hirly

JustMarkets

Incident Response & DFIR Lead

Europe

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at JustMarkets first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

hirly's read of this role

Seniority
Lead / management
Work mode
Remote-friendly
First seen by hirly
30 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

We are inviting you, a highly motivated and results-oriented Incident Response & DFIR Lead to join our team on a full-time basis.

Our team has unique expertise in research, analysis, and product development. By relying on technical insights and a data-driven approach, we create disruptive future-defining innovations of the fin-tech industry that remain our basis for success.

Responsibilities

Lead incident response, containment and forensic coordination for confirmed security incidents

Act as Incident Commander for major security incidents within the defined authority model

Assign incident roles and maintain clear ownership of investigation, containment and recovery actions

Maintain incident timelines, evidence logs, decision logs and action tracking

Coordinate investigation across endpoints, servers, identities, cloud platforms, SaaS environments and relevant network telemetry

Direct forensic collection and analysis required to determine attack path, scope, persistence and impact

Coordinate containment actions with IAM, Platform, IT, Security Engineering, Product and other technical owners

Recommend high-impact containment decisions to the Group Manager of Cyber Defense and CISO where required

Coordinate eradication and recovery activities and ensure systems return to a sufficiently trusted state

Ensure relevant evidence is preserved for Legal, HR, regulatory, disciplinary and post-incident requirements

Maintain practical forensic and evidence-handling standards

Develop and maintain incident playbooks, forensic checklists and containment procedures

Lead post-incident reviews and root-cause analysis

Ensure post-incident remediation actions have accountable owners, due dates and follow-up

Identify telemetry, detection and forensic-readiness gaps exposed during investigations

Convert investigation findings into recommendations for Detection Engineering, IAM, Security Engineering, Product Security and other control owners

Support incident exercises and readiness testing

Develop and mentor Incident Response / DFIR Specialists

Coordinate with external forensic, incident-response or specialist providers where required

Provide concise incident updates to Cyber Defense leadership, CISO and relevant stakeholders

Requirements

Strong hands-on knowledge of the incident response lifecycle: investigation, containment, eradication, recovery and lessons learned

Experience leading complex security incidents and coordinating multiple technical teams during active response

Practical experience investigating endpoint, identity, server, cloud or network compromise using EDR/XDR, SIEM and relevant audit logs

Ability to reconstruct attacker activity, including initial access, credential abuse, persistence, privilege escalation, lateral movement, data access and exfiltration

Working knowledge of digital forensics, evidence preservation, forensic timelines and chain-of-custody principles

Experience designing and validating containment actions such as endpoint isolation, account/session revocation, credential rotation, blocking indicators, network restrictions and service isolation

Experience with Microsoft Entra ID / Active Directory incident investigation

Understanding of common incident scenarios including ransomware, malware, phishing/BEC, account takeover, cloud/SaaS compromise, data exfiltration and insider misuse

Strong understanding of Windows, Linux, identity and enterprise networking from an investigation perspective

Ability to document technical findings, timelines, evidence, assumptions and containment recommendations clearly

Will be a plus

Hands-on experience with Cortex XDR, Elastic Security or equivalent enterprise platforms

Experience investigating AWS or other cloud environments

Experience with forensic tools such as Velociraptor, KAPE, Volatility, Autopsy, Magnet, EnCase, FTK or equivalent

Experience investigating ransomware, BEC, insider-threat or cloud-account-compromise cases

Experience developing or improving incident response playbooks and containment procedures

Experience running tabletop or cyber incident exercises

Experience working with Legal, Privacy, HR or regulators during security incidents

Experience managing external DFIR or incident-response retainers

Python, PowerShell or other scripting experience useful for investigation and evidence processing

Experience in fintech, payments, brokerage, trading, banking or another regulated environment

Relevant certifications such as GCIH, GCFA, GCFE, GNFA, OSCP, CISSP or equivalent

We offer

20 paid vacation days per year

10 paid sick leave days per year

Public holidays as per the company's approved Public holiday list

Medical budget

Opportunity to work remotely

Professional education budget

Language learning budget

Wellness budget (gym membership, sports gear and related expenses)

Original posting on JustMarkets's site ↗

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job