CyberSecurity Engineer, Incident Response Lead

Mistral

Paris

Sur place

EUR 90 000 - 150 000

Plein temps

14 jours+

Recevez plus de réponses des employeurs

Envoyez un CV adapté au poste en quelques minutes.

Avantages offerts par ce poste

Health insurance
Transportation allowance
Sport allowance
Meal vouchers
Private pension plan
Generous parental leave policy

Résumé du poste

Mistral is seeking a senior Incident Response and Digital Forensics specialist to lead our incident response capability across a complex AI ecosystem. You will own incidents end-to-end, act as incident commander, and help define our response methodologies.

Based in Paris with a hybrid working model, you will build runbooks, develop forensic tooling, mentor teammates, and coordinate with SOC, legal, and engineering during high‑stakes events.

Qualifications

  • Extensive experience leading complex IR and digital forensics investigations in cloud-native or high-stakes environments.
  • Ability to command during critical incidents and coordinate multidisciplinary teams.
  • Knowledge of cloud and container forensics across AWS, GCP, Kubernetes and on-prem.
  • Experience building runbooks, forensic workflows, tabletop exercises, and post-incident reviews.
  • Proficiency in Python or Go for automation.

Responsabilités

  • Own incident response lifecycle for high-severity events.
  • Act as incident commander coordinating teams.
  • Develop and test incident response runbooks.
  • Operate forensic capabilities across cloud, container, and on‑prem.
  • Preserve and analyze digital evidence.
  • Improve detection-to-response workflows.
  • Design tabletop exercises with stakeholders.
  • Lead post-mortems and translate lessons into improvements.
  • Define incident communication and escalation practices.
  • Mentor future incident response team members.

Connaissances

Incident response leadership
Digital forensics
Cloud forensics
MITRE ATT&CK framework
Python/Go scripting
Tabletop exercises
Post-incident reviews
Communication with stakeholders
Mentoring/team-building

Outils

Kubernetes
AWS
GCP
macOS forensics

Description du poste

Role Summary

Mistral AI is looking for a senior Incident Response and Digital Forensics specialist to lead our incident response capability across a complex, rapidly evolving AI ecosystem.

Reporting to the SOC Lead, you will take end-to-end ownership of major security incidents, from initial investigation and containment through remediation and post-incident improvement. During critical events, you will act as the incident commander, bringing structure, sound judgment, and calm leadership to high-pressure situations.

This is a hands‑on, player‑coach position combining deep technical investigations with capability building. You will help define our incident response methodology, forensic tooling, runbooks, exercises, and post‑mortem practices. As the organization grows, the role may also offer opportunities to build and lead a dedicated incident response team.

What You Will Do
  • Own the incident response lifecycle for high‑severity security events, including triage, investigation, containment, remediation, recovery, and post‑incident review.
  • Act as incident commander, coordinating technical teams and key stakeholders during complex security incidents.
  • Build, maintain, and test incident response runbooks covering Mistral’s most important risk scenarios.
  • Develop and operate forensic capabilities across cloud, containerized, on‑premises, and endpoint environments.
  • Preserve, collect, and analyze digital evidence using rigorous and repeatable forensic methodologies.
  • Partner with SOC and Detection Engineering teams to strengthen detection‑to‑response workflows and improve investigative readiness.
  • Design and facilitate tabletop exercises with engineering, legal, communications, and leadership stakeholders.
  • Lead blameless post‑mortems and ensure lessons learned translate into durable technical and organizational improvements.
  • Define clear incident communication and escalation practices for both technical and non‑technical stakeholders.
  • Contribute to the long‑term development of Mistral’s incident response function, with the potential to mentor or lead future team members.
About You
  • Significant experience leading complex incident response and digital forensics investigations in cloud‑native, technology, or similarly high‑stakes environments.
  • Demonstrated ability to take command during critical incidents and coordinate multidisciplinary teams under pressure.
  • Strong knowledge of cloud and container forensics, including environments such as AWS, GCP, Kubernetes, and on‑premises infrastructure.
  • Hands‑on experience with endpoint forensics, ideally including macOS environments.
  • Strong understanding of attacker behaviors, investigation methodologies, evidence handling, and the MITRE ATT&CK framework.
  • Experience building incident response runbooks, forensic workflows, tabletop exercises, and post‑incident review practices.
  • Ability to automate investigative or response workflows using Python, Go, or similar languages.
  • Excellent written and verbal communication skills, with the ability to communicate clearly with engineers, legal teams, executives, and other stakeholders.
  • A calm, methodical, and pragmatic approach, combined with a strong sense of ownership.
  • Experience mentoring others or helping build an incident response capability is highly valued.
Location & Remote

The position is based in our Paris HQ offices and we encourage going to the office as much as we can (at least 3 days per week) to create bonds and smooth communication. Our remote policy aims to provide flexibility, improve work‑life balance and increase productivity. Each manager can decide the amount of days worked remotely based on autonomy and a specific context (e.g. more flexibility can occur during summer). In any case, employees are expected to maintain regular communication with their teams and be available during core working hours.

Location: Paris, France
Working model: Hybrid
Scope: Global
Level: Senior / Staff

What we offer
  • Competitive salary and equity package
  • Health insurance
  • Transportation allowance
  • Sport allowance
  • Meal vouchers
  • Private pension plan
  • Generous parental leave policy
Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

CyberSecurity Engineer, SOC Analyst
CyberSecurity Engineer, SOC Analyst

Mistral • Paris

Sur place
EUR 55 000 - 75 000
Health insurance
Transportation allowance
Sport allowance
+3
CyberSecurity Engineer, Offensive Security
CyberSecurity Engineer, Offensive Security

Mistral • Paris

Sur place
EUR 70 000 - 90 000
Competitive salary and equity
Health insurance
Transportation allowance
+5
Senior Incident Commander & Digital Forensics Lead
Senior Incident Commander & Digital Forensics Lead

Mistral • Paris

Hybride
EUR 90 000 - 150 000
Health insurance
Transportation allowance
Sport allowance
+3
CyberSecurity Engineer, DevSecOps
CyberSecurity Engineer, DevSecOps

Mistral • Paris

Sur place
EUR 85 000 - 120 000
Health insurance
Transportation allowance
Sport allowance
+3
AI Deployment Strategist, Cybersecurity - EMEA
AI Deployment Strategist, Cybersecurity - EMEA

Mistral • Paris

Sur place
EUR 90 000 - 130 000
Cash salary & equity
Meal vouchers
Gym discounts
+5
Security Compliance Specialist
Security Compliance Specialist

Mistral • Paris

Sur place
EUR 80 000 - 110 000
Healthcare coverage
Parental leave
Relocation support
Deputy Director, Safety & security HQ
Deputy Director, Safety & security HQ

Mistral • Paris

Sur place
EUR 75 000 - 100 000
Healthcare coverage
Parental leave
Relocation support
+1
Deputy Director, Safety & Security HQ
Deputy Director, Safety & Security HQ

jobr.pro • Paris

Sur place
EUR 60 000 - 80 000
Healthcare coverage
Parental leave
Retirement plans
+4
Applied AI, Use-case, Software Engineer (Harness)
Applied AI, Use-case, Software Engineer (Harness)

Mistral • Paris

Sur place
EUR 90 000 - 140 000
Competitive salary and equity
Health insurance
Transportation allowance
+5
CyberSecurity, Offensive Security Engineer
CyberSecurity, Offensive Security Engineer

Mistral • Paris

Hybride
EUR 90 000 - 120 000