JD.COM
Cyber Defense Security Manager

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
About the Role
You will lead high-impact incidents and investigations, drive continuous improvements in defense, detection and response capabilities, and help scale security operations through automation and intelligent workflows. Operating within a 24/7 global environment (follow the sun model), you will own the full incident lifecycle end-to-end - from detection and triage through containment, eradication, and recovery - while partnering cross-functionally to strengthen Joybuy's overall security posture. A key aspect of this role is leveraging automation and AI-driven approaches to improve detection fidelity, accelerate investigations, and reduce response times. You will help shape how modern tooling and data are applied to stay ahead of evolving adversary tactics. This role is ideal for someone who thrives in high-tempo environments, brings strong Digital Forensics and Incident Response (DFIR) expertise, and is equally passionate about operational excellence and building scalable detection and response systems and workflows.
Responsibilities
- Lead and coordinate end-to-end incident response for high-severity security events within a 24/7 global on-call model, with this role operating during EMEA business hours
- Prepare clear executive communications that keep stakeholders informed during incidents
- Investigate complex security incidents across cloud environments, applying strong DFIR methodologies
- Build and enhance automation and AI-assisted workflows to improve triage, investigation speed, and response consistency
- Partner with Threat Intelligence to contextualize threats and improve detection coverage
- Conduct root cause analysis (RCA) and lead post-incident reviews to drive continuous improvement and risk reduction
- Develop and maintain runbooks, playbooks, and operational documentation
- Mentor other engineers and help elevate the team’s overall incident response maturity
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Qualifications
- Strong experience in security incident response and investigations in cloud-first environments
- Hands-on experience with SIEM, EDR, and/or detection engineering
- Experience with cloud platforms (AWS & GCP)
- Familiarity with threat intelligence and adversary tactics (e.g., MITRE ATT&CK)
- Experience building or working with automation (e.g., Python, scripting, SOAR platforms)
- Ability to operate effectively during high-severity incidents
- Excellent written communication skills with a passion for clear, actionable documentation
- Growth mindset with a proactive approach to identifying and mitigating security risks


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Required Skills
- Strong experience in security incident response and investigations in cloud-first environments
- Hands-on experience with SIEM, EDR, and/or detection engineering
- Experience with cloud platforms (AWS & GCP)
- Familiarity with threat intelligence and adversary tactics (e.g., MITRE ATT&CK)
- Experience building or working with automation (e.g., Python, scripting, SOAR platforms)
- Ability to operate effectively during high-severity incidents
- Excellent written communication skills with a passion for clear, actionable documentation
- Growth mindset with a proactive approach to identifying and mitigating security risks
Preferred Skills
- Certifications in offensive security, security engineering, cyber defense, or cloud platforms
- Demonstrable experience building and deploying agentic AI workflows to support detection, response, and remediation
- Experience in security competitions, Capture the Flags (CTFs) or testing platforms such as Hack The Box, TryHackMe, Overthewire, JD SRC
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location