JustMarkets

JustMarkets

JustMarkets is a leading online trading platform that offers a wide range of financial instruments including Forex, CFDs, Gold, and Oil. With low spreads, high leverage up to 1:3000, and fast execution, JustMarkets provides a next-level trading experie...

Capital Markets
1-10

Description

  • Lead incident response, containment, eradication, recovery, and forensic coordination for confirmed security incidents.
  • Act as Incident Commander for major security incidents and assign investigation, containment, and recovery responsibilities.
  • Coordinate investigations across endpoints, servers, identities, cloud platforms, SaaS environments, and network telemetry.
  • Direct forensic collection and analysis to determine attack paths, scope, persistence, and impact.
  • Coordinate containment and recovery actions with IAM, IT, Platform, Security Engineering, Product, and other technical teams.
  • Maintain incident timelines, evidence logs, decision records, action tracking, and evidence-handling standards.
  • Develop and maintain incident playbooks, forensic checklists, and containment procedures.
  • Lead post-incident reviews, root-cause analysis, remediation tracking, and incident-readiness exercises.
  • Identify detection and forensic-readiness gaps and translate findings into recommendations for security control owners.
  • Mentor Incident Response and DFIR Specialists and coordinate with external forensic providers when needed.

Requirements

  • Strong hands-on knowledge of the full incident response lifecycle, including investigation, containment, eradication, recovery, and lessons learned.
  • Experience leading complex security incidents and coordinating multiple technical teams during active response.
  • Practical experience investigating endpoint, identity, server, cloud, or network compromises using EDR/XDR, SIEM, and audit logs.
  • Ability to reconstruct attacker activity, including initial access, credential abuse, persistence, privilege escalation, lateral movement, data access, and exfiltration.
  • Working knowledge of digital forensics, evidence preservation, forensic timelines, and chain-of-custody principles.
  • Experience designing and validating containment actions such as endpoint isolation, credential rotation, indicator blocking, and service isolation.
  • Experience investigating Microsoft Entra ID and Active Directory incidents.
  • Understanding of ransomware, malware, phishing/BEC, account takeover, cloud/SaaS compromise, data exfiltration, and insider misuse.
  • Strong investigation-focused knowledge of Windows, Linux, identity systems, and enterprise networking.
  • Preferred: Experience with Cortex XDR, Elastic Security, AWS, forensic tools, scripting, incident exercises, regulated environments, or external DFIR providers.
  • Preferred: Relevant certifications such as GCIH, GCFA, GCFE, GNFA, OSCP, CISSP, or equivalent.

Benefits

  • 20 paid vacation days per year.
  • 10 paid sick leave days per year.
  • Medical budget.
  • Remote work opportunity.
  • Professional education budget.
  • Language learning budget.
  • Wellness budget for gym membership, sports gear, and related expenses.
  • Public holidays according to the company-approved holiday list.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Cyber Security Specialist

RecargaPay 251-1K Capital Markets

RecargaPay is hiring a Cyber Security Specialist to join its remote CSIRT team and lead detection, response, containment, and automation for security incidents across its cloud-native payments platform.

AWS Bash CrowdStrike Cybersecurity Elasticsearch Kibana Linux Python
1 hour, 48 minutes ago

GRC Security Analyst - Information Security

Appfire 251-1K Internet Software & Services

Appfire is hiring a fully remote GRC Security Analyst in Spain to support governance, risk management, compliance, vendor assessments, and audit readiness for its growing Atlassian app business.

Azure Heroku
1 day, 1 hour ago

GRC Security Analyst - Information Security

Appfire 251-1K Internet Software & Services

Appfire is seeking a GRC Security Analyst to support governance, risk, compliance, vendor assessments, and audit readiness across its globally distributed Atlassian app business.

Azure Heroku
1 day, 1 hour ago

GRC Security Analyst - Information Security

Appfire 251-1K Internet Software & Services

Appfire is hiring a GRC Security Analyst in Bulgaria to manage information security governance, risk, compliance, vendor reviews, remediation, and audit support for its growing Atlassian app business.

AWS Azure Heroku
2 days ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers