Lead Incident Response

Eye Security

Den Haag

On-site

EUR 90,000 - 130,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Eye Security seeks an Incident Response Lead to join our Security Operations department in the Netherlands. You will lead the people who own our most serious cases end to end, coordinating ransomware and BEC investigations, doing the forensic work, and being the person on the phone when a client needs a straight answer under real pressure.

Your first responsibility is people, not just process. You’re a first-line manager with direct accountability for the performance and development of your

Qualifications

  • 6+ years hands-on incident response and digital forensics experience.
  • Proven leadership and people-management experience.
  • Strong incident-report writing and client communication under pressure.
  • Fluent English; Dutch (C2) required for client-facing work.

Responsibilities

  • Lead, coach, and develop the Incident Response team with regular feedback and performance reviews.
  • personally handle the most complex or high-profile incidents when needed.
  • Oversee end-to-end incident response: intake, coordination, technical execution, and reporting.
  • Own delivery KPIs (time-to-containment, case quality, client satisfaction) and escalate when targets are at risk.
  • Manage on-call and case-lead rostering, prioritising by severity and client exposure.
  • Act as senior escalation point and incident commander for major incidents when required.
  • Drive quality assurance for incident reporting and run structured peer reviews.
  • Scale automation in evidence collection, timeline building, and reporting with engineering support.
  • Improve IR playbooks, tooling, and SOPs to reflect volume and learnings.
  • Represent Incident Response in cross-functional discussions with SOC, Prevention, Product, and Legal.

Skills

Incident Response
Leadership
People Management
English (Fluent)
Dutch (C2)

Tools

EDR
Cloud Security

Job description

About this role

We are looking for an Incident Response Lead to join our Security Operations department.

You will lead the people who own our most serious cases end to end - coordinating ransomware and business email compromise investigations, doing the forensic work, and being the person on the phone when a client needs a straight answer under real pressure.

Your first responsibility is people, not just process. You're a first-line manager distinct from a senior individual contributor, with direct accountability for the performance and development of your team - while carrying enough hands-on DFIR credibility to run the most complex case yourself, or take over one mid-flight, when the situation demands it.

What you will do
  • Lead, coach, and develop the Incident Response team: regular one-to-ones, feedback, and performance/development conversations aligned with Eye's career framework
  • Lead by doing: manage the caseload and the people, but personally take point on the most complex or highest-profile incidents when needed
  • Own end-to-end incident response service quality: case intake and coordination, technical execution, client communication, and closure/reporting
  • Own delivery KPIs (time-to-containment, case-report quality and timeliness, client satisfaction on incident cases) and step in to unblock the team or personally lead a case when targets are at risk
  • Manage on-call and case-lead rostering and workload across the team, prioritising by severity and client exposure
  • Act as the senior escalation point and, when needed, incident commander for major incidents - large ransomware, multi-entity BEC, or cases with legal/regulatory exposure
  • Own quality assurance for incident reporting: set the reporting standard and run structured peer review of case reports before they reach the client
  • Own and scale automation across the function's casework (evidence collection, timeline building, reporting), partnering with engineering where it makes sense
  • Drive continuous improvement of IR playbooks, tooling, and process as case volume grows; keep runbooks and SOPs accurate and actually used
  • Represent Incident Response in cross-functional discussions with SOC, Prevention, Product, Customer Success, and Legal where relevant
What you will need
  • Technical: 6+ years of hands-on incident response / digital forensics experience with deep, current knowledge of DFIR methodology, EDR platforms, cloud security, and attacker TTPs; able to personally run a complex case, not just sign off on one
  • Leadership: composure and sound judgement under real pressure, often with incomplete information, during live incidents; strong incident-report writing and a sharp eye for reviewing others’ reports; clear, calm, authoritative communication with clients and internal stakeholders during a crisis
  • People management: proven experience leading or supervising a technical team through high-pressure, time-critical work, with a genuine interest in coaching people and helping them grow; first-line management experience or a strong informal leadership track record
  • Fluent English; Dutch (C2) required for client-facing work
Nice-to-have
  • Background in a CERT, CSIRT, MDR, or DFIR-focused environment
  • Experience handling cases with legal or regulatory exposure
  • Scripting/automation experience applied to investigation workflows
  • Familiarity with compliance frameworks relevant to SMEs (NIS2, ISO 27001, GDPR)
About Eye Security

Eye Security provides cybersecurity with embedded cyber insurance solutions for organisations across Europe. Headquartered in the Netherlands, we combine 24/7 detection and response with hands-on incident response to keep SMEs protected, and we're growing internationally. When a client's worst day happens, this is the team that shows up.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Incident Response Lead — DFIR Team Coach & Case Commander
Incident Response Lead — DFIR Team Coach & Case Commander

Eye Security • Den Haag

On-site
EUR 90,000 - 130,000
Cyber Security incident response Manager
Cyber Security incident response Manager

Darwin Recruitment • Amsterdam

Hybrid
EUR 90,000 - 130,000
Hybrid work model
Security Incident Response
Security Incident Response

Tergos • Eindhoven

On-site
EUR 70,000 - 90,000
International Contract Bench, Incident Response (DFIR)
International Contract Bench, Incident Response (DFIR)

Jobgether SRL • Netherlands

On-site
EUR 60,000 - 100,000
Flexible contract engagement
Exposure to complex investigations
Work with an experienced IR/DFIR team
Cyber defense specialist incident response
Cyber defense specialist incident response

Forensic Focus • Weert

Hybrid
EUR 66,000 - 84,000
Senior Incident Response Lead (MDR Security)
Senior Incident Response Lead (MDR Security)

Eye Security • Amsterdam

On-site
EUR 70,000 - 100,000
Generous time-off policy
Remote-friendly culture
Quarterly meetups and annual retreats
Staff Product Manager – German Speaking - Managed Detection and Incident Response (m/f/x)
Staff Product Manager – German Speaking - Managed Detection and Incident Response (m/f/x)

Eye Security • Den Haag

Hybrid
EUR 120,000 - 160,000
Remote-friendly culture
Quarterly meetups
Annual retreats
+3
Senior Incident Response & Digital Forensics Lead
Senior Incident Response & Digital Forensics Lead

Forensic Focus • Weert

Hybrid
EUR 66,000 - 84,000
Staff Product Manager – German Speaking - Managed Detection and Incident Response (m/f/x)
Staff Product Manager – German Speaking - Managed Detection and Incident Response (m/f/x)

Eye Security • Netherlands

Hybrid
GBP 110,000 - 160,000
Meaningful mission
Top-tier professionals
Strategic ownership
+6
Junior Cyber Security Consultant (m/f/x)
Junior Cyber Security Consultant (m/f/x)

Eye Security • Rotterdam, Den Haag

On-site
EUR 38,000 - 58,000
Remote-friendly culture
Regular team meetups
Career development