigation, containment, remediation, and recovery activities.
Beyond incident response, you will help strengthen our overall detection and response capability through proactive threat hunting, detection enhancement, forensic analysis, automation, and continuous improvement of our tools, playbooks, and investigation processes.
You will also play an important role in maintaining the technical quality of our Cybersecurity Incident Response service by reviewing complex investigations, validating findings and conclusions, identifying investigation gaps, and helping ensure that incident cases are complete, evidence-based, technically accurate, and consistently documented.
As a senior technical reference within the team, you will support and mentor L1 and L2 analysts, provide hands-on guidance during challenging investigations, and share your experience through case reviews, technical training, and knowledge-sharing activities.
In this role, you will:
- Act as the L3 technical escalation point for complex and high-impact cybersecurity incidents.
- Lead advanced incident investigations and determine attack scope, root cause, attacker techniques, affected assets, identities, and potential business impact.
- Perform advanced analysis across endpoint, network, identity, cloud, email, and application telemetry.
- Lead technical incident response activities, including investigation, containment, eradication, remediation, and recovery recommendations.
- Perform advanced forensic analysis, including evidence collection, timeline reconstruction, endpoint analysis, and suspicious file analysis.
- Lead proactive and hypothesis-driven threat hunting activities based on emerging threats, threat intelligence, and attacker behaviours.
- Develop, enhance, and technically validate security detections across SIEM, EDR/XDR, identity, cloud, network, and other security platforms.
- Translate incident and threat hunting findings into improved detections, monitoring coverage, investigation procedures, and response capabilities.
- Perform technical quality reviews of L1 and L2 investigations, including investigation approach, evidence, scope assessment, conclusions, escalation decisions, and recommended actions.
- Review significant incident cases and reports to ensure findings are complete, technically accurate, evidence-based, and aligned with established investigation standards.
- Identify recurring investigation or quality gaps and help improve playbooks, SOPs, documentation standards, analyst training, and investigation methodologies.
- Support threat intelligence, purple-team, and threat-informed defence activities to improve detection and response effectiveness.
- Develop or support scripts, queries, SOAR workflows, and automation to improve investigation efficiency.
- Provide technical guidance, mentoring, and hands-on support to L1 and L2 analysts.
- Contribute to Cyber Security projects and initiatives with implications for Incident Response, threat detection, and security operations.
HOW WILL YOU EXPERIENCE SUCCESS WITH US?
You will be successful in this role if you combine strong hands-on technical investigation skills with the ability to lead complex investigations, challenge assumptions, maintain high investigation standards, and communicate clearly with both technical and non-technical stakeholders.
You will bring:
- Typically 5–8+ years of relevant cybersecurity experience, including hands-on experience in Security Operations, Incident Response, Threat Hunting, Digital Forensics, or related disciplines.
- Advanced knowledge of networking, operating systems, identity, cloud environments, and enterprise infrastructure.
- Strong experience investigating attacker techniques such as credential access, privilege escalation, persistence, defence evasion, lateral movement, command and control, and data exfiltration.
- Strong practical experience analysing endpoint, network, identity, cloud, email, and application telemetry and correlating activity across multiple data sources.
- Practical experience with digital forensic investigation techniques, including evidence collection, timeline analysis, endpoint artefacts, suspicious file analysis, and root cause analysis.
- Strong hands-on experience with security technologies such as SIEM, SOAR, EDR/XDR, IDS/IPS, NDR, mail security, identity security, and cloud security platforms.
- Experience developing, improving, or validating security detections, investigation queries, threat hunting methodologies, and response procedures.
- Strong understanding of attacker tactics, techniques, and procedures, including practical use of frameworks such as MITRE ATT&CK.
- Experience using analytics and investigation languages such as SPL, KQL, SQL, or equivalent.
- Experience with scripting or automation using Python, PowerShell, Bash, or equivalent would be an advantage.
- The ability to independently investigate ambiguous, unfamiliar, or technically complex cybersecurity incidents where established playbooks may not provide the full answer.
- Strong technical quality-assurance skills, with the ability to review investigations critically, identify gaps, and ensure conclusions are supported by evidence.
- Strong analytical, problem-solving, and communication skills.
- Experience providing technical guidance, mentoring, or support to less experienced analysts.
- Experience working in a large, multinational, or distributed enterprise environment would be a strong advantage.
- Excellent proficiency in English. Additional languages would be an asset.
Relevant industry certifications such as CISSP, GCIH, GCIA, GCFA, GCFE, GNFA, GREM, GCTI, OSCP, SC-200, or equivalent qualifications would be considered a strong asset.
WHAT MAKES OUR GROUP DIFFERENT?
Our true power does not lie in our similarities but in the rich diversity of our arts, cultures, and human skills, as well as our specific ability to foster untapped potential.
- We value freedom, collegiality, loyalty, and solidarity.
- We foster empathy, curiosity, courage, humility, and integrity.
- We care for the world we live in.
YOUR JOURNEY WITH US
Our recruitment process is designed to give both you and the team an opportunity to understand whether the role is the right fit.
You can expect the process to include:
- An initial conversation with our Talent Acquisition team to understand your experience, motivation, and expectations.
- An interview with the Hiring Manager to discuss the role, team, Cybersecurity Incident Response operating model, and your previous experience.
- A technical interview or practical discussion with members of the Cyber Security team, focused on areas such as incident investigation, threat hunting, detection, forensic analysis, and how you would approach complex security scenarios.
- A final conversation with relevant stakeholders to discuss team fit, ways of working, and the broader organisation.
Throughout the process, you will have the opportunity to learn more about the team, the challenges we are solving, and how this L3 technical leadership role contributes to strengthening our Cybersecurity Incident Response capability.
#Richemont #WeCraftTheFuture