Cyber Security Incident Responder

Ørsted

Warszawa

Hybrid

PLN 180,000 - 280,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Ørsted is seeking a cybersecurity professional to lead incident response and drive cyber defence activities across IT and OT. You will analyze events, determine root causes, and inform stakeholders to strengthen security postures worldwide.

Collaborate with security teams, intelligence vendors, and authorities, maintain 24/7 readiness, develop playbooks, and advance threat hunting through forensic investigations.

Qualifications

  • Several years of incident response experience.
  • Experience with cloud logs, network captures, and forensic images.
  • Knowledge of SIEM, XDR and networking.
  • Strong communication skills with stakeholders.
  • GCFA/GCFE or similar certifications preferred.

Responsibilities

  • Lead incidents and act as a technical analyst in cyber response activities across IT and OT environments globally.
  • Analyze and understand security events and incidents to determine root cause and impact.
  • Inform stakeholders and improve Ørsted's security posture through reporting and lessons learned.
  • Collect incident data and coordinate analyses.
  • Write and update incident analyst playbooks at operational and coordination levels.
  • Design and execute intelligence-based threat hunting and drive forensic investigations to completion.
  • Maintain 24/7 readiness to respond to cyber-attacks globally.

Skills

Incident response
SIEM
XDR
Networking
Threat hunting
Technical writing
Communication
GCFA GCFE

Job description

Join us in this role where you’ll take charge of cybersecurity incidents and drive and develop our cyber response, threat hunting, and forensic investigation activities to protect our company, our employees, the production assets, and intellectual property from threat actors that seek harm to us and our partners. We invest in modern and advanced technologies to support the team members.

You’ll be part of Cyber Defence Centre where you, together with your colleagues, will work in close collaboration with other security departments, intelligence vendors, and national authorities around the world. The work environment is very healthy and diverse. You’ll have time to focus, deep dive, learn, and improve, so you’re the best at what you do, and you’ll have plenty of opportunities to excel, innovate, and push the conventional boundaries further. As a team, we are constantly developing, so you’ll find challenges that keep you motivated for months ahead.

You’ll play an important role in:
  • leading incidents and being a technical analyst in cyber response activities, both in IT and OT environments globally within the Cyber Defence Centre
  • analyzing and understanding information security events as well as analyzing incidents to identify root cause and impact
  • informing stakeholders and improving Ørsted’s security posture based on reporting and lessons learned from incidents
  • collecting incident report information and coordinating analyses
  • technical writing and updating incident analyst playbooks on operational and coordination level
  • designing and executing intelligence-based threat hunting activities and driving forensic investigations to completion
  • maintaining our 24/7 readiness in responding to cyber-attacks against Ørsted, around the globe.
To succeed in the role, you:
  • have some years of incident response experience
  • understand a broad palette of source material, whether cloud-related logs, network captures and forensic images
  • have experience in SIEM, XDR, networking and similar technologies
  • have a well-developed sense for communication to key stakeholders
  • are self-driven with in-depth technical knowledge, are curious in nature, and a team player
  • can keep updated on the latest developments in cybersecurity, supported by inputs from the team and formal training
  • have industry wide recognized certifications such as GCFA, GCFE or similar.

Maybe you’ve read the above and can see you have some transferable skills, even though they don’t quite match all the points. If you think you can bring something to the team, we still encourage you to apply.

As an applicant or employee, you may request reasonable work and position accommodation or adjustments via accommodation@orsted.com.

Please note that for your application to be taken into consideration, you must submit your application via our online career pages and answer the screening questions relevant for your country. We don't take applications or inquiries from external recruiters or agencies into account for this position.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Incident Responder
Cyber Security Incident Responder

Ørsted A/S • Warszawa

On-site
PLN 180,000 - 270,000
Cybersecurity Incident Response Analyst
Cybersecurity Incident Response Analyst

Hitachi Energy • Kraków

Hybrid
PLN 120,000 - 180,000
Competitive salaries
Flexible working hours
Professional development opportunities
+1
Senior IT Security Specialist Automation
Senior IT Security Specialist Automation

Nordea • Warszawa

Hybrid
PLN 180,000 - 240,000
Hybrid working model
Cybersecurity Incident Response Analyst
Cybersecurity Incident Response Analyst

Hitachi Vantara Corporation • Kraków

Hybrid
PLN 120,000 - 180,000
OT Security Engineer
OT Security Engineer

Ramboll • Warszawa

On-site
PLN 120,000 - 160,000
OT Security Engineer
OT Security Engineer

Ramboll • Poland

On-site
PLN 180,000 - 240,000
Cyber Incident & Response Team Analyst
Cyber Incident & Response Team Analyst

Euroclear • Poland

Hybrid
PLN 180,000 - 260,000
Competitive benefits
Hybrid work model
Security Engineer – Incident Response Team (f/m/x)
Security Engineer – Incident Response Team (f/m/x)

Sii Sweden AB • Warszawa

On-site
PLN 120,000 - 180,000
Cybersecurity Incident Response Analyst
Cybersecurity Incident Response Analyst

ITDS • Kraków

Hybrid
PLN 180,000 - 240,000
Hybrid work model
Security Engineer – Incident Response Team (f/m/x)
Security Engineer – Incident Response Team (f/m/x)

Sii Ukraїna TOV • Warszawa

On-site
PLN 120,000 - 180,000