Cybersecurity Incident Responder
Employer · pl
Cybersecurity Incident Responder at Employer, based in pl. This is a permanent role.
- Salary
- Competitive
- Location
- pl
- Contract
- Permanent
- Posted
- 1 month ago
- Closes
- 30 Sep 2026
- Sector
- Security
Reference j_48abc95
About the role
Contribute to the development, maintenance, testing and continuous improvement of the organization’s Incident Response Plan and incident handling capabilities Develop, implement and assess incident response procedures, playbooks, workflows and operational processes Identify, analyze, contain, mitigate and communicate cybersecurity incidents across enterprise environments Lead and support technical cybersecurity incident investigations throughout all phases of the incident response lifecycle Collect, analyze and correlate cyber threat information originating from multiple sources to determine incident impact, scope and root cause Perform incident triage activities and assess reported security alerts to determine appropriate response actions Monitor, investigate and respond to security events identified through Security Operations Centre (SOC) capabilities and cybersecurity monitoring platforms Assess, prioritize and manage technical vulnerabilities and support remediation activities Measure and evaluate incident detection and response effectiveness and recommend process improvements Evaluate the effectiveness and resilience of cybersecurity controls and security measures following security incidents and data breaches Develop and improve incident handling testing methodologies, exercises and validation techniques Establish procedures for incident analysis, lessons learned activities and incident reporting Document incident investigations, findings, response activities, corrective actions and recommendations Manage, review and analyze log files, security events and forensic evidence to support investigations Operate and utilize Incident Response (IR) tools including Extended Detection and Response (XDR), Security Information and Event Management (SIEM) and Network Detection and Response (NDR) platforms Support and collaborate with Security Operations Centres (SOC) and Computer Security Incident Response Teams (CSIRT) Work closely with technical, operational, legal, compliance and business stakeholders during cybersecurity incidents Prepare and deliver incident response reports, executive summaries and post-incident assessments Review existing security controls and provide recommendations to improve detection, response and prevention capabilities Develop and maintain security procedures and policies with emphasis on information protection and data privacy requirements Support security monitoring, threat analysis and incident management activities across operating systems, servers, cloud services and enterprise infrastructure Contribute to regulatory and compliance-driven incident reporting activities in accordance with applicable legal and regulatory frameworks Perform additional tasks as assigned by the supervisor Minimum 8 years of experience in cybersecurity incident response, incident handling, security operations or cyber defence roles At least two of the following incident handling certifications (or an equivalent certification recognized internationally and accepted by the Contracting Authority): GCIH (GIAC Certified Incident Handler) GCIA (GIAC Certified Intrusion Analyst) ECIH (EC-Council Certified Incident Handler) CSIH (SEI Certified Computer Security Incident Handler) SCMO (SABSA Certified Security Operations & Service Management Specialist) or equivalent, internationally recognized certification Additionally, at least one of the following certifications (or an equivalent certification recognized internationally and accepted by the Contracting Authority): GPEN (GIAC Certified Penetration Tester) CCFP (Certified Cyber Forensics Professional) SCMO (SABSA Certified Security Operations & Service Management Specialist) or equivalent, internationally recognized certification Strong knowledge of incident handling standards, methodologies and frameworks Strong understanding of incident response best practices and operational procedures Hands-on experience with incident handling and cybersecurity investigation tools Knowledge of incident management, escalation and communication procedures Strong knowledge of operating system security concepts and security hardening practices Strong understanding of computer and network security principles Good knowledge of cyber threats, threat actors, attack techniques and adversary tactics Knowledge of cybersecurity attack procedures and intrusion methodologies Strong understanding of system vulnerabilities, exploitation techniques and remediation approaches Knowledge of cybersecurity-related laws, regulations and compliance requirements Experience working within Security Operations Centres (SOC) environments Experience collaborating with Computer Security Incident Response Teams (CSIRT) Ability to perform all technical, operational and functional aspects of cybersecurity incident handling and response Experience collecting, correlating and analyzing threat intelligence and security event data from multiple sources Experience working with operating systems, servers, cloud…
Reference: j_48abc95 · Posted 1 month ago · Closes 30 Sep 2026 · Listed via Employer
Apply for this job
This role is listed via Employer. Applications are handled on the employer's site.
Apply on employer siteOpens the employer's website in a new tab.
Safe applying: a genuine employer will never ask you to pay for a DBS check, training or equipment, or move you onto WhatsApp before you are hired. If this listing does, report it and do not pay anything.