JustMarkets
Incident Response & DFIR Lead
Europe
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →hirly's read of this role
- Seniority
- Lead / management
- Work mode
- Remote-friendly
- First seen by hirly
- 30 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
We are inviting you, a highly motivated and results-oriented Incident Response & DFIR Lead to join our team on a full-time basis.
Our team has unique expertise in research, analysis, and product development. By relying on technical insights and a data-driven approach, we create disruptive future-defining innovations of the fin-tech industry that remain our basis for success.
Responsibilities
Lead incident response, containment and forensic coordination for confirmed security incidents
Act as Incident Commander for major security incidents within the defined authority model
Assign incident roles and maintain clear ownership of investigation, containment and recovery actions
Maintain incident timelines, evidence logs, decision logs and action tracking
Coordinate investigation across endpoints, servers, identities, cloud platforms, SaaS environments and relevant network telemetry
Direct forensic collection and analysis required to determine attack path, scope, persistence and impact
Coordinate containment actions with IAM, Platform, IT, Security Engineering, Product and other technical owners
Recommend high-impact containment decisions to the Group Manager of Cyber Defense and CISO where required
Coordinate eradication and recovery activities and ensure systems return to a sufficiently trusted state
Ensure relevant evidence is preserved for Legal, HR, regulatory, disciplinary and post-incident requirements
Maintain practical forensic and evidence-handling standards
Develop and maintain incident playbooks, forensic checklists and containment procedures
Lead post-incident reviews and root-cause analysis
Ensure post-incident remediation actions have accountable owners, due dates and follow-up
Identify telemetry, detection and forensic-readiness gaps exposed during investigations
Convert investigation findings into recommendations for Detection Engineering, IAM, Security Engineering, Product Security and other control owners
Support incident exercises and readiness testing
Develop and mentor Incident Response / DFIR Specialists
Coordinate with external forensic, incident-response or specialist providers where required
Provide concise incident updates to Cyber Defense leadership, CISO and relevant stakeholders
Requirements
Strong hands-on knowledge of the incident response lifecycle: investigation, containment, eradication, recovery and lessons learned
Experience leading complex security incidents and coordinating multiple technical teams during active response
Practical experience investigating endpoint, identity, server, cloud or network compromise using EDR/XDR, SIEM and relevant audit logs
Ability to reconstruct attacker activity, including initial access, credential abuse, persistence, privilege escalation, lateral movement, data access and exfiltration
Working knowledge of digital forensics, evidence preservation, forensic timelines and chain-of-custody principles
Experience designing and validating containment actions such as endpoint isolation, account/session revocation, credential rotation, blocking indicators, network restrictions and service isolation
Experience with Microsoft Entra ID / Active Directory incident investigation
Understanding of common incident scenarios including ransomware, malware, phishing/BEC, account takeover, cloud/SaaS compromise, data exfiltration and insider misuse
Strong understanding of Windows, Linux, identity and enterprise networking from an investigation perspective
Ability to document technical findings, timelines, evidence, assumptions and containment recommendations clearly
Will be a plus
Hands-on experience with Cortex XDR, Elastic Security or equivalent enterprise platforms
Experience investigating AWS or other cloud environments
Experience with forensic tools such as Velociraptor, KAPE, Volatility, Autopsy, Magnet, EnCase, FTK or equivalent
Experience investigating ransomware, BEC, insider-threat or cloud-account-compromise cases
Experience developing or improving incident response playbooks and containment procedures
Experience running tabletop or cyber incident exercises
Experience working with Legal, Privacy, HR or regulators during security incidents
Experience managing external DFIR or incident-response retainers
Python, PowerShell or other scripting experience useful for investigation and evidence processing
Experience in fintech, payments, brokerage, trading, banking or another regulated environment
Relevant certifications such as GCIH, GCFA, GCFE, GNFA, OSCP, CISSP or equivalent
We offer
20 paid vacation days per year
10 paid sick leave days per year
Public holidays as per the company's approved Public holiday list
Medical budget
Opportunity to work remotely
Professional education budget
Language learning budget
Wellness budget (gym membership, sports gear and related expenses)
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job