3 дня назад
Team Lead Incident Response (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Team Lead Incident Response (Cybersecurity): Leading and developing an Incident Response team while coordinating ransomware and business email compromise investigations, forensic work, and client communication with an accent on hands-on DFIR leadership, service quality, and major-incident command. Focus on managing complex cases, improving reporting and automation workflows, and scaling playbooks, tooling, and operational processes.
Location: Hybrid roles in The Hague, Belgium, and Berlin
Company
provides cybersecurity and embedded cyber insurance solutions for organisations across Europe, combining 24/7 detection and response with hands-on incident response for SMEs.
What you will do
- Lead, coach, and develop the Incident Response team through regular one-to-ones, feedback, and performance conversations.
- Personally lead complex or high-profile ransomware, business email compromise, and other major incidents when required.
- Own end-to-end incident response delivery, including intake, coordination, technical execution, client communication, closure, and reporting.
- Manage delivery KPIs, on-call and case-lead rostering, workload allocation, and escalation during high-severity incidents.
- Set reporting quality standards, conduct peer reviews, and improve incident response playbooks, tooling, SOPs, and automation.
- Represent Incident Response in discussions with SOC, Prevention, Product, Customer Success, Engineering, and Legal.
Requirements
- 6+ years of hands-on incident response or digital forensics experience with current expertise in DFIR methodology, EDR platforms, cloud security, and attacker TTPs.
- Proven ability to personally run complex investigations and take over active cases when necessary.
- Experience leading or supervising technical teams in high-pressure, time-critical environments, with a strong focus on coaching and development.
- Strong incident-report writing, quality-review skills, judgement under pressure, and clear communication with clients and stakeholders.
- Fluent English and Dutch required for client-facing work.
Nice to have
- Experience in a CERT, CSIRT, MDR, or DFIR-focused environment.
- Experience with legal or regulatory exposure in incident cases.
- Scripting and automation experience applied to investigation workflows.
- Familiarity with NIS2, ISO 27001, or GDPR.
Culture & Benefits
- Full-time work in the Security Operations department.
- Work closely with cybersecurity, engineering, customer, product, and legal functions.
- Support organisations across Europe through 24/7 detection, response, and hands-on incident handling.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
3 дня назад
Senior Security Engineer - SecOps
68 000 - 91 000€
7 дней назад
Cyber Security Analyst (Microsoft Sentinel)
3 дня назад
Senior Security Engineer - SecOps
66 000 - 88 000€
3 дня назад
Senior Security Engineer (SecOps)
56 000 - 74 000€
3 дня назад
Director, Security Operations (Security Engineering)
8 дней назад