Incident Response & DFIR Lead

New
J
JustMarketsCybersecurity
Location: EuropeFull-TimeLead
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Required Skills
Linux

Requirements

  • Strong hands-on knowledge of the incident response lifecycle, including investigation, containment, eradication, recovery and lessons learned.
  • Experience leading complex security incidents and coordinating multiple technical teams during active response.
  • Practical experience investigating endpoint, identity, server, cloud or network compromise using EDR/XDR, SIEM and relevant audit logs.
  • Ability to reconstruct attacker activity, including initial access, credential abuse, persistence, privilege escalation, lateral movement, data access and exfiltration.
  • Working knowledge of digital forensics, evidence preservation, forensic timelines and chain-of-custody principles.
  • Experience designing and validating containment actions such as endpoint isolation, account or session revocation, credential rotation, indicator blocking, network restrictions and service isolation.
  • Understanding of ransomware, malware, phishing/BEC, account takeover, cloud/SaaS compromise, data exfiltration and insider misuse.
  • Strong understanding of Windows, Linux, identity and enterprise networking from an investigation perspective.
  • Ability to document technical findings, timelines, evidence, assumptions and containment recommendations clearly.
  • Experience with Microsoft Entra ID / Active Directory incident investigation.

Responsibilities

  • Lead incident response, containment and forensic coordination for confirmed security incidents.
  • Act as Incident Commander for major incidents and assign roles and ownership for investigation, containment and recovery.
  • Maintain incident timelines, evidence logs, decision logs and action tracking.
  • Coordinate investigations across endpoints, servers, identities, cloud platforms, SaaS environments and network telemetry.
  • Direct forensic collection and analysis to determine attack path, scope, persistence and impact.
  • Coordinate containment, eradication and recovery actions with technical owners and ensure systems return to a sufficiently trusted state.
  • Preserve relevant evidence and maintain forensic and evidence-handling standards.
  • Lead post-incident reviews and ensure remediation actions have owners, due dates and follow-up.
  • Develop incident playbooks, forensic checklists and containment procedures; identify telemetry and forensic-readiness gaps.
  • Develop and mentor Incident Response / DFIR Specialists and provide incident updates to leadership and stakeholders.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now