Incident response Lead

Tamarind Intelligence

Madrid

Híbrido

EUR 80.000 - 130.000

Jornada completa

Hace 13 días

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Ventajas ofrecidas por este puesto de trabajo

Breakfast in the office 4 days a week
Hybrid work model
Medical Insurance (including Dental &
Life Insurance
Vacation 23 days

Descripción de la vacante

RingCentral seeks an experienced cybersecurity incident response leader to protect the organization, customers, and services. You will oversee identification, containment, and resolution of major incidents, coordinating across multiple teams and communicating with executives.

The role requires strong incident leadership, RCA work, and experience with cloud platforms, containers, and enterprise identity systems. Hybrid work model with in-office coverage four days a week is offered.

Formación

  • Significant professional experience in cybersecurity, incident response, security operations, digital forensics, threat detection, or related discipline.
  • Demonstrated experience leading complex cybersecurity incidents involving multiple technical and business teams.
  • Experience coordinating containment, eradication, recovery, and impact assessment activities.
  • Experience communicating security incidents to senior leadership.
  • Experience leading or facilitating root cause analyses.
  • Experience tracking corrective actions through completion.
  • Practical experience with modern production environments (cloud, containers, identity systems, networks, customer-facing apps).
  • Ability to participate in on-call or major-incident escalation arrangements.
  • Experience responding to incidents involving customer data or personal data.
  • Experience developing incident response playbooks, severity models, reporting standards, and tabletop exercises.
  • Strong written and spoken English.

Responsabilidades

  • Incident Leadership & Control: lead major security incidents with clarity and authority.
  • Declaration, Scoping & Technical Analysis: identify and declare incidents; assess scope and impact.
  • Threat Containment, Eradication & Recovery: contain threats and restore production services.
  • Stakeholder Facilitation & Multi-Audience Communication: report to executives and partners.
  • Root Cause Analysis (RCA) & Problem Management: drive long-term security improvements.
  • Corrective Action & Continuous Capability Improvement: ensure actions are completed and verified.

Conocimientos

Incident leadership
Cybersecurity
Incident response
Security operations
Communication to leadership
Root-cause analysis
On-call readiness

Herramientas

Cloud platforms
Containers
Identity systems
Networks

Descripción del empleo

RingCentral is a global leader in agentic voice AI--powered business communications, delivering an integrated platform for business phone, SMS, contact center, workforce engagement management, video collaboration, and messaging. As the communications layer connecting businesses and customers, RingCentral is the front door of business communication and is in the advantageous position to apply AI at every phase of the conversation journey --- before, during, and after each interaction. Our agentic AI portfolio includes autonomous voice-first AI agents that automate calls, assist in the moment, and analyze every interaction -- enabling businesses to work smarter, respond faster, and connect more meaningfully with their customers.

Role mission Protect the organisation, its customers, and its services by ensuring that potential and confirmed cybersecurity incidents are identified, assessed, contained, investigated, communicated, and resolved in a timely, disciplined, and evidence-based manner.

