Senior Incident Response Consultant (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Incident Response Consultant (Cybersecurity): Leading complex digital forensics and incident response (DFIR) investigations and building organizational readiness strategies with an accent on cloud artifacts and threat actor TTPs. Focus on conducting large-scale investigations, designing customized IR playbooks, and guiding containment and recovery efforts in enterprise environments.
Location: Remote (Romania)
Company
is a leading cybersecurity provider specializing in Managed Detection and Response (MDR) and Security Operations.
What you will do
- Lead large-scale, complex DFIR investigations across host, network, and cloud environments to determine root causes.
- Review incident response plans, identify gaps, and develop tailored strategies to strengthen preparedness.
- Design and deliver customized IR playbooks and facilitate training sessions for customers.
- Coordinate containment, remediation, and recovery efforts to secure environments post-incident.
- Lead tabletop exercises, drills, and functional simulations to evaluate response readiness.
- Brief senior leadership and technical teams on findings, risks, and strategic recommendations.
Requirements
- Must be based in Romania.
- 8–12 years of experience in cybersecurity, with a focus on incident response and readiness.
- Expertise in forensic tools (EDR, log analysis, malware analysis) and enterprise environments including Windows, Linux, Azure, AWS, and M365.
- Deep understanding of attacker Tactics, Techniques, and Procedures (TTPs) and modern detection strategies.
- Willingness to travel up to 20%, including on short notice, for on-site engagements.
- Ability to lead cross-functional teams and maintain an authoritative presence during high-pressure incidents.
Nice to have
- Relevant certifications such as GIAC, CISSP, or CISM.
Culture & Benefits
- Full remote work arrangement within Romania.
- Permanent employment contract.
- Participation in a 24x7 emergency response rotation.
- Opportunity to work with high-profile incidents and advanced threat intelligence.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →