Skip to content
← Back to job listings

Incident Response & DFIR Lead

JustMarkets · Remote

CybersecurityRemoteImported listingfull-timeabout 20 hours ago

About The Role

<p>We are inviting you, a highly motivated and results-oriented <strong>Incident Response & DFIR Lead</strong> to join our team on a full-time basis.</p>
<p>Our team has unique expertise in research, analysis, and product development. By relying on technical insights and a data-driven approach, we create disruptive future-defining innovations of the fin-tech industry that remain our basis for success.</p>
<p><strong>Responsibilities</strong></p>
<ul>
<li>Lead incident response, containment and forensic coordination for confirmed security incidents</li>
<li>Act as Incident Commander for major security incidents within the defined authority model</li>
<li>Assign incident roles and maintain clear ownership of investigation, containment and recovery actions</li>
<li>Maintain incident timelines, evidence logs, decision logs and action tracking</li>
<li>Coordinate investigation across endpoints, servers, identities, cloud platforms, SaaS environments and relevant network telemetry</li>
<li>Direct forensic collection and analysis required to determine attack path, scope, persistence and impact</li>
<li>Coordinate containment actions with IAM, Platform, IT, Security Engineering, Product and other technical owners</li>
<li>Recommend high-impact containment decisions to the Group Manager of Cyber Defense and CISO where required</li>
<li>Coordinate eradication and recovery activities and ensure systems return to a sufficiently trusted state</li>
<li>Ensure relevant evidence is preserved for Legal, HR, regulatory, disciplinary and post-incident requirements</li>
<li>Maintain practical forensic and evidence-handling standards</li>
<li>Develop and maintain incident playbooks, forensic checklists and containment procedures</li>
<li>Lead post-incident reviews and root-cause analysis</li>
<li>Ensure post-incident remediation actions have accountable owners, due dates and follow-up</li>
<li>Identify telemetry, detection and forensic-readiness gaps exposed during investigations</li>
<li>Convert investigation findings into recommendations for Detection Engineering, IAM, Security Engineering, Product Security and other control owners</li>
<li>Support incident exercises and readiness testing</li>
<li>Develop and mentor Incident Response / DFIR Specialists</li>
<li>Coordinate with external forensic, incident-response or specialist providers where required</li>
<li>Provide concise incident updates to Cyber Defense leadership, CISO and relevant stakeholders</li>
</ul>
<p><strong>Requirements</strong></p>
<div class="sc-eWidsO cXpNwe">
<div class="sc-fueQRQ jYYoIc">
<ul>
<li>Strong hands-on knowledge of the incident response lifecycle: investigation, containment, eradication, recovery and lessons learned</li>
<li>Experience leading complex security incidents and coordinating multiple technical teams during active response</li>
<li>Practical experience investigating endpoint, identity, server, cloud or network compromise using EDR/XDR, SIEM and relevant audit logs</li>
<li>Ability to reconstruct attacker activity, including initial access, credential abuse, persistence, privilege escalation, lateral movement, data access and exfiltration</li>
<li>Working knowledge of digital forensics, evidence preservation, forensic timelines and chain-of-custody principles</li>
<li>Experience designing and validating containment actions such as endpoint isolation, account/session revocation, credential rotation, blocking indicators, network restrictions and service isolation</li>
<li>Experience with Microsoft Entra ID / Active Directory incident investigation</li>
<li>Understanding of common incident scenarios including ransomware, malware, phishing/BEC, account takeover, cloud/SaaS compromise, data exfiltration and insider misuse</li>
<li>Strong understanding of Windows, Linux, identity and enterprise networking from an investigation perspective</li>
<li>Ability to document technical findings, timelines, evidence, assumptions and containment recommendations clearly</li>
</ul>
</div>
</div>
<p><strong>Will be a plus</strong></p>
<ul>
<li>Hands-on experience with Cortex XDR, Elastic Security or equivalent enterprise platforms</li>
<li>Experience investigating AWS or other cloud environments</li>
<li>Experience with forensic tools such as Velociraptor, KAPE, Volatility, Autopsy, Magnet, EnCase, FTK or equivalent</li>
<li>Experience investigating ransomware, BEC, insider-threat or cloud-account-compromise cases</li>
<li>Experience developing or improving incident response playbooks and containment procedures</li>
<li>Experience running tabletop or cyber incident exercises</li>
<li>Experience working with Legal, Privacy, HR or regulators during security incidents</li>
<li>Experience managing external DFIR or incident-response retainers</li>
<li>Python, PowerShell or other scripting experience useful for investigation and evidence processing</li>
<li>Experience in fintech, payments, brokerage, trading, banking or another regulated environment</li>
<li>Relevant certifications such as GCIH, GCFA, GCFE, GNFA, OSCP, CISSP or equivalent</li>
</ul>
<p><strong>We offer</strong></p>
<ul>
<li>20 paid vacation days per year</li>
<li>10 paid sick leave days per year</li>
<li>Public holidays as per the company's approved Public holiday list</li>
<li>Medical budget</li>
<li>Opportunity to work remotely</li>
<li>Professional education budget</li>
<li>Language learning budget</li>
<li>Wellness budget (gym membership, sports gear and related expenses)</li>
</ul>

This is an external listing. JobSpring does not represent or verify the employer. Report this listing