Senior Cyber Incident Response Consultant
Endava Vezi toate joburile
- Cluj-Napoca, Cluj
- Permanent
- Full-time
- Lead and coordinate cyber incident response activities across internal teams, managed SOC providers, and technology stakeholders.
- Act as the senior technical escalation point for security operations and incident response investigations.
- Investigate complex security incidents including malware infections, account compromise, insider threats, and advanced attack activity.
- Coordinate containment, remediation, and recovery actions during cyber incidents.
- Improve security monitoring and response processes by refining detection logic, alert triage processes, and response playbooks.
- Partner with SOC, Threat Intelligence, and Vulnerability Management teams to strengthen detection coverage and threat visibility.
- Lead the development and maintenance of incident response playbooks and response procedures.
- Drive improvements in cyber defence capabilities through automation using SOAR and security tooling integrations.
- Analyse incident trends and root causes to identify security control gaps and recommend preventative improvements.
- Ensure accurate incident documentation, audit trails, and post-incident reviews including lessons learned and improvement actions.
- Participate in cyber incident simulations and response exercises to improve organisational readiness.
- Support service governance with managed SOC providers, ensuring service delivery meets defined SLAs and operational KPIs.
- 10+ years of experience in cybersecurity or IT, with at least 6 years in Security Operations Centre (SOC) or Incident Response roles.
- Demonstrated experience leading or coordinating cyber incident investigations in enterprise environments.
- Hands-on experience performing digital forensics, threat investigation, and incident containment activities.
- Experience working within hybrid security operations models that include outsourced SOC providers or managed security services.
- Experience developing incident response processes, playbooks, and operational procedures.
- Experience improving detection engineering and response capabilities using SIEM, EDR, and security automation platforms.
- Experience analysing threat intelligence and attacker techniques to improve detection use cases.
- Relevant cybersecurity certifications such as GIAC, CISM, OSCP, CEH, or equivalent are desirable.
- Hands-on experience with modern cyber defence technologies including:
- SIEM platforms (e.g., Splunk, Sentinel, or equivalent)
- Endpoint Detection and Response (e.g., CrowdStrike, Microsoft Defender)
- Security Orchestration and Automation (SOAR) platforms
- Threat intelligence platforms and monitoring tools
- Strong knowledge of incident response methodologies and cyber kill chain analysis.
- Experience analysing attacker techniques and mapping detections using frameworks such as MITRE ATT&CK.
- Experience developing detection use cases and improving alert fidelity.
- Familiarity with cyber incident management metrics such as:
- Mean Time to Detect (MTTD)
- Mean Time to Respond (MTTR)
- Detection coverage and response effectiveness
- Understanding of digital forensics techniques including log analysis, endpoint investigation, and network event analysis.
- Ability to translate threat intelligence, incident learnings, and vulnerability insights into improvements in security controls and detection capabilities.
- Experience scripting or automating response workflows to improve security operations efficiency is advantageous.
- Familiarity with regulatory and compliance obligations related to incident reporting and evidence preservation (e.g., GDPR, NIS2) is beneficial.
- Finance: Competitive salary package, share plan, company performance bonuses, value-based recognition awards, referral bonus;
- Career Development: Career coaching, global career opportunities, non-linear career paths, internal development programmes for management and technical leadership;
- Learning Opportunities: Complex projects, rotations, internal tech communities, training, certifications, coaching, online learning platforms subscriptions, pass-it-on sessions, workshops, conferences;
- Work-Life Balance: Hybrid work and flexible working hours, employee assistance programme;
- Health: Global internal wellbeing programme, access to wellbeing apps;
- Community: Global internal tech communities, hobby clubs and interest groups, inclusion and diversity programmes, events and celebrations.