Lead Incident Response

Posted 5 Days Ago
Be an Early Applicant
2 Locations
Hybrid
Senior level
Cybersecurity
The Role
Leads and develops an Incident Response team while personally handling complex cybersecurity incidents. Owns end-to-end response quality, client communication, KPIs, on-call scheduling, incident escalation, reporting QA, automation, playbooks, and cross-functional coordination. Requires deep digital forensics and incident response expertise, people-management experience, strong crisis communication, fluent English, and Dutch proficiency.
Summary Generated by Built In

About this role
We are looking for an Incident Response Lead to join our Security Operations department.

You will lead the people who own our most serious cases end to end — coordinating ransomware and business email compromise investigations, doing the forensic work, and being the person on the phone when a client needs a straight answer under real pressure.

Your first responsibility is people, not just process. You’re a first-line manager distinct from a senior individual contributor, with direct accountability for the performance and development of your team — while carrying enough hands-on DFIR credibility to run the most complex case yourself, or take over one mid-flight, when the situation demands it.


What you will do

  • Lead, coach, and develop the Incident Response team: regular one-to-ones, feedback, and performance/development conversations aligned with Eye’s career framework

  • Lead by doing: manage the caseload and the people, but personally take point on the most complex or highest-profile incidents when needed

  • Own end-to-end incident response service quality: case intake and coordination, technical execution, client communication, and closure/reporting

  • Own delivery KPIs (time-to-containment, case-report quality and timeliness, client satisfaction on incident cases) and step in to unblock the team or personally lead a case when targets are at risk

  • Manage on-call and case-lead rostering and workload across the team, prioritising by severity and client exposure

  • Act as the senior escalation point and, when needed, incident commander for major incidents — large ransomware, multi-entity BEC, or cases with legal/regulatory exposure

  • Own quality assurance for incident reporting: set the reporting standard and run structured peer review of case reports before they reach the client

  • Own and scale automation across the function’s casework (evidence collection, timeline building, reporting), partnering with engineering where it makes sense

  • Drive continuous improvement of IR playbooks, tooling, and process as case volume grows; keep runbooks and SOPs accurate and actually used

  • Represent Incident Response in cross-functional discussions with SOC, Prevention, Product, Customer Success, and Legal where relevant

What you will need

  • Technical: 6+ years of hands-on incident response / digital forensics experience with deep, current knowledge of DFIR methodology, EDR platforms, cloud security, and attacker TTPs; able to personally run a complex case, not just sign off on one

  • Leadership: composure and sound judgement under real pressure, often with incomplete information, during live incidents; strong incident-report writing and a sharp eye for reviewing others’ reports; clear, calm, authoritative communication with clients and internal stakeholders during a crisis

  • People management: proven experience leading or supervising a technical team through high-pressure, time-critical work, with a genuine interest in coaching people and helping them grow; first-line management experience or a strong informal leadership track record

  • Fluent English; Dutch (C2) required for client-facing work

Nice-to-have

  • Background in a CERT, CSIRT, MDR, or DFIR-focused environment

  • Experience handling cases with legal or regulatory exposure

  • Scripting/automation experience applied to investigation workflows

  • Familiarity with compliance frameworks relevant to SMEs (NIS2, ISO 27001, GDPR)

About Eye Security
Eye Security provides cybersecurity with embedded cyber insurance solutions for organisations across Europe. Headquartered in the Netherlands, we combine 24/7 detection and response with hands-on incident response to keep SMEs protected, and we’re growing internationally. When a client’s worst day happens, this is the team that shows up.

Skills Required

  • 6+ years of hands-on incident response and digital forensics experience
  • Deep knowledge of DFIR methodology, EDR platforms, cloud security, and attacker TTPs
  • Ability to personally lead complex incident response cases
  • Experience leading or supervising a technical team in high-pressure, time-critical work
  • First-line management experience or strong informal leadership track record
  • Strong incident-report writing and report-review skills
  • Clear, calm, authoritative communication during crises
  • Fluent English
  • Dutch proficiency for client-facing work
  • Experience in a CERT, CSIRT, MDR, or DFIR-focused environment
  • Experience handling legal or regulatory exposure cases
  • Scripting or automation experience applied to investigation workflows
  • Familiarity with NIS2, ISO 27001, and GDPR
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: 's-Gravenhage
253 Employees
Year Founded: 2020

What We Do

Eye Security protects small and medium-sized European enterprises from cyber threats and the high costs that follow after a successful attack. We are a specialized team of people with a background in intelligence services as well as commercial environments. We understand the threat landscape and the difficulties entrepreneurs face in battling cybercrime. Our goal is to unburden SME's with an affordable all-in-one service that safeguards them against threats targeted to their industry. Our service combines endpoint monitoring with awareness campaigns, a 24/7 incident response strategy and a cyber insurance. Your company, our cyber expertise. Together we keep your business running. Want to join our mission? Visit our career page: https://jobs.eye.security

Similar Jobs

Navan Logo Navan

Senior Product Manager

Fintech • Information Technology • Payments • Productivity • Software • Travel • Automation
Easy Apply
Hybrid
Berlin, DEU
3300 Employees

Benchling Logo Benchling

Account Executive

Cloud • Healthtech • Social Impact • Software • Biotech
Remote or Hybrid
27 Locations
605 Employees

Hewlett Packard Enterprise Logo Hewlett Packard Enterprise

Enterprise Account Manager

Artificial Intelligence • Cloud • Information Technology • Consulting
In-Office
4 Locations
85422 Employees

Academia.edu Logo Academia.edu

Peer Review Assistant

Consumer Web • Digital Media • Edtech • Information Technology • Social Impact • Software
Remote or Hybrid
26 Locations
110 Employees

Similar Companies Hiring

Copia Automation Thumbnail
Cybersecurity • Industrial
New York, New York
50 Employees
SEON Thumbnail
Artificial Intelligence • Cybersecurity
Budapest, Budapest
415 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account