Cybersecurity Incident Responder

  • Contribute to the development, maintenance, testing and continuous improvement of the organization’s Incident Response Plan and incident handling capabilities
  • Develop, implement and assess incident response procedures, playbooks, workflows and operational processes
  • Identify, analyze, contain, mitigate and communicate cybersecurity incidents across enterprise environments
  • Lead and support technical cybersecurity incident investigations throughout all phases of the incident response lifecycle
  • Collect, analyze and correlate cyber threat information originating from multiple sources to determine incident impact, scope and root cause
  • Perform incident triage activities and assess reported security alerts to determine appropriate response actions
  • Monitor, investigate and respond to security events identified through Security Operations Centre (SOC) capabilities and cybersecurity monitoring platforms
  • Assess, prioritize and manage technical vulnerabilities and support remediation activities
  • Measure and evaluate incident detection and response effectiveness and recommend process improvements
  • Evaluate the effectiveness and resilience of cybersecurity controls and security measures following security incidents and data breaches
  • Develop and improve incident handling testing methodologies, exercises and validation techniques
  • Establish procedures for incident analysis, lessons learned activities and incident reporting
  • Document incident investigations, findings, response activities, corrective actions and recommendations
  • Manage, review and analyze log files, security events and forensic evidence to support investigations
  • Operate and utilize Incident Response (IR) tools including Extended Detection and Response (XDR), Security Information and Event Management (SIEM) and Network Detection and Response (NDR) platforms
  • Support and collaborate with Security Operations Centres (SOC) and Computer Security Incident Response Teams (CSIRT)
  • Work closely with technical, operational, legal, compliance and business stakeholders during cybersecurity incidents
  • Prepare and deliver incident response reports, executive summaries and post-incident assessments
  • Review existing security controls and provide recommendations to improve detection, response and prevention capabilities
  • Develop and maintain security procedures and policies with emphasis on information protection and data privacy requirements
  • Support security monitoring, threat analysis and incident management activities across operating systems, servers, cloud services and enterprise infrastructure
  • Contribute to regulatory and compliance-driven incident reporting activities in accordance with applicable legal and regulatory frameworks
  • Perform additional tasks as assigned by the supervisor
  • Minimum 8 years of experience in cybersecurity incident response, incident handling, security operations or cyber defence roles
  • At least two of the following incident handling certifications (or an equivalent certification recognized internationally and accepted by the Contracting Authority):
  1. GCIH (GIAC Certified Incident Handler)
  2. GCIA (GIAC Certified Intrusion Analyst)
  3. ECIH (EC-Council Certified Incident Handler)
  4. CSIH (SEI Certified Computer Security Incident Handler)
  5. SCMO (SABSA Certified Security Operations & Service Management Specialist)
  6. or equivalent, internationally recognized certification
  • Additionally, at least one of the following certifications (or an equivalent certification recognized internationally and accepted by the Contracting Authority):
  1. GPEN (GIAC Certified Penetration Tester)
  2. CCFP (Certified Cyber Forensics Professional)
  3. SCMO (SABSA Certified Security Operations & Service Management Specialist)
  4. or equivalent, internationally recognized certification
  • Strong knowledge of incident handling standards, methodologies and frameworks
  • Strong understanding of incident response best practices and operational procedures
  • Hands-on experience with incident handling and cybersecurity investigation tools
  • Knowledge of incident management, escalation and communication procedures
  • Strong knowledge of operating system security concepts and security hardening practices
  • Strong understanding of computer and network security principles
  • Good knowledge of cyber threats, threat actors, attack techniques and adversary tactics
  • Knowledge of cybersecurity attack procedures and intrusion methodologies
  • Strong understanding of system vulnerabilities, exploitation techniques and remediation approaches
  • Knowledge of cybersecurity-related laws, regulations and compliance requirements
  • Experience working within Security Operations Centres (SOC) environments
  • Experience collaborating with Computer Security Incident Response Teams (CSIRT)
  • Ability to perform all technical, operational and functional aspects of cybersecurity incident handling and response
  • Experience collecting, correlating and analyzing threat intelligence and security event data from multiple sources
  • Experience working with operating systems, servers, cloud platforms and enterprise infrastructure environments
  • Ability to perform effectively in high-pressure and time-sensitive situations
  • Excellent communication, presentation and reporting skills
  • Strong experience analyzing security logs, audit trails and security events
  • Excellent analytical, investigative and problem-solving skills
  • Strong attention to detail and ability to rapidly assess security situations
  • Security clearance required (EU Restricted) from 1st day of collaboration