Cybersecurity Incident Response Lead

Fineco Bank

Turbigo

Ibrido

EUR 80.000 - 100.000

Tempo pieno

14 giorni+

Ricevi più risposte dai datori di lavoro

Invia un CV specifico per questa offerta in pochi minuti.

Vantaggi offerti da questo lavoro

Equal Opportunity Employer
Safe and inclusive workplace

Descrizione del lavoro

Fineco Bank in Milan is seeking a Cybersecurity Incident Response Lead to manage the end-to-end incident response program within their ICT & Cybersecurity department. The role involves orchestrating incident response across teams, building and testing incident response playbooks, and conducting post-incident analyses. Candidates should have at least 7 years of relevant experience, proficiency with key frameworks, and strong technical communication skills. The position offers a hybrid work model, accommodating both on-site presence and smart working.

Competenze

  • 7+ years of experience in incident response, security operations, or cyber crisis management.
  • Hands-on experience with key IR frameworks and tools.
  • Ability to make containment decisions under pressure.

Mansioni

  • Guide operational coordination of security incident response.
  • Build, maintain, and test the incident response program.
  • Conduct structured post-incident reviews.

Conoscenze

Incident response coordination
Proficiency with key IR frameworks
Scripting and automation skills (Python)
Strong knowledge of networks and protocols
Ability to communicate effectively

Formazione

At least 7 years of experience in incident response

Strumenti

SIEM
EDR/XDR enterprise tools
Forensic analysis tools

Descrizione del lavoro

Fineco Bank is a leading European bank with 20 years of history and a fully digital, branchless approach. We offer a wide range of products including trading, investment and payment services, a proprietary trading/investment platform, and banking solutions for domestic and international demand.

Position

We are looking for a Cybersecurity Incident Response Lead to join the ICT & Cybersecurity department. This role heads the end‑to‑end IR program, leads incident response coordination, and provides clear status to management. The lead works closely with SOC, technical teams, and governance functions, orchestrating contributions from teams not directly reporting to Cybersecurity.

The role is not SOC shift management nor purely forensic or compliance. The focus is coordinating incident response, maturing the IR program, orchestrating involved technical teams, and turning cyber events into operational decisions, manager communication, and audit‑ready evidence.

