hirly

Eye Security

Manager Incident Response

The Hague - hybrid · Berlin - hybrid · Belgium

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Eye Security first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

hirly's read of this role

Seniority
Lead / management
Countries
NL, DE, BE
Work mode
On-site / unstated
First seen by hirly
29 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

  • About this role
  • We are looking for a Team Lead Incident Response to join our Security Operations department. You will lead the people who own our most serious cases end to end — coordinating ransomware and business email compromise investigations, doing the forensic work, and being the person on the phone when a client needs a straight answer under real pressure.
  • Your first responsibility is people, not just process. You’re a first-line manager distinct from a senior individual contributor, with direct accountability for the performance and development of your team — while carrying enough hands-on DFIR credibility to run the most complex case yourself, or take over one mid-flight, when the situation demands it.

What you will do

Lead, coach, and develop the Incident Response team: regular one-to-ones, feedback, and performance/development conversations aligned with Eye’s career framework

Lead by doing: manage the caseload and the people, but personally take point on the most complex or highest-profile incidents when needed

Own end-to-end incident response service quality: case intake and coordination, technical execution, client communication, and closure/reporting

Own delivery KPIs (time-to-containment, case-report quality and timeliness, client satisfaction on incident cases) and step in to unblock the team or personally lead a case when targets are at risk

Manage on-call and case-lead rostering and workload across the team, prioritising by severity and client exposure

Act as the senior escalation point and, when needed, incident commander for major incidents — large ransomware, multi-entity BEC, or cases with legal/regulatory exposure

Own quality assurance for incident reporting: set the reporting standard and run structured peer review of case reports before they reach the client

Own and scale automation across the function’s casework (evidence collection, timeline building, reporting), partnering with engineering where it makes sense

Drive continuous improvement of IR playbooks, tooling, and process as case volume grows; keep runbooks and SOPs accurate and actually used

Represent Incident Response in cross-functional discussions with SOC, Prevention, Product, Customer Success, and Legal where relevant

What you will need

Technical: 6+ years of hands-on incident response / digital forensics experience — the same bar as Staff Incident Response Analyst — with deep, current knowledge of DFIR methodology, EDR platforms, cloud security, and attacker TTPs; able to personally run a complex case, not just sign off on one

Leadership: composure and sound judgement under real pressure, often with incomplete information, during live incidents; strong incident-report writing and a sharp eye for reviewing others’ reports; clear, calm, authoritative communication with clients and internal stakeholders during a crisis

People management: proven experience leading or supervising a technical team through high-pressure, time-critical work, with a genuine interest in coaching people and helping them grow; first-line management experience or a strong informal leadership track record

Fluent English; Dutch required for client-facing work

Nice-to-have

Background in a CERT, CSIRT, MDR, or DFIR-focused environment

Experience handling cases with legal or regulatory exposure

Scripting/automation experience applied to investigation workflows

Familiarity with compliance frameworks relevant to SMEs (NIS2, ISO 27001, GDPR)

  • About Eye Security
  • Eye Security provides cybersecurity with embedded cyber insurance solutions for organisations across Europe. Headquartered in the Netherlands, we combine 24/7 detection and response with hands-on incident response to keep SMEs protected, and we’re growing internationally. When a client’s worst day happens, this is the team that shows up.
Original posting on Eye Security's site ↗

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job