This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
This role will lead enterprise-wide incident response efforts, ensuring effective coordination, analysis, and remediation of cybersecurity events. It involves managing the full incident lifecycle, maintaining compliance, and continuously improving response capabilities through planning, testing, and cross-functional collaboration.
Job Responsibility:
Lead enterprise-wide incident response efforts, ensuring effective coordination, analysis, and remediation of cybersecurity events
Manage the full incident lifecycle, maintaining compliance, and continuously improving response capabilities through planning, testing, and cross-functional collaboration
Directs and coordinates teams across the organization during security investigations and vendor-related incidents, overseeing the full lifecycle from detection to resolution
Monitors and evaluate server and network activity to identify vulnerabilities and emerging threats
Serves as the primary point of contact during incidents, managing communications and driving remediation efforts
Maintains and improves the Security Incident Response Plan (SIRP), aligning with frameworks like NIST, ISO 27035, and MITRE ATT&CK
conducts tabletop exercises to validate readiness
Ensures adherence to legal and regulatory requirements, tracks KPIs, and provides updates to executives and technical teams throughout the response process
Requirements:
10-15 years in security operations and incident response
2+ years in leadership role managing internal teams and MSSPs during cybersecurity events
Bachelor’s degree in Cybersecurity, Information Technology, or a related discipline
Strong understanding of threat landscapes, attack vectors, malware behavior, and forensic techniques
Proficient in using and interpreting data from IR tools like SIEM and EDR
Capable of working flexible hours during active incidents to support global response efforts across multiple time zones
Proficient in English for effective communication and coordination
Nice to have:
Industry-recognized credentials such as GCIH, GCFA, GCIA, GNFA, CISM, or CISSP are highly desirable
Bi-lingual in English and Korean language proficiency is preferred
Background in cybersecurity consulting or advisory services, particularly in incident response, is a plus
Familiarity with cloud platforms like Azure, AWS, and GCP enhances effectiveness