Incident Response and DFIR Lead

JustMarkets Tech Responds Quickly
$$$$
Product

We are inviting you, a highly motivated and results-oriented Incident Response & DFIR Lead to join our team on a full-time basis.

Our team has unique expertise in research, analysis, and product development. By relying on technical insights and a data-driven approach, we create disruptive future-defining innovations of the fin-tech industry that remain our basis for success.
 

Responsibilities

  • Lead incident response, containment and forensic coordination for confirmed security incidents.
  • Act as Incident Commander for major security incidents within the defined authority model.
  • Assign incident roles and maintain clear ownership of investigation, containment and recovery actions.
  • Maintain incident timelines, evidence logs, decision logs and action tracking.
  • Coordinate investigation across endpoints, servers, identities, cloud platforms, SaaS environments and relevant network telemetry.
  • Direct forensic collection and analysis required to determine attack path, scope, persistence and impact.
  • Coordinate containment actions with IAM, Platform, IT, Security Engineering, Product and other technical owners.
  • Recommend high-impact containment decisions to the Group Manager of Cyber Defense and CISO where required.
  • Coordinate eradication and recovery activities and ensure systems return to a sufficiently trusted state.
  • Ensure relevant evidence is preserved for Legal, HR, regulatory, disciplinary and post-incident requirements.
  • Maintain practical forensic and evidence-handling standards.
  • Develop and maintain incident playbooks, forensic checklists and containment procedures.
  • Lead post-incident reviews and root-cause analysis.
  • Ensure post-incident remediation actions have accountable owners, due dates and follow-up.
  • Identify telemetry, detection and forensic-readiness gaps exposed during investigations.
  • Convert investigation findings into recommendations for Detection Engineering, IAM, Security Engineering, Product Security and other control owners.
  • Support incident exercises and readiness testing.
  • Develop and mentor Incident Response / DFIR Specialists.
  • Coordinate with external forensic, incident-response or specialist providers where required.
  • Provide concise incident updates to Cyber Defense leadership, CISO and relevant stakeholders.
     

Requirements

  • Strong hands-on knowledge of the incident response lifecycle: investigation, containment, eradication, recovery and lessons learned.
  • Experience leading complex security incidents and coordinating multiple technical teams during active response.
  • Practical experience investigating endpoint, identity, server, cloud or network compromise using EDR/XDR, SIEM and relevant audit logs.
  • Ability to reconstruct attacker activity, including initial access, credential abuse, persistence, privilege escalation, lateral movement, data access and exfiltration.
  • Working knowledge of digital forensics, evidence preservation, forensic timelines and chain-of-custody principles.
  • Experience designing and validating containment actions such as endpoint isolation, account/session revocation, credential rotation, blocking indicators, network restrictions and service isolation.
  • Experience with Microsoft Entra ID / Active Directory incident investigation.
  • Understanding of common incident scenarios including ransomware, malware, phishing/BEC, account takeover, cloud/SaaS compromise, data exfiltration and insider misuse.
  • Strong understanding of Windows, Linux, identity and enterprise networking from an investigation perspective.
  • Ability to document technical findings, timelines, evidence, assumptions and containment recommendations clearly.
     

Will be a plus

  • Hands-on experience with Cortex XDR, Elastic Security or equivalent enterprise platforms.
  • Experience investigating AWS or other cloud environments.
  • Experience with forensic tools such as Velociraptor, KAPE, Volatility, Autopsy, Magnet, EnCase, FTK or equivalent.
  • Experience investigating ransomware, BEC, insider-threat or cloud-account-compromise cases.
  • Experience developing or improving incident response playbooks and containment procedures.
  • Experience running tabletop or cyber incident exercises.
  • Experience working with Legal, Privacy, HR or regulators during security incidents.
  • Experience managing external DFIR or incident-response retainers.
  • Python, PowerShell or other scripting experience useful for investigation and evidence processing.
  • Experience in fintech, payments, brokerage, trading, banking or another regulated environment.
  • Relevant certifications such as GCIH, GCFA, GCFE, GNFA, OSCP, CISSP or equivalent (preferred, not mandatory).
     

We offer

  • 20 paid vacation days per year
  • 10 paid sick leave days per year
  • Public holidays as per the company's approved Public holiday list
  • Medical budget
  • Opportunity to work remotely
  • Professional education budget
  • Language learning budget
  • Wellness budget (gym membership, sports gear and related expenses)

Required skills experience

Incident Response 4 years
SIEM 4 years
EDR 4.5 years
XDR 4.5 years
SOC (Security Operations Center) 5 years

Required languages

English B2 - Upper Intermediate
Ukrainian Native
Published 30 September
5 views
ยท
0 applications
To apply for this and other jobs on Djinni login or signup.
Loading...