At Zimmer Biomet, we believe in pushing the boundaries of innovation and driving our mission forward. As a global medical technology leader for nearly 100 years, a patient's mobility is enhanced by a Zimmer Biomet product or technology every 8 seconds.
As a Zimmer Biomet team member, you will share in our commitment to providing mobility and renewed life to people around the world. To support our talent team, we focus on development opportunities, robust employee resource groups (ERGs), a flexible working environment, location specific competitive total rewards, wellness incentives and a culture of recognition and performance awards. We are committed to creating an environment where every team member feels included, respected, empowered and recognised.
What You Can Expect
Role Summary (GCC)
Incident Response Manager will lead and manage our GCC Cybersecurity Incident Response Team (CIRT). Will oversee the detection, analysis, containment, eradication, and recovery of cybersecurity incidents affecting our organization. Will work closely with IT, legal, compliance, and executive leadership to develop and enhance our incident response program while ensuring alignment with industry regulations and best practices. Supports global 24x7 cyber incident response operations from the Bangalore GCC. This role provides technical leadership during incidents, coordinates response activities across time zones, and ensures operational readiness. Will also conduct hands-on analysis and investigation of security incidents.
Work Location: Bangalore
Work Mode: Hybrid (3 Days in office)
How You'll Create Impact
Key Responsibilities
- Lead and manage the GCC Incident Response Team, providing strategic guidance, mentorship, and operational oversight.
- Act as incident commander during APAC and follow-the-sun coverage.
- Lead incident triage, investigation, containment, and recovery activities.
- Conduct in-depth technical analysis of security incidents, utilizing a variety of tools and techniques such as forensic analysis, log analysis, network traffic inspection, and endpoint monitoring.
- Mentor and train junior GCC staff on incident response methodologies, technical tools, and best practices, ensuring continuous growth and capability development within the team.
- Oversee forensic investigations and collaborate with law enforcement or external security experts as needed.
- Coordinate with SOC, Infrastructure, Cloud, Legal, and Privacy teams.
- Maintain and execute incident response playbooks.
- Support post-incident reviews and root cause analysis.
- Ensure compliance with industry standards and regulations (e.g., HIPAA, FDA cybersecurity guidelines, NIST, ISO 27001).
This is not an exhaustive list of duties or functions and might not necessarily comprise all of the essential functions.
What Makes You Stand Out
Core Competencies
- Strong communication and stakeholder management skills, with the ability to present complex security issues to non-technical audiences.
- Strong technical understanding of network security, malware analysis, and incident response procedures.
- Proven ability to apply clear critical thinking in complex, stressful situations.
- Proven ability to influence and persuade others to influence design and operational outcomes without direct-line authority.
- Strong understanding of information security technology, especially relating to SIEM tool functions.
- Ability to collaborate and build positive relationships across multiple stakeholders.
- Agile thinking and analysis that leads to win-win and innovative solutions.
- Ability to quickly and accurately triage security events and incidents to stop immediate threats.
Your Background
Technologies & Tools
- SIEM/SOAR: Microsoft Sentinel, Sophos/Secureworks Taegis
- EDR/XDR: CrowdStrike, Microsoft Defender for Endpoint
- Network: Cisco ISE, Cisco Secure Network Analytics (StealthWatch)
- Cloud: Amazon Web Services, Google Cloud Platform, Windows Azure
- ITSM: ServiceNow
Qualifications
- 6–9+ years in incident response or SOC operations
- Strong experience supporting 24x7 global security operations
- Certifications preferred: GCIH, GCFA, GCED, GSOC, CISSP
- Certifications (nice to have): SC-200, OSCP.
Physical Requirements
Travel Expectations
EOE/M/F/Vet/Disability