Cyber Incident Responder

Il y a 3 jours

Henegouwen, Henegouwen, Belgique Wlgroup Temps plein 80 000 € - 120 000 € Contrat

When something gets in, somebody has to be the one who stays calm and works the problem. That is this job.

You would join the incident response team of a multinational defence organisation in Mons, Belgium, under the section head — responding to security incidents around the clock, and helping the wider alliance and its partners do the same.

What you would be doing

  • Running incident response — triage, containment, eradication, recovery — in normal hours and on occasional call-out
  • Giving technical coordination and support to operating authorities across member and partner nations, non-governmental organisations and industry partners
  • Leading or supporting response teams sent out to extend that coverage to one or several physical locations, including on operations and missions
  • Building and maintaining the taxonomy behind the branch's information, and the content of the portals that sit on it
  • Designing and distributing the reports, briefings and dashboards that business owners, the operational community, service management and security people each need
  • Keeping a live network of security peers, so an urgent action can be coordinated when it is needed rather than when it is convenient
  • Finding and implementing improvements to the response process as the threats move
  • Writing the standard operating procedures and instructions that cover it all
  • Acting as the response expert in meetings across the organisation and in an incident task force

What you would bring

  • At least four years of hands-on incident response, or a directly adjacent field — digital forensics, threat hunting, or malware and network analysis
  • A thorough grasp of computer and communications security, networking, and where modern operating systems and applications actually break
  • Recent hands‑on intrusion detection and response inside an enterprise‑scale response team, ideally against the MITRE ATT&CK framework
  • At least three years in information and knowledge management, preferably in security
  • Working alongside IT service management
  • Very good communication and analysis, and professional English
  • Vulnerability assessment and scoring — CVSS, SSVC, coordinated disclosure
  • A relevant certification such as CISM, CISSP or a GIAC security qualification
  • A bachelor's degree in a related discipline with three years of related experience — or, exceptionally, ten years of progressive expertise in this kind of work

Nice to have

  • A degree in cyber or IT security, or information management
  • Practical work or research on using AI and language models in defensive security
  • Vulnerability management end to end: ingestion, scoring, prioritisation, impactAn IT service management certification, and depth on security event sources and how to read them
  • Hands‑on system and network administration, including TCP/IP engineering
  • Time in a large organisational response team, and contribution to recognised communities such as FIRST

Why this one is worth a look

Very few response teams operate at this scale or with this reach, and the work is genuinely operational rather than advisory.