Cyber Incident Manager

NVISO GmbH

Brussel

Hybrid

EUR 90,000 - 130,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Training budget
Company car
Flexible hours
Home working

Job summary

NVISO GmbH is seeking a Cyber Incident Manager to lead responses to high-impact security incidents. You will own the full lifecycle from triage to recovery and report to senior stakeholders, coordinating across technical and business streams for timely, concrete actions.

The role requires 5+ years in cybersecurity or crisis management, strong leadership, and the ability to translate complex findings into practical guidance.

Qualifications

  • 5+ years of relevant experience in cybersecurity, incident response, or crisis management.
  • Ability to explain technically complex matters for varied stakeholders.
  • Proven experience leading cyber incidents, including triage, containment, and post-incident review.
  • Strong stakeholder-management and leadership during stressful situations.
  • Customer-facing consulting maturity and risk-based decision making.
  • Dutch and/or French and English at C1+ proficiency.

Responsibilities

  • Act as Incident Lead during active engagements, coordinating the technical response team and steering decisions on containment, eradication, recovery, evidence preservation, and business continuity.
  • Assess incoming incidents, determine severity and impact, and activate the right people and escalation paths quickly.
  • Run customer and internal incident calls, establish a war-room cadence, and maintain incident timeline and action tracker.
  • Serve as primary point of contact for customer leadership, delivering concise, factual updates on situation, impact, and next steps.
  • Produce high-quality incident deliverables, including executive updates, status reports, and root-cause analysis.
  • Ensure response follows agreed framework, scope, evidence-handling, and regulatory obligations.
  • Coordinate with legal, privacy, risk, communications, and external specialists as needed; support regulatory reporting by identifying facts and timelines.
  • Balance technical urgency with operational realities to enable defensible risk-based decisions on isolation and recovery.
  • Mentor incident-response team members, delegate work, remove blockers, and maintain wellbeing during high-pressure incidents.
  • Collaborate with cloud providers, MSPs, insurers, counsel, PR advisers, and law enforcement as involved.
  • Maintain traceable incident documentation and ensure decisions and actions are recorded.
  • Lead post-incident reviews and convert findings into improvements to playbooks and readiness services.
  • Identify patterns and weaknesses; recommend pragmatic security enhancements to reduce future risks.
  • Contribute to NVISO’s incident-management methodology, templates, and crisis communications approach.
  • Support tabletop exercises and executive briefings to improve readiness.
  • Stay current on threat activity and regulatory developments; apply insights to guidance for customers.

Skills

Incident management
Stakeholder management
Cybersecurity
Communication
Leadership
Regulatory awareness

Job description

It all starts with the mission: NVISO is here to protect European society from potentially devastating cyber attacks! This means we offer cyber security services to private and governmental organizations to help them better prepare for, prevent, detect and respond to cyber security incidents.

All of this is built on four fundamental values that define who we are: We are Proud, We Break Barriers, We Care and No BS!

What will you do?

As our Cyber Incident Manager, you will lead NVISO’s response to high-impact cyber incidents and act as the primary customer-facing decision-maker throughout the engagement. You will take ownership of the full incident lifecycle, from initial triage and scoping through investigation, containment, eradication, recovery, and post-incident improvement. You bring structure to complex, fast-moving situations by establishing the response model, defining priorities and investigative questions, coordinating technical and business workstreams, and ensuring decisions and actions are clearly documented and followed through. Working closely with Incident Responders, Digital Forensics specialists, Threat Intelligence, legal, IT, risk, data protection, communications, and customer leadership, you translate technical findings and business impact into clear, practical recommendations for senior stakeholders. Your role is to keep the response focused, coordinated, and effective, enabling the customer to make timely, well-informed decisions while the technical team investigates and contains the incident.

