hirq
← All jobs

JustMarkets

Incident Response & DFIR Lead

Europe · Remote · Security

Apply well, not just fast

Create a free account and upload your resume to get a match score, keyword gaps, a tailored resume, a cover letter and interview prep for this job.

About the role

Incident ResponseIAMPythonAWSLinuxSIEM
We are inviting you, a highly motivated and results-oriented Incident Response & DFIR Lead to join our team on a full-time basis. Our team has unique expertise in research, analysis, and product development. By relying on technical insights and a data-driven approach, we create disruptive future-defining innovations of the fin-tech industry that remain our basis for success. Responsibilities - Lead incident response, containment and forensic coordination for confirmed security incidents - Act as Incident Commander for major security incidents within the defined authority model - Assign incident roles and maintain clear ownership of investigation, containment and recovery actions - Maintain incident timelines, evidence logs, decision logs and action tracking - Coordinate investigation across endpoints, servers, identities, cloud platforms, SaaS environments and relevant network telemetry - Direct forensic collection and analysis required to determine attack path, scope, persistence and impact - Coordinate containment actions with IAM, Platform, IT, Security Engineering, Product and other technical owners - Recommend high-impact containment decisions to the Group Manager of Cyber Defense and CISO where required - Coordinate eradication and recovery activities and ensure systems return to a sufficiently trusted state - Ensure relevant evidence is preserved for Legal, HR, regulatory, disciplinary and post-incident requirements - Maintain practical forensic and evidence-handling standards - Develop and maintain incident playbooks, forensic checklists and containment procedures - Lead post-incident reviews and root-cause analysis - Ensure post-incident remediation actions have accountable owners, due dates and follow-up - Identify telemetry, detection and forensic-readiness gaps exposed during investigations - Convert investigation findings into recommendations for Detection Engineering, IAM, Security Engineering, Product Security and other control owners - Support incident exercises and readiness testing - Develop and mentor Incident Response / DFIR Specialists - Coordinate with external forensic, incident-response or specialist providers where required - Provide concise incident updates to Cyber Defense leadership, CISO and relevant stakeholders Requirements - Strong hands-on knowledge of the incident response lifecycle: investigation, containment, eradication, recovery and lessons learned - Experience leading complex security incidents and coordinating multiple technical teams during active response - Practical experience investigating endpoint, identity, server, cloud or network compromise using EDR/XDR, SIEM and relevant audit logs - Ability to reconstruct attacker activity, including initial access, credential abuse, persistence, privilege escalation, lateral movement, data access and exfiltration - Working knowledge of digital forensics, evidence preservation, forensic timelines and chain-of-custody principles - Experience designing and validating containment actions such as endpoint isolation, account/session revocation, credential rotation, blocking indicators, network restrictions and service isolation - Experience with Microsoft Entra ID / Active Directory incident investigation - Understanding of common incident scenarios including ransomware, malware, phishing/BEC, account takeover, cloud/SaaS compromise, data exfiltration and insider misuse - Strong understanding of Windows, Linux, identity and enterprise networking from an investigation perspective - Ability to document technical findings, timelines, evidence, assumptions and containment recommendations clearly Will be a plus - Hands-on experience with Cortex XDR, Elastic Security or equivalent enterprise platforms - Experience investigating AWS or other cloud environments - Experience with forensic tools such as Velociraptor, KAPE, Volatility, Autopsy, Magnet, EnCase, FTK or equivalent - Experience investigating ransomware, BEC, insider-threat or cloud-account-compromise cases - Experience developing or improving incident response playbooks and containment procedures - Experience running tabletop or cyber incident exercises - Experience working with Legal, Privacy, HR or regulators during security incidents - Experience managing external DFIR or incident-response retainers - Python, PowerShell or other scripting experience useful for investigation and evidence processing - Experience in fintech, payments, brokerage, trading, banking or another regulated environment - Relevant certifications such as GCIH, GCFA, GCFE, GNFA, OSCP, CISSP or equivalent We offer - 20 paid vacation days per year - 10 paid sick leave days per year - Public holidays as per the company's approved Public holiday list - Medical budget - Opportunity to work remotely - Professional education budget - Language learning budget - Wellness budget (gym membership, sports gear and related expenses)