Blue Team Lead – Detection & Incident Response
We are looking for a Blue Team Lead to join an international cybersecurity team and provide technical leadership in threat detection and incident response. You will help build and maintain detection and response capabilities, guide analysts, and drive security incidents through to resolution.
Requirements
- At least 5 years of experience in incident detection and response.
- Experience in Digital Forensics and Incident Response (DFIR), including tools such as Velociraptor or KAPE.
- Experience with Cortex and vulnerability management.
- Strong incident management skills and a structured approach to investigations.
- Ability to guide analysts, collaborate across teams, and make decisions under pressure.
- Strong written and verbal communication skills.
- A calm, rigorous, and results-oriented approach.
- Good command of English.
Responsibilities
- Provide technical leadership and support analysts’ skills development.
- Detect, investigate, and respond to security incidents across the organization.
- Conduct digital forensic investigations and proactive threat hunting based on threat intelligence.
- Develop and tune detection rules.
- Create and maintain operational runbooks.
- Perform root cause analysis and post-incident reviews.
- Improve incident response plans and detection and response processes.
- Evaluate security technologies to strengthen detection and response capabilities.
- Validate and triage vulnerabilities, tracking remediation through to completion.
- Participate in emergency response activities when required.
- Provide regular reporting on security activities and findings.
Nice to have
- The job description does not specify additional preferred qualifications.
Working conditions
- International environment with English as the working language.
- Close collaboration with the cybersecurity team, reporting to the CISO.
- Opportunity to shape detection and response capabilities across a global organization.
- Participation in emergency response activities when required.