← Back to jobs

Remote job

Incident Response & DFIR Lead

Other Full-time Permanent Europe

Job details

Not specified Salary
Europe Eligibility
Lead Experience
Full-time Employment

About this role

Role overview Lead the incident response and digital forensics function for a fintech organization, owning the full lifecycle from detection through recovery. This full-time position combines hands-on forensic investigation with team leadership, acting as Incident Commander for major security events and driving continuous improvement in detection and response capabilities.

Responsibilities - Serve as Incident Commander during major security incidents, assigning roles, owning timelines, and coordinating across IAM, platform, IT, security engineering, and product teams - Direct evidence collection and forensic analysis to reconstruct attack paths across endpoints, servers, identities, cloud, SaaS, and network telemetry - Design and validate containment actions such as endpoint isolation, credential rotation, session revocation, and service isolation - Coordinate eradication and recovery efforts, ensuring systems return to a trusted state and evidence is preserved for legal, HR, regulatory, and disciplinary needs - Lead post-incident reviews and root-cause analyses, tracking remediation actions with accountable owners and due dates - Mentor DFIR specialists, maintain playbooks and forensic checklists, and run incident readiness exercises - Translate investigation findings into actionable recommendations for detection engineering, IAM, and product security teams

Requirements - Strong hands-on command of the incident response lifecycle including investigation, containment, eradication, recovery, and lessons learned - Demonstrated experience leading complex incidents and coordinating multiple technical teams under pressure - Practical experience investigating endpoint, identity, server, cloud, or network compromise using EDR/XDR, SIEM, and audit logs - Ability to reconstruct attacker activity from initial access through credential abuse, persistence, privilege escalation, lateral movement, and exfiltration - Working knowledge of digital forensics, evidence preservation, forensic timelines, and chain-of-custody principles - Experience with Microsoft Entra ID or Active Directory incident investigation and understanding of Windows, Linux, and enterprise networking from an investigative perspective

Nice to have - Hands-on experience with Cortex XDR, Elastic Security, Velociraptor, KAPE, Volatility, Autopsy, Magnet, EnCase, or FTK - Cloud forensics experience in AWS or similar environments - Background investigating ransomware, BEC, insider threat, or cloud account compromise cases - Scripting ability in Python or PowerShell to support investigation and evidence processing - Certifications such as GCIH, GCFA, GCFE, GNFA, OSCP, or CISSP

Benefits and work setup - 20 paid vacation days and 10 paid sick leave days annually, plus public holidays - Medical, professional education, language learning, and wellness budgets - Fully remote work opportunity

Skills detected in the listing

PythonStakeholder ManagementAWS
Detected Sep 30, 2026
Last verified Sep 30, 2026

Hidden Jobs Access

Unlock application links

Read the full job details for free. An active Hidden Jobs Access subscription is required to open the original application link.

Weekly

FREE $6.99/week after trial
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching
  • Cancel anytime before day 7

Monthly

$35.99 $17.99 /month
  • 35% cheaper than weekly
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching

Lifetime

$99.99 $49.99 /forever
  • One-time payment
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching
Hidden Jobs gives subscribers direct access to original application links
Offer ends in 00:00:00 Your profile-fit rate expires at midnight