NVISO logo

Cyber Incident Manager

Hiring from
Belgium
Work type
Hybrid
Posted
Is this job info correct?
Show job description

It all starts with the mission: NVISO is here to protect European society from potentially devastating cyber attacks. This means we offer cyber security services to private and governmental organizations to help them better prepare for, prevent, detect and respond to cyber security incidents. All of this is built on four fundamental values that define who we are: We are Proud, We Break Barriers, We Care and No BS!

As our Cyber Incident Manager, you will lead NVISO’s response to high-impact cyber incidents and act as the primary customer-facing decision-maker throughout the engagement. You will take ownership of the full incident lifecycle, from initial triage and scoping through investigation, containment, eradication, recovery, and post-incident improvement. You bring structure to complex, fast-moving situations by establishing the response model, defining priorities and investigative questions, coordinating technical and business workstreams, and ensuring decisions and actions are clearly documented and followed through. Working closely with Incident Responders, Digital Forensics specialists, Threat Intelligence, legal, IT, risk, data protection, communications, and customer leadership, you translate technical findings and business impact into clear, practical recommendations for senior stakeholders. Your role is to keep the response focused, coordinated, and effective, enabling the customer to make timely, well-informed decisions while the technical team investigates and contains the incident.

Your responsibilities

  • Act as Incident Lead during active engagements, coordinating the technical response team and steering decisions on containment, eradication, recovery, evidence preservation, and business continuity.
  • Assess incoming incidents, determine their severity and potential business impact, and ensure the right people, expertise, and escalation paths are activated quickly.
  • Run customer and internal incident calls, establish an effective war-room cadence, and keep a clear incident timeline, decision log, action tracker, and stakeholder map.
  • Serve as the primary point of contact for customer leadership during incidents, delivering concise, factual, and timely updates on the situation, business impact, decisions required, response progress, and next steps.
  • Produce and quality-review high-quality incident deliverables, including executive updates, status reports, incident reports, root-cause analysis, and actionable remediation roadmaps.
  • Ensure the incident response follows the agreed response framework, engagement scope, evidence-handling requirements, and applicable regulatory, contractual, and organisational obligations.
  • Coordinate with legal, privacy, risk, communications, insurance, and external specialists where required; ensure the customer has the information needed to make informed notification, disclosure, and recovery decisions.
  • Support customers with regulatory incident reporting by identifying relevant facts, timelines, impact, and evidence, while leaving legal determinations and formal notification decisions to the appropriate customer and legal stakeholders.
  • Balance technical urgency with operational realities: help customers make defensible risk-based decisions on isolation, recovery, restoration of critical services, and communications.
  • Manage and mentor incident response team members during engagements: delegate work effectively, remove blockers, maintain quality, and protect team wellbeing during sustained high-pressure incidents.
  • Coordinate third parties such as cloud providers, managed service providers, insurers, outside counsel, PR advisers, and law enforcement where they are involved in the response.
  • Maintain accurate incident documentation and ensure evidence, key decisions, customer actions, and outstanding risks are traceable throughout the engagement.
  • Lead or oversee post-incident reviews and lessons-learned sessions; turn findings into practical improvements to playbooks, detection coverage, response procedures, recovery plans, and customer readiness.
  • Identify recurring incident patterns and systemic weaknesses and recommend pragmatic security enhancements to reduce the likelihood and impact of future incidents as part of structured lessons learned sessions
  • Contribute to and continuously improve NVISO’s incident-management methodology, templates, crisis communications approach, escalation procedures, and readiness services.
  • Support incident readiness engagements, such as tabletop exercises, crisis simulations, forensic readiness assessments, response-plan reviews, and executive briefings.
  • Stay current on threat actor activity, attacker TTPs, major incident trends, and relevant regulatory developments, and use these insights to improve response decision-making and customer advice.

What we are looking for

  • You hold citizenship in one of the 32 NATO member states;
  • 5+ years of relevant experience in cybersecurity, incident response, digital forensics, crisis management, IT service management, or a comparable high-pressure operational role.
  • Ability to explain technically complex matters for a wide variety of stakeholders.

Demonstrated experience leading or coordinating cyber incidents, including triage, investigation, containment, eradication, recovery, stakeholder communication, and post-incident review.

Proven stakeholder-management skills: comfortable leading calls and communicating with technical teams, IT leadership, CISOs, executives, legal counsel, privacy professionals, risk teams, and external providers during stressful situations.

  • Strong coordination and leadership skills: able to organise parallel workstreams, delegate effectively, keep actions and their actioner moving, resolve blockers, and create an effective working rhythm during prolonged incidents.
  • Customer-facing consulting maturity, with the ability to build trust quickly, challenge constructively, and balance technical, commercial, legal, and operational considerations.
  • A continuous-improvement mindset: you are motivated to turn lessons learned into stronger playbooks, readiness measures, detection capabilities, and response processes.
  • Up-to-date knowledge of current cyber threats, attacker tradecraft, and the wider incident-response landscape.
  • Language: Dutch and/or French and English at C1+ proficiency for client-facing work across BE/NL/LUX.

Your availability

  • We have an On-call rotation, typically one week per month.
  • Be prepared to operate outside standard business hours as part of an on-call rotation and during active incidents.

Travel

  • Some limited travel within BE/NL/LUX/DE/AT/CH (~10–20%) for onsite response, workshops, and stakeholder meetings.

At NVISO, we care. We are committed to offering you a highly competitive remuneration package including financial and non-financial components:

  • A training budget of 10.000€ and 10 days every two years
  • Company car + Belgian fuel card
  • Working and learning from the best people in the European cyber security industry. We have multiple SANS Instructors working at NVISO, our staff has presented at popular hacking conferences (BlackHat, BruCON, OWASP, etc) and all of our technical staff can acquire deep technical security certifications (GSE, GXPN, GREM, GCFA, OSCP, etc)
  • An entrepreneurial and agile company, where you will be stimulated and supported in driving new initiatives (either through internal innovation or by improving our service offering), without losing sight of having fun!
  • Regular team-building and fun events throughout the year;
  • Our commitment to coach and counsel you and help you grow; each employee receives a personal coach within the team, whose role is to ensure your well-being and helps you grow in your career!
  • Flexible working hours and home office possibilities
  • Flex Reward Plan
  • 32 holidays

IF YOU'RE INTERESTED, PLEASE SEND US YOUR APPLICATION!

WE'RE LOOKING FORWARD TO MEETING YOU!

Disclaimer on the Use of AI Tools in the Application Process

Please be aware that the creation and submission of application documents (e.g. CV, cover letter, case studies, etc.) using AI-powered tools is only permitted to a limited extent.

Our expectations:

  • Application documents must authentically reflect your own qualifications, personality, and motivation.
  • The use of AI for supportive purposes (e.g. spell-checking, improving wording) is acceptable.
  • Fully generated application documents created by AI without personal adaptation or review are not permitted.
  • Under no circumstances may NVISO information, data, or documents be uploaded to or processed by external AI tools.

We reserve the right to exclude applications from the selection and interview process that are clearly created primarily or exclusively by AI and show no recognizable personal input.

The purpose of this policy is to ensure a fair and transparent recruitment process and to obtain an authentic impression of our applicants.

Similar jobs

Apply for this job