Responsibilities
  • Incident Leadership & Control: Ensure major security incidents are led with absolute clarity, authority, and control, establishing a structured response environment from declaration to resolution.
  • Declaration, Scoping & Technical Analysis: Ensure security incidents are identified and declared consistently, while accurately assessing incident scope, attacker behaviour, and technical impact.
  • Threat Containment, Eradication & Recovery: Contain active security threats before additional harm occurs, eradicate root causes, and safely restore impacted production services.
  • Stakeholder Facilitation & Multi-Audience Communication: Deliver transparent, decision-useful reporting to executives, governance teams and cross-functional partners throughout the incident lifecycle.
  • Root Cause Analysis (RCA) & Problem Management: Facilitate meaningful Root Cause Analyses that look beyond surface-level symptoms to produce tangible, long-term security improvements.
  • Corrective Action & Continuous Capability Improvement: Ensure corrective actions are fully completed and verified---not merely recorded---to continuously elevate the overall incident response capability.
Required Experience
  • Significant professional experience in cybersecurity, incident response, security operations, digital forensics, threat detection, or a closely related discipline.
  • Demonstrated experience leading complex cybersecurity incidents involving multiple technical and business teams.
  • Experience coordinating containment, eradication, recovery, and impact assessment activities.
  • Experience communicating security incidents to senior leadership.
  • Experience leading or facilitating root cause analyses.
  • Experience tracking corrective actions through completion.
  • Practical experience working with modern production environments, such as cloud platforms, containers, enterprise identity systems, networks, or customer-facing applications.
  • Ability to participate in an on-call or major-incident escalation arrangement.
  • Experience responding to incidents involving customer data or personal data.
  • Experience developing incident response playbooks, severity models, reporting standards, and tabletop exercises.
  • Strong written and spoken English.
Would be a plus
  • Familiarity with NIST incident response guidance, ISO/IEC 27035, SANS incident handling practices, MITRE ATT&CK, or comparable frameworks.
  • Relevant certifications may include GCIH, GCFA, GCFE, CISSP, CISM, or equivalent practical experience.
What We Offer
  • Well-coordinated professional team;
  • Breakfast in the office 4 days a week;
  • Cutting edge technologies, interesting and challenging tasks, dynamic project, great opportunities for self-realization, professional and career growth;
  • Flexible working hours and opportunity for a hybrid work;
  • Job placement and payment of salary take place according to the labor code, as well as vacation; sick lists are paid at 100% of full pay;
  • Medical Insurance, including Dental and Vision;
  • Life Insurance;
  • Vacation 23 days.
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Incident response Lead
Incident response Lead

RingCentral • Valencia

Híbrido
EUR 90.000 - 120.000
Breakfast in the office
Hybrid work
Medical Insurance
+3
Incident response Lead
Incident response Lead

RingCentral • Comunidad Valenciana

Híbrido
EUR 60.000 - 90.000
Breakfast in the office (4 days/week)
Medical Insurance
Life Insurance
+1
Incident Response Lead — Hybrid & Flexible Hours
Incident Response Lead — Hybrid & Flexible Hours

Tamarind Intelligence • Madrid

Híbrido
EUR 80.000 - 130.000
Breakfast in the office 4 days a week
Hybrid work model
Medical Insurance (including Dental &
+2
Senior Security Incident Responder
Senior Security Incident Responder

Montash • Barcelona

Híbrido
EUR 70.000 - 90.000
Hybrid work
Bonus scheme
Pension contributions
+5
Incident Response Lead - Hybrid & Flexible Hours
Incident Response Lead - Hybrid & Flexible Hours

RingCentral • Comunidad Valenciana

Híbrido
EUR 60.000 - 90.000
Breakfast in the office (4 days/week)
Medical Insurance
Life Insurance
+1
Incident Response Lead — Hybrid & Flexible Hours
Incident Response Lead — Hybrid & Flexible Hours

RingCentral • Valencia

Híbrido
EUR 90.000 - 120.000
Breakfast in the office
Hybrid work
Medical Insurance
+3
Senior Cyber Incident Response Analyst
Senior Cyber Incident Response Analyst

Integrity360 • Madrid

Presencial
EUR 60.000 - 90.000
Senior Incident Coordinator (Hybrid option)
Senior Incident Coordinator (Hybrid option)

Swiss Re • Madrid

Híbrido
EUR 62.000 - 94.000
Performance-based variable compensation
Global and location-specific benefits
Cybersecurity incidence response senior analyst (SOC L2/L3) for an international IT Hub
Cybersecurity incidence response senior analyst (SOC L2/L3) for an international IT Hub

Agrupa Global Talent • Barcelona

Híbrido
EUR 50.000 - 70.000
Competitive compensation
Health and dental insurance
Lunch vouchers
+1
Cyber Security Analyst
Cyber Security Analyst

Graphic Packaging International • Igualada

Presencial
EUR 42.000 - 68.000