Manager, Dfir, Global Cyber Security Intrusion Response Team (Csirt)
Vancouver, British Columbia, Ca
Managed a team of DFIR professionals and provided several critical security services as Manager of Teck Resources’ Digital Forensics & Incident Response Team. Including but not limited to, DFIR, enterprise threat hunting, Cyber Threat Intelligence, tabletop, and purple team exercises. Hired additional staff and expanded the team to support ongoing projects.Oversaw several major projects in 2021 and beyond. Managed budgeting and timelines for all Incident Response projects: Cloud DFIR readiness (migration from GCP to Azure for core business applications), phishing response automation, onboarding of Threat Intelligence Platform, Incident Response platform migration, Cyber Threat Intelligence capability uplift project.Regularly published finish intelligence in both English and Spanish to several key stakeholders such as Teck’s Vulnerability Advisory Board, audit committee, RACE21 digital transformation project, Operational Technology staff, security awareness team, and senior leadership. Providing high value, actionable intelligence to the business to enable safe and equitable production.Led and conducted several high severity intrusion and insider threat investigations, with support of legal and HR, and across several cross functions using the National Incident Management System framework.Led a team that detected and responded to all intrusions early in the kill chain, leading to no material breaches for several years despite a high volume of financially motivated threat actors.Assess, prioritize, and mitigate risks in a complex enterprise environment consisting of on premises, cloud, operational technology, SaaS, and shadow IT infrastructure.Ability to establish high functioning teams and work in a fast-paced environment with competing priorities and stakeholders.