Cyber Defence Expert - Incident Management & Response
On-siteStockholm, Stockholm, Sweden
Job Summary
Lead end-to-end cyber incident response activities across detection, triage, analysis, containment, eradication, recovery, and closure. Act as incident commander or senior response lead for high-severity cyber incidents, ensuring clear ownership, decision-making, and escalation. Design and maintain incident response frameworks, playbooks, and operating procedures while coordinating technical investigations across SOC, infrastructure, cloud, and third-party teams. Drive post-incident reviews, root cause analysis, and measurable improvements to reduce recurrence. Mature SOC operations by defining metrics, SLAs, and KPIs, providing governance for managed providers, and strengthening SIEM, SOAR, EDR, and cloud security workflows. Own detection engineering capabilities, translating threat intelligence into actionable use cases and driving automation through SOAR playbooks. Lead crisis coordination during major incidents, preparing executive briefings and collaborating with legal, privacy, and business continuity teams. Plan and support tabletop simulations to validate response capabilities.
Required Qualifications
- Minimum 8 years of experience in security operations, cyber defence, incident response or related cybersecurity roles
- Strong hands-on experience leading or coordinating high-severity cyber incidents in complex enterprise environments
- Deep understanding of SOC operations, alert triage, escalation management, incident handling, threat detection and response workflows
- Experience with SIEM, SOAR, EDR, NDR, XDR, identity security, cloud security monitoring and managed security service providers
- Strong understanding of incident response frameworks and methodologies such as NIST, ISO 27035, SANS/PICERL and MITRE ATT&CK
- Ability to communicate clearly during incidents, including concise executive updates, technical coordination and post-incident reporting
- Proven ability to drive continuous improvement across people, process, tooling, governance and operational performance
- Relevant bachelor's or master's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or equivalent practical experience
- Position based at our Global Headquarters in Stockholm (Sweden)
- English is the natural language
- Background check may be conducted on the final candidate(s)
Desired Qualifications
- Relevant certifications are considered an advantage, such as CISSP, GCIH, GCIA, GCFA, GSEC, OSCP, CEH, Microsoft Security certifications or cloud security certifications
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.