About this role
Job title: Cyber Incident Response Specialist
About the Role Join the Incident Response team and operate in an international, dynamic and growing context, with a key role in the Bank's CSIRT. You will autonomously manage cyber incidents, coordinating with technical teams and essential functions to resolve events and assess operational, business and regulatory impacts. You will also contribute to post-incident analysis and incident readiness activities, supporting the ongoing strengthening of the Bank's Incident Response capabilities.
What You'll Do
- Analyze and contextualize cyber security incidents escalated to CSIRT from other Bank functions, assessing technical complexity and potential operational and business impacts.
- Evaluate notifications and assign severity and priority in line with processes and policies.
- Autonomously support and coordinate advanced technical analysis of incidents.
- Contribute to containment and response activities, identifying involved support functions and coordinating mitigation and restoration.
- Monitor the effectiveness of actions taken and progress of recovery activities.
- Support incident management with potential Business Continuity impacts, collaborating with functions to assess operational impacts, activate measures and restore services.
- Track incidents and prepare reports to stakeholders including top management.
- Manage the incident response process in coordination with internal Bank actors and liaise with external counterparts.
- Contribute to continuous improvement of Incident Response processes through structured application of post-incident lessons learned.
- Identify events and scenarios that could cause business interruptions or other significant impacts, including inputs from Cyber Threat Intelligence.
- Support and monitor forensic analysis on assets involved in incidents.
- Plan and execute incident readiness simulations involving different Bank functions.
What We're Looking For
- 3-5 years of experience in Incident Response and Cybersecurity.
- STEM degree (Engineering, Computer Science, Cyber Security or related).
- Excellent written and spoken English.
- Deep and up-to-date knowledge of the cyber threat landscape and main TTPs.
- Solid experience with security systems: SIEM, UEBA, SOAR, AV, Scanners, Proxies, WAF, IDS, forensic tools.
- Advanced knowledge of MITRE ATT&CK and Cyber Kill Chain.
- Comprehensive knowledge of Incident Response frameworks and guidelines (NIST, ENISA, CISA).
- Strong understanding of security implications and investigative methodologies for core IT components: network infrastructure, security systems, OS, services and application architectures.
- Knowledge of major cyber regulations (GDPR, DORA).
- Consolidated experience in Incident Response / CSIRT / SOC in complex corporate contexts; financial sector experience preferred.
- Direct experience managing complex cyber security incidents.
- Experience in log analysis, forensic analysis and threat hunting.
- Knowledge and experience in programming or scripting languages (Python, C, C++, Java).
- Preferential certifications: CSIH, CISSP, GCIH, GFCA, GREM, GCIA.
Nice to Have
- Preferential certifications listed above.
Compensation & Benefits
- Gross annual salary starting from €45,000.00.
- Variable remuneration component as per Group policies.
- Professional development via Corporate Academy for ongoing skills growth.
- Flexible work arrangements and 4x9 short week option.
- Comprehensive welfare program including healthcare and supplementary pension from start of employment.
- Banking product and service benefits for Group customers.