Incident Response & DFIR Lead @JustMarkets
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted Today

[Hiring] Incident Response & DFIR Lead @JustMarkets

Today - JustMarkets is hiring a remote Incident Response & DFIR Lead. πŸ’Έ Salary: unspecified πŸ“Location: Europe

Role Description

We are inviting you, a highly motivated and results-oriented Incident Response & DFIR Lead to join our team on a full-time basis. Our team has unique expertise in research, analysis, and product development. By relying on technical insights and a data-driven approach, we create disruptive future-defining innovations of the fin-tech industry that remain our basis for success.

Responsibilities

  • Lead incident response, containment and forensic coordination for confirmed security incidents
  • Act as Incident Commander for major security incidents within the defined authority model
  • Assign incident roles and maintain clear ownership of investigation, containment and recovery actions
  • Maintain incident timelines, evidence logs, decision logs and action tracking
  • Coordinate investigation across endpoints, servers, identities, cloud platforms, SaaS environments and relevant network telemetry
  • Direct forensic collection and analysis required to determine attack path, scope, persistence and impact
  • Coordinate containment actions with IAM, Platform, IT, Security Engineering, Product and other technical owners
  • Recommend high-impact containment decisions to the Group Manager of Cyber Defense and CISO where required
  • Coordinate eradication and recovery activities and ensure systems return to a sufficiently trusted state
  • Ensure relevant evidence is preserved for Legal, HR, regulatory, disciplinary and post-incident requirements
  • Maintain practical forensic and evidence-handling standards
  • Develop and maintain incident playbooks, forensic checklists and containment procedures
  • Lead post-incident reviews and root-cause analysis
  • Ensure post-incident remediation actions have accountable owners, due dates and follow-up
  • Identify telemetry, detection and forensic-readiness gaps exposed during investigations
  • Convert investigation findings into recommendations for Detection Engineering, IAM, Security Engineering, Product Security and other control owners
  • Support incident exercises and readiness testing
  • Develop and mentor Incident Response / DFIR Specialists
  • Coordinate with external forensic, incident-response or specialist providers where required
  • Provide concise incident updates to Cyber Defense leadership, CISO and relevant stakeholders

Qualifications

  • Strong hands-on knowledge of the incident response lifecycle: investigation, containment, eradication, recovery and lessons learned
  • Experience leading complex security incidents and coordinating multiple technical teams during active response
  • Practical experience investigating endpoint, identity, server, cloud or network compromise using EDR/XDR, SIEM and relevant audit logs
  • Ability to reconstruct attacker activity, including initial access, credential abuse, persistence, privilege escalation, lateral movement, data access and exfiltration
  • Working knowledge of digital forensics, evidence preservation, forensic timelines and chain-of-custody principles
  • Experience designing and validating containment actions such as endpoint isolation, account/session revocation, credential rotation, blocking indicators, network restrictions and service isolation
  • Experience with Microsoft Entra ID / Active Directory incident investigation
  • Understanding of common incident scenarios including ransomware, malware, phishing/BEC, account takeover, cloud/SaaS compromise, data exfiltration and insider misuse
  • Strong understanding of Windows, Linux, identity and enterprise networking from an investigation perspective
  • Ability to document technical findings, timelines, evidence, assumptions and containment recommendations clearly

Requirements

  • Hands-on experience with Cortex XDR, Elastic Security or equivalent enterprise platforms
  • Experience investigating AWS or other cloud environments
  • Experience with forensic tools such as Velociraptor, KAPE, Volatility, Autopsy, Magnet, EnCase, FTK or equivalent
  • Experience investigating ransomware, BEC, insider-threat or cloud-account-compromise cases
  • Experience developing or improving incident response playbooks and containment procedures
  • Experience running tabletop or cyber incident exercises
  • Experience working with Legal, Privacy, HR or regulators during security incidents
  • Experience managing external DFIR or incident-response retainers
  • Python, PowerShell or other scripting experience useful for investigation and evidence processing
  • Experience in fintech, payments, brokerage, trading, banking or another regulated environment
  • Relevant certifications such as GCIH, GCFA, GCFE, GNFA, OSCP, CISSP or equivalent

Benefits

  • 20 paid vacation days per year
  • 10 paid sick leave days per year
  • Public holidays as per the company's approved Public holiday list
  • Medical budget
  • Opportunity to work remotely
  • Professional education budget
  • Language learning budget
  • Wellness budget (gym membership, sports gear and related expenses)
Before You Apply
️
remote Be aware of the location restriction for this remote position: Europe
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Incident Response & DFIR Lead @JustMarkets
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted Today
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: Europe
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 129,479+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later