
Staff Cybersecurity Specialist – Incident Response
Posted 6 days ago

Posted 6 days ago
This is a fully remote position, open to applicants in Belgium.
• Lead incident response efforts from the investigation phase through to recovery.
• Serve as the technical lead during investigations, coordinating response activities and driving results.
• Conduct forensic investigations to establish the scope of attacks, identify root causes, and assess impacts.
• Provide support to customers during active cybersecurity incidents, delivering clear technical advice.
• Assist with Managed Detection and Response (MDR) and Security Operations tasks when not actively involved in incident responses.
• Collaborate with internal and external stakeholders, including management, legal counsel, law enforcement, and regulatory bodies as necessary.
• Mentor junior and mid-level responders, enhancing the technical capabilities of the team.
• Lead strategic initiatives for improvement and influence the future direction of incident response and security operations.
• Contribute to the ongoing enhancement of incident response methodologies, playbooks, and operational processes.
• Engage in internal research projects, Bug Bounty Fridays, Capture The Flag events, and other technical initiatives.
• Report directly to the Director of Security Operations.
• Over 6 years of experience in cybersecurity, with substantial hands-on involvement in Incident Response, Digital Forensics, Security Operations, or related fields.
• Demonstrated capability to independently lead and manage cybersecurity incidents from start to finish.
• Comprehensive knowledge of Windows, Linux, and macOS operating systems, including file systems, security architecture, and attack vectors.
• Strong understanding of enterprise infrastructure, networking, and principles of network security.
• Experience with Endpoint Detection and Response (EDR) platforms such as CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne, or comparable technologies.
• Familiarity with cloud environments and security concepts across Microsoft 365, Azure, AWS, or Google Cloud.
• Strong investigative and analytical abilities, with experience in collecting and analyzing evidence during security incidents.
• Capable of conveying technical findings clearly to both technical and non-technical audiences.
• Experience in mentoring or coaching fellow security professionals.
• Excellent ownership, collaboration, and communication skills.
• Proficiency in English (the internal working language).
• C2 proficiency in Dutch (mandatory for client interactions).
• Nice-to-have: Experience in developing scripts, tools, or automations to aid investigations and response efforts.
• Nice-to-have: Experience in conducting technical security research.
• Nice-to-have: Familiarity with threat actors and their tactics, techniques, and procedures (TTPs).
• Nice-to-have: Experience working in a CERT, CSIRT, MDR, or DFIR setting.
• Applicants must possess a residence permit allowing work for any employer in the country of application, or be an EU/EEA citizen with unrestricted work rights.
• A meaningful mission: safeguarding organizations across Europe from real-world cyber threats.
• Collaborate with top-tier professionals from national CERTs, intelligence agencies, and leading technology sectors.
• A remote-friendly culture with quarterly gatherings and annual company retreats in destinations like Spain, Portugal, and Italy.
• Thursday socials to foster connections.
• A generous time-off policy that includes wellbeing and volunteering days.
Integrity360
Rackspace Technology
Efficient Computer
Presidio
Get handpicked remote jobs straight to your inbox weekly.