Responsibilities
- Serve as the single accountable leader during active responses for high-severity incidents, directing investigative focus from detection through recovery while maintaining a calm and decisive demeanor under pressure.
- Ensure our response strategies and forensic evidence gathering align with strict reporting requirements for GDPR, PCI-DSS, NIS2, DORA, MAS TRM, and other regional mandates.
- Lead blameless post-incident reviews to ensure continuous improvement, durable engineering solutions, and systemic resilience.
- Serve as the primary interface to stakeholders during critical security incidents, translating complex technical realities into clear risk, impact, and decision frameworks.
- Design and develop in-house solutions, automated workflows, and scalable systems to eliminate repetitive processes, reduce triage time, and continuously improve the overall quality and efficiency of our security incident response operations.
- Act as a hands-on technical leader and role model, actively mentoring teams and individuals within your domain to raise the overall technical bar and share your experience.
- Define, track, and improve core operational metrics (MTTD, MTTR) to identify systemic gaps and propose strategic, long-term security investments.
- Proactively design and facilitate complex, realistic tabletop simulations and purple team engagements to stress-test our playbooks, uncover detection blind spots, and train the wider security and engineering organizations.
- Participate in a predictable on-call rotation as an Incident Responder, leading the charge on high-severity, out-of-hours escalations.
Requirements
- Proven experience leading end-to-end security incident response for high-severity incidents in a global, high-transaction environment.
- Deep understanding of global compliance frameworks including GDPR, PCI-DSS, NIS2, DORA, MAS TRM.
- Strong 'builder mindset' — ability to approach operational bottlenecks as engineering problems.
- Hands-on technical leadership with experience building systems, developing custom tooling, and architecting automated workflows.
- Ability to make high-consequence decisions during times of ambiguity.
- Experience with incident command and maintaining calm under pressure.
- Proven ability to translate complex technical realities into clear risk, impact, and decision frameworks for stakeholders.
- Experience leading blameless post-incident reviews and driving systemic remediation.
- Data-driven mindset with ability to define and improve core security metrics (MTTD, MTTR).
- Experience designing and facilitating tabletop exercises and purple team engagements.
Nice to Have
- Background in environments spanning logistics, e-commerce, and FinTech.
- Prior experience in highly regulated industries.
Work Arrangement
Remote (Worldwide)
Additional Information
- Participation in a predictable on-call rotation as an Incident Responder.