Principali Attività
  • Guide operational coordination of security incident response: triage, containment priority, reconstruct initial vector, kill chain, propagation, blast radius, and coordination of eradication and recovery with owner teams.
  • Maintain an operational timeline and structured decision log during incidents, tracking hypotheses, containment decisions, owners, available evidence, and residual risks.
  • Build, maintain, and test the IR program: playbook, runbook, escalation procedures, roles and responsibilities, incident classification criteria, and continuous improvement mechanisms.
  • Contribute to the evolution of detection and response capabilities, defining requirements with the SOC based on real incidents, tabletop exercises, threat intelligence, and improving SIEM/SOAR/EDR/XDR workflows.
  • Integrate threat intelligence into the IR cycle: translate indicators of compromise, TTPs and threat scenarios into concrete detection, hunting, containment, and hardening actions.
  • Conduct structured post‑incident reviews: root‑cause analysis, impact measurement, lessons learned, remediation roadmap, and follow‑up with technical teams and management.
  • Plan and lead periodic exercises: tabletop, crisis simulations, collaborative sessions with SOC, red team, blue team to test program maturity, quality of escalations, and operational readiness.
  • Support governance functions with incident classification for regulatory purposes, evidence collection, timeline reconstruction, and presentation of technical elements for escalation or formal notifications.
  • Produce technical reports and executive summaries during and after incidents, ensuring clear, timely, and consistent communication to management, governance, and operational teams.
Requirements
  • At least 7 years of experience in incident response, security operations, or cyber crisis management with demonstrable operational coordination in complex enterprise environments.
  • Proficiency with key IR frameworks: ISO/IEC 27035, SANS IR Process, NIST SP 800‑61 or equivalents; use MITRE ATT&CK for TTP analysis, gap detection, and control improvement.
  • Hands‑on experience with SIEM, EDR/XDR enterprise, forensic analysis tools, and incident handling workflows.
  • Strong knowledge of networks, protocols, system/application logs, and traffic analysis techniques to reconstruct attack vectors, lateral movement, privilege escalation, and persistence.
  • Scripting and automation skills, preferably Python, to support triage, enrichment, evidence collection, repetitive task automation, and workflow customization.
  • Understanding of attack surfaces in hybrid on‑prem/cloud environments, native AWS/Azure logs, cloud identity, container workloads, propagation scenarios, and containment techniques.
  • Ability to make containment decisions with incomplete information, under time pressure, and with potential impact on service, business, and operational continuity.
  • Capability to communicate the same incident across audiences: technical between SOC and infrastructure/app teams; concise, risk‑based, decision‑oriented to management and governance.
  • Ability to orchestrate teams not hierarchically reporting to Cybersecurity, leveraging process, technical authority, clarity of priorities, and communication quality.
  • Excellent command of English.
Gradite
  • Certifications: GCIH, GCFE, GCIA (GIAC) or similar.
  • Deep knowledge of Windows/Linux enterprise, Active Directory (useful for lateral movement and privilege escalation investigations).
  • Experience in banking or regulated financial services.
  • Exposure to threat intelligence platforms (MISP, OpenCTI) and proactive threat hunting techniques.
  • Experience managing major incidents, cyber crisis exercises, or war room operations in regulated contexts.
  • Familiarity with classification, escalation, and regulatory reporting processes for ICT/cyber incidents in finance.
Other Information
  • High visibility role on mission‑critical infrastructure: proprietary platform, core banking, and brokerage used by 1.8 million customers in real time.
  • Hybrid technical environment of real complexity on‑prem/cloud where incidents have direct business impact.
  • Exposure to structured regulatory processes (DORA).
  • Direct responsibility on a substantial perimeter within ICT & Cyber, strategic weight for the bank.
  • High‑profile technical team, problem‑solving culture.
Sede di lavoro

Milano (alternating on‑site presence and smart working).

Il Gruppo Fineco is proud to be an Equal Opportunity Employer and is committed to creating a safe and inclusive workplace based on mutual respect and diversity, offering equal job opportunities. Fineco “The Place To Be”.

Ottieni la revisione del curriculum gratis e riservata.
o trascina qui il file.
Similar jobs

Offerte di lavoro simili che vale la pena confrontare

IT & Security Governance Analyst
IT & Security Governance Analyst

Fineco Bank • Turbigo

Ibrido
EUR 30.000 - 45.000
IT&Security Governance Specialist
IT&Security Governance Specialist

Fineco Bank • Milano

Ibrido
EUR 90.000 - 130.000
Incident Response Lead, Cybersecurity Program
Incident Response Lead, Cybersecurity Program

Fineco Bank • Turbigo

Ibrido
EUR 80.000 - 100.000
Expert Cyber Threat Hunter
Expert Cyber Threat Hunter

Intesa Sanpaolo Group • Napoli

In loco
EUR 45.000 - 70.000
Incident Coordination Specialist
Incident Coordination Specialist

SiliconDev S.p.A. • Milano

Ibrido
EUR 36.000 - 40.000
Work ibrida
SOC & Incident Response Specialist
SOC & Incident Response Specialist

Webuild • Milano

Ibrido
EUR 65.000 - 90.000
buoni pasto
telemedicina
polizza sanitaria
+2
Incident Coordination Specialist
Incident Coordination Specialist

SILICONDEV SPA • Milano

Ibrido
EUR 36.000 - 40.000
Incident Coordination Specialist
Incident Coordination Specialist

SILICONDEV SPA • Roma

Ibrido
EUR 36.000 - 40.000
Senior Cybersecurity Advisor
Senior Cybersecurity Advisor

NTT DATA Europe & Latam • Milano

Ibrido
EUR 90.000 - 110.000
Operational Risk Specialist
Operational Risk Specialist

Fineco Bank • Turbigo

Ibrido
EUR 45.000 - 65.000