Team Lead - Security Incident Response (all genders)
Core
Lead the Security Incident Response team to protect customer data, corporate assets, and online shop security through incident management, forensics, and threat mitigation.
Role type
Senior Team Lead, Security Incident Response (Blue Team/DFIR)
Builds
Incident response playbooks, automated monitoring/scanning tools, DFIR infrastructure, and AI-integrated security operations.
Domain
Cyber Security, Cloud-Native Environments, Digital Forensics
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure | physical/clinical work
Required skills
Digital Forensics and Incident Response (DFIR), SIEM management, Python programming, Linux proficiency, Cloud-native security, Threat intelligence analysis, Incident response playbooks creation, Web Application Firewall (WAF) management, Leadership, AI integration in security operations
Preferred skills
SANS/GIAC certifications, OffSec OSIR, HackTheBox/TryHackMe experience, Laravel/PHP knowledge, AWS/GCP experience, Gitlab CI/CD, Terraform/Terragrunt
Technologies
Python, Linux, SIEM, Cloudflare, WAF, AWS, GCP, Gitlab CI/CD, Terraform, Terragrunt, AI/LLMs
Responsibilities
Set up and maintain DFIR tools and infrastructure, Provide first response during security incidents including digital forensics, Maintain and improve SIEM tools, Investigate and respond to security alerts, Create and maintain incident response playbooks, Integrate AI into security operations beyond Q/A chat
Seniority
Senior, hands-on IC with leadership responsibilities
