Назад
Company hidden
3 дня назад

Team Lead Incident Response (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
lead
Английский
c1
Страна
Netherlands/Germany/Belgium
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Team Lead Incident Response (Cybersecurity): Leading and developing an Incident Response team while coordinating ransomware and business email compromise investigations, forensic work, and client communication with an accent on hands-on DFIR leadership, service quality, and major-incident command. Focus on managing complex cases, improving reporting and automation workflows, and scaling playbooks, tooling, and operational processes.

Location: Hybrid roles in The Hague, Belgium, and Berlin

Company

hirify.global provides cybersecurity and embedded cyber insurance solutions for organisations across Europe, combining 24/7 detection and response with hands-on incident response for SMEs.

What you will do

  • Lead, coach, and develop the Incident Response team through regular one-to-ones, feedback, and performance conversations.
  • Personally lead complex or high-profile ransomware, business email compromise, and other major incidents when required.
  • Own end-to-end incident response delivery, including intake, coordination, technical execution, client communication, closure, and reporting.
  • Manage delivery KPIs, on-call and case-lead rostering, workload allocation, and escalation during high-severity incidents.
  • Set reporting quality standards, conduct peer reviews, and improve incident response playbooks, tooling, SOPs, and automation.
  • Represent Incident Response in discussions with SOC, Prevention, Product, Customer Success, Engineering, and Legal.

Requirements

  • 6+ years of hands-on incident response or digital forensics experience with current expertise in DFIR methodology, EDR platforms, cloud security, and attacker TTPs.
  • Proven ability to personally run complex investigations and take over active cases when necessary.
  • Experience leading or supervising technical teams in high-pressure, time-critical environments, with a strong focus on coaching and development.
  • Strong incident-report writing, quality-review skills, judgement under pressure, and clear communication with clients and stakeholders.
  • Fluent English and Dutch required for client-facing work.

Nice to have

  • Experience in a CERT, CSIRT, MDR, or DFIR-focused environment.
  • Experience with legal or regulatory exposure in incident cases.
  • Scripting and automation experience applied to investigation workflows.
  • Familiarity with NIS2, ISO 27001, or GDPR.

Culture & Benefits

  • Full-time work in the Security Operations department.
  • Work closely with cybersecurity, engineering, customer, product, and legal functions.
  • Support organisations across Europe through 24/7 detection, response, and hands-on incident handling.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →