Stop applying to remote jobs that are already dead.
Every listing checked, aged honestly, expired when filled.

All listings

JustMarkets via Greenhouse

Incident Response & DFIR Lead

Europe lead
still open verified 1d ago posted 1d ago seen 2h ago
Apply at job-boards.eu.greenhouse.io

This is the employer's own posting, not a copy on a job board.

What we know

Is it still open?

Confirmed still open

Last checked 1d ago — checked against the employer's own applicant tracking system, which is the company answering directly.

We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.

Check this listing's status as JSON

How old is it?

Posted 1d ago

The date the source published, not the day we noticed it (2026-09-30). Last seen at its source 2h ago.

We have tracked this listing since 30 Sep 2026 (1 days). The employer's own board has carried it every time we have read it, most recently 2 hours ago.

Is it remote?

The listing says yes

The location field doesn't say remote, so our assessment is based on the title or the description. Read the listing before applying.

Who may apply?

Europe

The description states no restriction of its own. This is the source's own tag.

Skills named in the ad

AWSActive DirectoryIncident ManagementLinuxPythonSIEMSplunk

Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.

Carried by 1 source

The listing

We are inviting you, a highly motivated and results-oriented Incident Response & DFIR Lead to join our team on a full-time basis.

Our team has unique expertise in research, analysis, and product development. By relying on technical insights and a data-driven approach, we create disruptive future-defining innovations of the fin-tech industry that remain our basis for success.

Responsibilities

  • Lead incident response, containment and forensic coordination for confirmed security incidents
  • Act as Incident Commander for major security incidents within the defined authority model
  • Assign incident roles and maintain clear ownership of investigation, containment and recovery actions
  • Maintain incident timelines, evidence logs, decision logs and action tracking
  • Coordinate investigation across endpoints, servers, identities, cloud platforms, SaaS environments and relevant network telemetry
  • Direct forensic collection and analysis required to determine attack path, scope, persistence and impact
  • Coordinate containment actions with IAM, Platform, IT, Security Engineering, Product and other technical owners
  • Recommend high-impact containment decisions to the Group Manager of Cyber Defense and CISO where required
  • Coordinate eradication and recovery activities and ensure systems return to a sufficiently trusted state
  • Ensure relevant evidence is preserved for Legal, HR, regulatory, disciplinary and post-incident requirements
  • Maintain practical forensic and evidence-handling standards
  • Develop and maintain incident playbooks, forensic checklists and containment procedures
  • Lead post-incident reviews and root-cause analysis
  • Ensure post-incident remediation actions have accountable owners, due dates and follow-up
  • Identify telemetry, detection and forensic-readiness gaps exposed during investigations
  • Convert investigation findings into recommendations for Detection Engineering, IAM, Security Engineering, Product Security and other control owners
  • Support incident exercises and readiness testing
  • Develop and mentor Incident Response / DFIR Specialists
  • Coordinate with external forensic, incident-response or specialist providers where required
  • Provide concise incident updates to Cyber Defense leadership, CISO and relevant stakeholders

Requirements

  • Strong hands-on knowledge of the incident response lifecycle: investigation, containment, eradication, recovery and lessons learned
  • Experience leading complex security incidents and coordinating multiple technical teams during active response
  • Practical experience investigating endpoint, identity, server, cloud or network compromise using EDR/XDR, SIEM and relevant audit logs
  • Ability to reconstruct attacker activity, including initial access, credential abuse, persistence, privilege escalation, lateral movement, data access and exfiltration
  • Working knowledge of digital forensics, evidence preservation, forensic timelines and chain-of-custody principles
  • Experience designing and validating containment actions such as endpoint isolation, account/session revocation, credential rotation, blocking indicators, network restrictions and service isolation
  • Experience with Microsoft Entra ID / Active Directory incident investigation
  • Understanding of common incident scenarios including ransomware, malware, phishing/BEC, account takeover, cloud/SaaS compromise, data exfiltration and insider misuse
  • Strong understanding of Windows, Linux, identity and enterprise networking from an investigation perspective
  • Ability to document technical findings, timelines, evidence, assumptions and containment recommendations clearly

Will be a plus

  • Hands-on experience with Cortex XDR, Elastic Security or equivalent enterprise platforms
  • Experience investigating AWS or other cloud environments
  • Experience with forensic tools such as Velociraptor, KAPE, Volatility, Autopsy, Magnet, EnCase, FTK or equivalent
  • Experience investigating ransomware, BEC, insider-threat or cloud-account-compromise cases
  • Experience developing or improving incident response playbooks and containment procedures
  • Experience running tabletop or cyber incident exercises
  • Experience working with Legal, Privacy, HR or regulators during security incidents
  • Experience managing external DFIR or incident-response retainers
  • Python, PowerShell or other scripting experience useful for investigation and evidence processing
  • Experience in fintech, payments, brokerage, trading, banking or another regulated environment
  • Relevant certifications such as GCIH, GCFA, GCFE, GNFA, OSCP, CISSP or equivalent

We offer

  • 20 paid vacation days per year
  • 10 paid sick leave days per year
  • Public holidays as per the company's approved Public holiday list
  • Medical budget
  • Opportunity to work remotely
  • Professional education budget
  • Language learning budget
  • Wellness budget (gym membership, sports gear and related expenses)

Role mission

Lead incident response and containment coordination so confirmed security incidents are contained quickly, investigated effectively, supported by reliable evidence and converted into lasting security improvements.

This is a hands-on Cyber Defense leadership role. The Lead is expected to understand attacker behaviour, investigation techniques and containment trade-offs, while also coordinating technical teams and business stakeholders during significant incidents.

The role is not a general SOC management position. Its primary focus is confirmed incidents, complex investigations, containment decisions, forensic coordination and recovery to a trusted state.

Requirements hard skills

- Strong hands-on knowledge of the incident response lifecycle: investigation, containment, eradication, recovery and lessons learned.
- Experience leading complex security incidents and coordinating multiple technical teams during active response.
- Practical experience investigating endpoint, identity, server, cloud or network compromise using EDR/XDR, SIEM and relevant audit logs.
- Ability to reconstruct attacker activity, including initial access, credential abuse, persistence, privilege escalation, lateral movement, data access and exfiltration.
- Working knowledge of digital forensics, evidence preservation, forensic timelines and chain-of-custody principles.
- Experience designing and validating containment actions such as endpoint isolation, account/session revocation, credential rotation, blocking indicators, network restrictions and service isolation.
- Understanding of common incident scenarios including ransomware, malware, phishing/BEC, account takeover, cloud/SaaS compromise, data exfiltration and insider misuse.
- Strong understanding of Windows, Linux, identity and enterprise networking from an investigation perspective.
- Practical experience with EDR/XDR platforms such as Cortex XDR, CrowdStrike Falcon, Microsoft Defender or equivalent.
- Practical experience with SIEM/log platforms such as Elastic Security, Splunk, Microsoft Sentinel or equivalent.
- Ability to document technical findings, timelines, evidence, assumptions and containment recommendations clearly..

Requirements soft skills

- Strong incident leadership and decision-making under time pressure.
- Ability to coordinate technical and business stakeholders during high-impact incidents.
- Clear communication of facts, uncertainty, risk and decisions.
- Strong ownership from incident activation through remediation follow-up.
- Ability to challenge unsafe or delayed containment decisions constructively.
- Ability to mentor and develop technical responders.
- Calm and structured approach during ambiguous or rapidly changing situations.

Responsibilities

- Lead incident response, containment and forensic coordination for confirmed security incidents.
- Act as Incident Commander for major security incidents within the defined authority model.
- Assign incident roles and maintain clear ownership of investigation, containment and recovery actions.
- Maintain incident timelines, evidence logs, decision logs and action tracking.
- Coordinate investigation across endpoints, servers, identities, cloud platforms, SaaS environments and relevant network telemetry.
- Direct forensic collection and analysis required to determine attack path, scope, persistence and impact.
- Coordinate containment actions with IAM, Platform, IT, Security Engineering, Product and other technical owners.
- Recommend high-impact containment decisions to the Group Manager of Cyber Defense and CISO where required.
- Coordinate eradication and recovery activities and ensure systems return to a sufficiently trusted state.
- Ensure relevant evidence is preserved for Legal, HR, regulatory, disciplinary and post-incident requirements.
- Maintain practical forensic and evidence-handling standards.
- Develop and maintain incident playbooks, forensic checklists and containment procedures.
- Lead post-incident reviews and root-cause analysis.
- Ensure post-incident remediation actions have accountable owners, due dates and follow-up.
- Identify telemetry, detection and forensic-readiness gaps exposed during investigations.
- Convert investigation findings into recommendations for Detection Engineering, IAM, Security Engineering, Product Security and other control owners.
- Support incident exercises and readiness testing.
- Develop and mentor Incident Response / DFIR Specialists.
- Coordinate with external forensic, incident-response or specialist providers where required.
- Provide concise incident updates to Cyber Defense leadership, CISO and relevant stakeholders.

Will be a plus

- Hands-on experience with Cortex XDR, Elastic Security or equivalent enterprise platforms.
- Experience investigating AWS or other cloud environments.
- Experience with Microsoft Entra ID / Active Directory incident investigation.
- Experience with forensic tools such as Velociraptor, KAPE, Volatility, Autopsy, Magnet, EnCase, FTK or equivalent.
- Experience with memory, disk or endpoint forensic analysis.
- Experience investigating ransomware, BEC, insider-threat or cloud-account-compromise cases.
- Experience developing or improving incident response playbooks and containment procedures.
- Experience running tabletop or cyber incident exercises.
- Experience working with Legal, Privacy, HR or regulators during security incidents.
- Experience managing external DFIR or incident-response retainers.
- Python, PowerShell or other scripting experience useful for investigation and evidence processing.
- Experience in fintech, payments, brokerage, trading, banking or another regulated environment.
- Relevant certifications such as GCIH, GCFA, GCFE, GNFA, OSCP, CISSP or equivalent (preferred, not mandatory).

Apply at job-boards.eu.greenhouse.io