Description
Bitdefender is a cybersecurity leader delivering best-in-class threat prevention, detection, and response solutions worldwide.
Guardian over millions of consumer, enterprise, and government environments, Bitdefender is one of the industry’s most trusted experts for eliminating threats, protecting privacy, digital identity and data, and enabling cyber resilience.
With deep investments in research and development, Bitdefender Labs discovers hundreds of new threats each minute and validates billions of threat queries daily.
The company has pioneered breakthrough innovations in antimalware, IoT security, behavioral analytics, and artificial intelligence and its technology is licensed by more than 180 of the world’s most recognized technology brands.
Founded in 2001, Bitdefender has customers in 170+ countries with offices around the world.
For more information, visit https://www.bitdefender.comThe Enterprise Support and Services team based in Bucharest is looking for a new enthusiastic member!
As an Incident Response Manager, you will be reporting directly to the Director of Enterprise Support and Services.
You will lead the coordination of security incidents affecting our enterprise customers, acting as incident commander from identification through resolution and post-incident review.
You will also be the bridge between Enterprise Support and Services and our digital forensics and incident response (DFIR) team, ensuring that incidents flow smoothly between the two organizations, with clear ownership, clean hand-offs and no loss of momentum.
This is a senior position.
We are looking for someone who has managed security incidents before and can establish the incident response processes, escalation paths and playbooks that keep response fast and well-coordinated.
The right person will be comfortable interfacing with clients and managing intricate and sensitive client relationships, remaining composed and decisive under pressure, and fostering these relationships until resolution has been reached.
For our strategic accounts, you will act as a trusted advisor and their voice inside the company during and after an incident.
We expect the ideal candidate to contribute to our positive team culture by sharing our values: outstanding service to our customers, partners, and each other; respect, accountability, and excellence in everything we do.
In this process, you will work closely with the DFIR team, enterprise support engineers and escalation managers, as well as security or sales experts, in a dynamic and competitive environment, which will enrich your experience and broaden your perspective.
Responsibilities
Lead the coordination of major security incidents affecting enterprise customers, acting as incident commander from identification through containment, resolution and post-incident review
Act as the primary interface between Enterprise Support and Services and the DFIR team, ensuring clear ownership, clean hand-offs and effective collaboration throughout the incident lifecycle
Establish and maintain incident response processes, escalation paths and playbooks, and continuously improve them based on lessons learned
Act as a trusted advisor and the voice of strategic accounts inside the company during and after security incidents
Coordinate containment, eradication and recovery activities together with the DFIR team, the MDR SOC and engineering teams
Provide clear, timely and accurate status updates to customers and internal senior stakeholders, tailoring the message to each audience
Initiate and manage the hierarchical escalation process for high-severity incidents, engaging senior stakeholders when needed
Own the post-incident review process: after-action reports, lessons learned and follow-up actions tracked to closure
Support incident readiness through playbook development, tabletop exercises and escalation drills
Define, monitor and report on incident management KPIs and SLAs, and use these insights to drive continuous service improvement
Participate in an on-call rotation to ensure incident response coverage outside standard business hours
Build strong relationships with other internal teams: DFIR, MDR SOC, enterprise support, product delivery, product management and sales
Adhere to our company’s values and principles
Technical requirements
Minimum 5 years of professional experience in the following areas:
Incident response management, with proven experience running major security incidents end to end
Building or maturing incident response processes, playbooks and escalation procedures
Working alongside or within DFIR, SOC or security operations teams
Good understanding of attacker tactics, techniques and procedures (TTPs) and the MITRE ATT&CK framework
IT Service Management and incident management processes (ITIL knowledge is desirable)
Strong IT technical background: operating systems, virtualization, networking
Working knowledge of IT security technologies, for example:
EDR / XDR
SIEM and security monitoring
Network security (firewalls, IDS/IPS, VPN)
Cloud and email security
Threat intelligence and threat hunting
Other requirements
Industry-standard incident response certifications – GIAC (e.g., GCIH, GCFA, GNFA) and/or CREST (e.g., CREST Certified Incident Manager) – or equivalent
Proven ability to remain composed and lead effectively in high-stress, high-pressure situations
Excellent verbal and written communication skills, quick learner, dynamic, energetic and customer-oriented
Able to translate technical findings for executive and non-technical audiences
Proven ability to lead, influence, and coordinate across functional groups not directly in the reporting structure
Experience creating and improving procedures, processes and documentation
Experience implementing methodologies to improve customer satisfaction and build strong internal relationships
Work independently; receive minimal guidance
Experience dealing with international teams and customers
Demonstrated strong work ethic
Ability to work in a fast-paced environment
Availability to participate in an on-call rotation
Prior experience working with business applications, like Salesforce, Jira, Office
Fluent in both written and spoken Romanian and English
French is a plus#LI-SA1