Cyber Security incident response Manager

Darwin Recruitment

Amsterdam

Hybrid

EUR 90,000 - 130,000

Full time

46 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Hybrid work model

Job summary

Darwin Recruitment is seeking an experienced Incident Response Manager to join a growing Cyber Security practice in the Netherlands. You will blend hands-on IR expertise with leadership and client engagement to build and shape the IR offering.

The role requires a strong technical background in DFIR, the ability to manage complex incidents, and close collaboration with SOC, Forensics and Threat Intelligence teams. Dutch language is essential and you should be based in the Netherlands.

Qualifications

  • 3–4+ years in Incident Response/DFIR in consulting or MSSP.
  • Experience handling ransomware, phishing, data breaches and APT-like attacks.
  • Knowledge of SIEM, EDR/XDR, cloud investigations.
  • Dutch fluency and Netherlands-based availability.

Responsibilities

  • Lead and grow the Incident Response practice in the Netherlands.
  • Coordinate responses to complex security incidents.
  • Develop playbooks, processes and procedures.
  • Work with SOC, Threat Intelligence and Forensics teams.
  • Participate in on-call Incident Response capability.

Skills

Incident Response
DFIR
Leadership
Threat Intelligence

Tools

SIEM
EDR/XDR
MITRE ATT&CK
NIST

Job description

Incident Response Manager – Cyber Security

Location: Netherlands

Working Model: Hybrid

Language: Fluent Dutch & English

Employment: Permanent

The Opportunity

We are looking for an experienced Incident Response Manager to join a growing Cyber Security practice in the Netherlands.

This is an opportunity to play a key role in building and developing an Incident Response capability that currently consists of two consultants. You will combine hands-on Incident Response expertise with leadership, customer engagement and responsibility for developing the wider practice.

The position would suit someone with a strong technical IR background who is ready to take greater ownership of a team and help shape how the service develops.

Key Responsibilities
  • Help build and grow the Incident Response practice in the Netherlands.
  • Lead and coordinate responses to complex cyber security incidents.
  • Support and develop the existing Incident Response consultants.
  • Manage incidents across triage, investigation, containment, eradication, recovery and post-incident review.
  • Perform and coordinate Digital Forensics & Incident Response (DFIR) activities.
  • Work directly with customers during business-critical security incidents.
  • Develop Incident Response playbooks, processes and procedures.
  • Conduct root-cause analysis and provide recommendations following incidents.
  • Support cyber readiness assessments, tabletop exercises and simulations.
  • Work closely with SOC, Threat Intelligence, Forensics and wider Cyber Security teams.
  • Participate in the team’s on-call Incident Response capability.
  • Help shape the longer-term growth and direction of the IR offering.
Your Background

You should bring approximately 3-4+ years of relevant Incident Response / DFIR experience, ideally gained within a consulting, MSSP or enterprise security environment.

Experience responding to incidents such as ransomware, malware, phishing, account compromise, data breaches and advanced cyber attacks would be highly valuable.

You should also have knowledge of areas such as SIEM, EDR/XDR, endpoint and network investigations, cloud environments, threat intelligence and frameworks including MITRE ATT&CK and NIST.

Previous leadership experience is beneficial, but we are equally interested in strong Senior Incident Response Consultants ready to take the next step into management.

Essential Requirements

Fluent Dutch is required due to the customer-facing and on-call nature of the position.

Candidates must also be based in the Netherlands and comfortable supporting customers locally when required.

This is a strong opportunity for someone who doesn’t simply want to join an established IR function, but wants to help build one and have genuine influence over its future direction.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Incident Response Manager: Lead & Grow Cyber IR
Incident Response Manager: Lead & Grow Cyber IR

Darwin Recruitment • Amsterdam

Hybrid
EUR 90,000 - 130,000
Hybrid work model
Cyber defense specialist incident response
Cyber defense specialist incident response

Forensic Focus • Weert

Hybrid
EUR 66,000 - 84,000
Senior Incident Response & Digital Forensics Lead
Senior Incident Response & Digital Forensics Lead

Forensic Focus • Weert

Hybrid
EUR 66,000 - 84,000
Senior Consultant Incident Response
Senior Consultant Incident Response

Forensic Focus • Amstelveen

Hybrid
EUR 66,000 - 84,000
Security Incident Response
Security Incident Response

Tergos • Eindhoven

On-site
EUR 70,000 - 90,000
European Cybersecurity Site Leader - SOC & CSIRT
European Cybersecurity Site Leader - SOC & CSIRT

IBM • Amsterdam

On-site
EUR 200,000 - 260,000
Principal Consultant – DFIR
Principal Consultant – DFIR

Forensic Focus Limited • Netherlands

Remote
EUR 78,000 - 91,000
Incident Response Tech Lead - Cyber Security
Incident Response Tech Lead - Cyber Security

S-RM Intelligence and Risk Consulting • Utrecht

Hybrid
EUR 90,000 - 120,000
Maternity leave
Paternity leave
Holiday days
+4
Technical Lead, Incident Response Cyber security Utrecht
Technical Lead, Incident Response Cyber security Utrecht

S-RM Intelligence and Risk Consulting • Utrecht

Hybrid
EUR 90,000 - 120,000
Maternity leave
Paternity leave
Holiday days
+4
Incident Response Consultant: Live IR & Digital Forensics
Incident Response Consultant: Live IR & Digital Forensics

Forensic Focus • Amstelveen

Hybrid
EUR 66,000 - 84,000