SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Eye Security is seeking a Manager of Incident Response to lead the Security Operations team responsible for end-to-end incident response and digital forensics work. You will manage a team handling the company's most serious cases—ransomware investigations, business email compromise cases, and complex forensic work—while maintaining hands-on technical credibility to personally lead critical incidents when needed.
Your primary responsibility is people management: conducting regular one-to-ones, providing feedback, and driving performance and development aligned with the company's career framework. You will also lead by example, personally taking point on the most complex or highest-profile incidents to maintain technical credibility and unblock the team.
Key responsibilities include:
- Leading, coaching, and developing the Incident Response team with structured feedback and career conversations
- Managing the incident caseload and team workload, prioritizing by severity and client exposure
- Owning end-to-end service quality: case intake, technical execution, client communication, and reporting
- Establishing and tracking delivery KPIs (time-to-containment, report quality, client satisfaction)
- Managing on-call and case-lead rostering across the team
- Serving as senior escalation point and incident commander for major incidents with legal or regulatory exposure
- Setting and enforcing quality standards for incident reporting through structured peer review
- Driving automation and continuous improvement of IR playbooks, tooling, and processes
- Representing Incident Response in cross-functional discussions with SOC, Prevention, Product, Customer Success, and Legal
Eye Security provides cybersecurity with embedded cyber insurance solutions for SMEs across Europe, combining 24/7 detection and response with hands-on incident response services.
Requirements:
- 6+ years of hands-on incident response and digital forensics experience with deep, current knowledge of DFIR methodology, EDR platforms, cloud security, and attacker TTPs; ability to personally run complex cases
- Proven experience leading or supervising a technical team through high-pressure, time-critical work with genuine interest in coaching and development; first-line management experience or strong informal leadership track record
- Composure and sound judgment under real pressure with incomplete information during live incidents
- Strong incident-report writing skills and ability to review others' reports critically
- Clear, calm, authoritative communication with clients and internal stakeholders during crises
- Fluent English; Dutch required for client-facing work
Nice-to-have:
- Background in CERT, CSIRT, MDR, or DFIR-focused environment
- Experience handling cases with legal or regulatory exposure
- Scripting/automation experience applied to investigation workflows
- Familiarity with compliance frameworks (NIS2, ISO 27001, GDPR)