CSIRT Level 3
The mission
MISSIONS AND RESPONSIBILITIES
Within a leading structure specializing in cybersecurity, the job holder will act as a reference expert for complex threat management. Their main missions include:
Supervision of the complete alert processing cycle: from initial collection to the technical qualification of threats.
Operational direction of incident interventions: definition of scope, containment, neutralization, and remediation strategy.
In-depth investigation of malicious samples to isolate actionable indicators of compromise (IOC).
Conducting proactive threat hunting campaigns within complex environments.
Formalization of high-level deliverables, including executive summaries, detailed timelines, and strategic recommendations.
Constant optimization of operational processes and response guides (playbooks).
Participation in an on-call rotation to ensure continuity of service during major crises.
Cross-functional coordination with monitoring centers (SOC) and threat intelligence hubs to strengthen detection capabilities.
Technical mentoring and operational steering of lower-level analysts during crisis phases.
EVOLUTION PERSPECTIVES
This international group offers an environment conducive to structured career progression, allowing for the expansion of one's field of action through various opportunities:
A framework promoting professional fulfillment and the strengthening of cross-functional skills.
The possibility to evolve into varied scopes, whether it be new business sectors, high-complexity projects, or geographic mobility.
A choice of flexible trajectories between cutting-edge technical specialization or an orientation toward management and leadership functions.
Integration within a global engineering organization offering visibility and international career perspectives.
Desired Profile
DESIRED PROFILE
Our client, a major player in cybersecurity, is looking for an incident response expert to strengthen its high-level operations. The ideal candidate has a higher academic background (Master's degree, engineer, or equivalent) completed by solid operational experience of at least five years within a security operations center or an emergency response team.
Leadership and human management: Demonstrated ability to unite teams, stimulate collective intelligence, and support the skill development of employees.
Crisis management: Ability to maintain total clarity under pressure, combined with the methodological rigor indispensable during the resolution of critical incidents.
Client posture: Excellent interpersonal skills, including proven experience in account management and direct consulting with various stakeholders, even in high-tension contexts.
Communication: Talent for technical popularization, allowing for the translation of complex issues into strategic recommendations for non-technical decision-makers.
Mobility and adaptability: Availability for frequent travel, operational flexibility, and possession of a driver's license.
Languages: Professional proficiency in English (minimum B2 level). Proficiency in French and an additional regional language is an asset.
TECHNICAL SKILLS
The position requires sharp technical expertise and the ability to intervene in heterogeneous environments:
Forensics and Investigation Expertise: Mastery of digital investigation methodologies on server infrastructures, networks, and cloud ecosystems, supported by recognized industry certifications.
Threat Analysis: Advanced skills in malware reverse engineering (static and dynamic analysis) and regular practice of Threat Hunting by relying on attacker tactics and techniques frameworks.
Mastery of artifacts: In-depth knowledge of system traces and indicators of compromise within operating environments.
Monitoring and Intelligence: Ability to integrate Threat Intelligence into the monitoring of malicious group operating modes.
Document production: Writing excellence in English for the formalization of incident reports and the definition of pragmatic remediation plans.
Automation: Mastery of scripting languages (Python, PowerShell, Bash) to optimize and maintain the team's intervention tools.
Multi-project management: Ability to simultaneously manage several complex incident files without compromising the quality of deliverables.
Required skills and experience
Highly motivated, interested in the fields of cyber defence and research
Experience in a similar job (in incident responses regarding cybersecurity)
Requires analytical thinking skills or analytical and problem-solving skills.
English B2 minimum
The company
A major player on the global technological scene accompanies public institutions and private organizations in securing their digital exchanges. At the heart of this mission, the challenge is to guarantee the integrity and reliability of daily interactions between systems and their users.
This entity deploys a complete ecosystem of advanced solutions, ranging from robust software architecture to cutting-edge encryption mechanisms, including biometric authentication systems. The objective is twofold:
Reliability of access: Ensuring rigorous verification of digital identities in complex environments.
Protection of information assets: Implementing sophisticated defense protocols to preserve the confidentiality and longevity of sensitive data.
Possible work location(s)
Contern, Luxembourg
Required experience
5 year(s)
Required education
Master (I or II)
Required skills
Analytical thinking / C (programming language) / Python (programming language) / Wireshark / Snort (intrusion detection system)
Required languages
English / French