Your responsibilities

  • Act as Incident Lead during active engagements, coordinating the technical response team and steering decisions on containment, eradication, recovery, evidence preservation, and business continuity.
  • Assess incoming incidents, determine their severity and potential business impact, and ensure the right people, expertise, and escalation paths are activated quickly.
  • Run customer and internal incident calls, establish an effective war-room cadence, and keep a clear incident timeline, decision log, action tracker, and stakeholder map.
  • Serve as the primary point of contact for customer leadership during incidents, delivering concise, factual, and timely updates on the situation, business impact, decisions required, response progress, and next steps.
  • Produce and quality-review high-quality incident deliverables, including executive updates, status reports, incident reports, root-cause analysis, and actionable remediation roadmaps.
  • Ensure the incident response follows the agreed response framework, engagement scope, evidence-handling requirements, and applicable regulatory, contractual, and organisational obligations.
  • Coordinate with legal, privacy, risk, communications, insurance, and external specialists where required; ensure the customer has the information needed to make informed notification, disclosure, and recovery decisions.
  • Support customers with regulatory incident reporting by identifying relevant facts, timelines, impact, and evidence, while leaving legal determinations and formal notification decisions to the appropriate customer and legal stakeholders.
  • Balance technical urgency with operational realities: help customers make defensible risk-based decisions on isolation, recovery, restoration of critical services, and communications.
  • Manage and mentor incident response team members during engagements: delegate work effectively, remove blockers, maintain quality, and protect team wellbeing during sustained high-pressure incidents.
  • Coordinate third parties such as cloud providers, managed service providers, insurers, outside counsel, PR advisers, and law enforcement where they are involved in the response.
  • Maintain accurate incident documentation and ensure evidence, key decisions, customer actions, and outstanding risks are traceable throughout the engagement.
  • Lead or oversee post-incident reviews and lessons-learned sessions; turn findings into practical improvements to playbooks, detection coverage, response procedures, recovery plans, and customer readiness.
  • Identify recurring incident patterns and systemic weaknesses and recommend pragmatic security enhancements to reduce the likelihood and impact of future incidents as part of structured lessons learned sessions
  • Contribute to and continuously improve NVISO’s incident-management methodology, templates, crisis communications approach, escalation procedures, and readiness services.
  • Support incident readiness engagements, such as tabletop exercises, crisis simulations, forensic readiness assessments, response-plan reviews, and executive briefings.
  • Stay current on threat actor activity, attacker TTPs, major incident trends, and relevant regulatory developments, and use these insights to improve response decision-making and customer advice.
Requirements
  • You hold citizenship in one of the 32 NATO member states;
  • 5+ years of relevant experience in cybersecurity, incident response, digital forensics, crisis management, IT service management, or a comparable high-pressure operational role.
  • Ability to explain technically complex matters for a wide variety of stakeholders.
  • Demonstrated experience leading or coordinating cyber incidents, including triage, investigation, containment, eradication, recovery, stakeholder communication, and post-incident review.
  • Proven stakeholder-management skills: comfortable leading calls and communicating with technical teams, IT leadership, CISOs, executives, legal counsel, privacy professionals, risk teams, and external providers during stressful situations.
  • Strong coordination and leadership skills: able to organise parallel workstreams, delegate effectively, keep actions and their actioner moving, resolve blockers, and create an effective working rhythm during prolonged incidents.
  • Customer-facing consulting maturity, with the ability to build trust quickly, challenge constructively, and balance technical, commercial, legal, and operational considerations.
  • A continuous-improvement mindset: you are motivated to turn lessons learned into stronger playbooks, readiness measures, detection capabilities, and response processes.
  • Up-to-date knowledge of current cyber threats, attacker tradecraft, and the wider incident-response landscape.
  • Language: Dutch and/or French and English at C1+ proficiency for client-facing work across BE/NL/LUX.
  • We have an On-call rotation, typically one week per month.
  • Be prepared to operate outside standard business hours as part of an on-call rotation and during active incidents.

Travel

  • Some limited travel within BE/NL/LUX/DE/AT/CH (~10–20%) for onsite response, workshops, and stakeholder meetings.
What do we offer

At NVISO, we care. We are committed to offering you a highly competitive remuneration package including financial and non-financial components:

  • A training budget of 10.000€ and 10 days every 2 years
  • Company car and Belgian charging card
  • Working and learning from the best people in the European cyber security industry. We have multiple SANS Instructors working at NVISO, our staff has presented at popular hacking conferences (BlackHat, BruCON, OWASP, etc) and all of our technical staff can acquire deep technical security certifications (GSE, GXPN, GREM, GCFA, OSCP, etc)
  • An entrepreneurial and agile working environment, where you will be challenged, stimulated and supported in driving new initiatives (either through internal innovation or by improving our service offering), without losing sight of having fun!
  • Regular team-building and fun events throughout the year;
  • Our commitment to coach and counsel you and help you grow; each employee receives a personal coach within the team, whose role is to ensure your well-being and helps you grow in your career!
  • Flexible working hours, working from home and even the possibility to work from abroad;
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Incident Response & Digital Forensics Consultant
Senior Incident Response & Digital Forensics Consultant

Nviso • Brussel Hoofdstad

On-site
EUR 60,000 - 90,000
Training budget of 10.000€ and 10 days every 2 years
Company car and Belgian charging card
Flexible working hours
+1
Security Operations Engineering Consultant
Security Operations Engineering Consultant

NVISO GmbH • Brussel Hoofdstad

Hybrid
EUR 42,000 - 60,000
Cyber Incident Manager
Cyber Incident Manager

Join • Brussel

Hybrid
EUR 90,000 - 125,000
Training budget 10.000€ and 10 days/2y
Company car + Belgian fuel card
Flexible working hours and home office
+1
Technical Lead Manager
Technical Lead Manager

NVISO • Brussel Hoofdstad

On-site
Confidential
Training budget 10.000€
Flexible working hours
32 paid leave days
Senior Cyber Strategy & Architecture Consultant
Senior Cyber Strategy & Architecture Consultant

NVISO Security • Brussel Hoofdstad

Hybrid
EUR 90,000 - 130,000
Training budget 10000€
Home office options
Flexible working hours
+3
Senior Red Teamer
Senior Red Teamer

Nviso • Brussel Hoofdstad

On-site
EUR 90,000 - 130,000
Training budget
Remote options
Flexible schedule
+1
Junior Application Security Consultant
Junior Application Security Consultant

Nviso • Belgium

On-site
EUR 40,000 - 60,000
Training budget and learning perks
Company car and Belgian fuel card
Regular team-building events
+1
Senior Security Operations Engineering Manager
Senior Security Operations Engineering Manager

NVISO GmbH • Brussel Hoofdstad

On-site
EUR 120,000 - 150,000
Training budget 10000€
Flexible working hours
Home office options
+3
Senior SOC Automation Consultant
Senior SOC Automation Consultant

nviso • Brussel Hoofdstad

On-site
EUR 90,000 - 130,000
Training budget 10,000€
Company car + Belgian fuel card
Flexible working hours and home office
+1
Service Delivery Manager – Penetration Testing
Service Delivery Manager – Penetration Testing

Nviso • Brussel Hoofdstad

On-site
EUR 90,000 - 120,000
Training budget €10,000
Flexible working model
5 additional leave days
+2