New

Incident Response Manager

Bucharest

Bitdefender is a cybersecurity leader delivering best-in-class threat prevention, detection, and response solutions worldwide. Guardian over millions of consumer, enterprise, and government environments, Bitdefender is one of the industry’s most trusted experts for eliminating threats, protecting privacy, digital identity and data, and enabling cyber resilience. With deep investments in research and development, Bitdefender Labs discovers hundreds of new threats each minute and validates billions of threat queries daily. The company has pioneered breakthrough innovations in antimalware, IoT security, behavioral analytics, and artificial intelligence and its technology is licensed by more than 180 of the world’s most recognized technology brands. Founded in 2001, Bitdefender has customers in 170+ countries with offices around the world. For more information, visit https://www.bitdefender.com

The Enterprise Support and Services team based in Bucharest is looking for a new enthusiastic member!

As an Incident Response Manager, you will be reporting directly to the Director of Enterprise Support and Services. You will lead the coordination of security incidents affecting our enterprise customers, acting as incident commander from identification through resolution and post-incident review. You will also be the bridge between Enterprise Support and Services and our digital forensics and incident response (DFIR) team, ensuring that incidents flow smoothly between the two organizations, with clear ownership, clean hand-offs and no loss of momentum.

This is a senior position. We are looking for someone who has managed security incidents before and can establish the incident response processes, escalation paths and playbooks that keep response fast and well-coordinated. The right person will be comfortable interfacing with clients and managing intricate and sensitive client relationships, remaining composed and decisive under pressure, and fostering these relationships until resolution has been reached. For our strategic accounts, you will act as a trusted advisor and their voice inside the company during and after an incident.

We expect the ideal candidate to contribute to our positive team culture by sharing our values: outstanding service to our customers, partners, and each other; respect, accountability, and excellence in everything we do.

In this process, you will work closely with the DFIR team, enterprise support engineers and escalation managers, as well as security or sales experts, in a dynamic and competitive environment, which will enrich your experience and broaden your perspective.

Responsibilities

  • Lead the coordination of major security incidents affecting enterprise customers, acting as incident commander from identification through containment, resolution and post-incident review
  • Act as the primary interface between Enterprise Support and Services and the DFIR team, ensuring clear ownership, clean hand-offs and effective collaboration throughout the incident lifecycle
  • Establish and maintain incident response processes, escalation paths and playbooks, and continuously improve them based on lessons learned
  • Act as a trusted advisor and the voice of strategic accounts inside the company during and after security incidents
  • Coordinate containment, eradication and recovery activities together with the DFIR team, the MDR SOC and engineering teams
  • Provide clear, timely and accurate status updates to customers and internal senior stakeholders, tailoring the message to each audience
  • Initiate and manage the hierarchical escalation process for high-severity incidents, engaging senior stakeholders when needed
  • Own the post-incident review process: after-action reports, lessons learned and follow-up actions tracked to closure
  • Support incident readiness through playbook development, tabletop exercises and escalation drills
  • Define, monitor and report on incident management KPIs and SLAs, and use these insights to drive continuous service improvement
  • Participate in an on-call rotation to ensure incident response coverage outside standard business hours
  • Build strong relationships with other internal teams: DFIR, MDR SOC, enterprise support, product delivery, product management and sales
  • Adhere to our company’s values and principles

Technical requirements

Minimum 5 years of professional experience in the following areas:

  • Incident response management, with proven experience running major security incidents end to end
  • Building or maturing incident response processes, playbooks and escalation procedures
  • Working alongside or within DFIR, SOC or security operations teams
  • Good understanding of attacker tactics, techniques and procedures (TTPs) and the MITRE ATT&CK framework
  • IT Service Management and incident management processes (ITIL knowledge is desirable)
  • Strong IT technical background: operating systems, virtualization, networking

Working knowledge of IT security technologies, for example:

  • EDR / XDR
  • SIEM and security monitoring
  • Network security (firewalls, IDS/IPS, VPN)
  • Cloud and email security
  • Threat intelligence and threat hunting

Other requirements

  • Industry-standard incident response certifications – GIAC (e.g., GCIH, GCFA, GNFA) and/or CREST (e.g., CREST Certified Incident Manager) – or equivalent
  • Proven ability to remain composed and lead effectively in high-stress, high-pressure situations
  • Excellent verbal and written communication skills, quick learner, dynamic, energetic and customer-oriented
  • Able to translate technical findings for executive and non-technical audiences
  • Proven ability to lead, influence, and coordinate across functional groups not directly in the reporting structure
  • Experience creating and improving procedures, processes and documentation
  • Experience implementing methodologies to improve customer satisfaction and build strong internal relationships
  • Work independently; receive minimal guidance
  • Experience dealing with international teams and customers
  • Demonstrated strong work ethic
  • Ability to work in a fast-paced environment
  • Availability to participate in an on-call rotation
  • Prior experience working with business applications, like Salesforce, Jira, Office
  • Fluent in both written and spoken Romanian and English
  • French is a plus

    #LI-SA1

Create a Job Alert

Interested in building your career at Bitdefender? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...