Skip to content

Open nowPosted 59 days ago

Incident Response Manager

Bitdefender54 open roles

Where
Bucharest
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowIncident Response ManagerBitdefender · Bucharest
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Bitdefender's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.4% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.5%1 day
  2. 3.5%3 days
  3. 7.4%7 days
  4. 13.1%14 days
  5. 34.4%30 days
This job: posted 59 days ago

The posting

Bitdefender is a cybersecurity leader delivering best-in-class threat prevention, detection, and response solutions worldwide. Guardian over millions of consumer, enterprise, and government environments, Bitdefender is one of the industry’s most trusted experts for eliminating threats, protecting privacy, digital identity and data, and enabling cyber resilience. With deep investments in research and development, Bitdefender Labs discovers hundreds of new threats each minute and validates billions of threat queries daily. The company has pioneered breakthrough innovations in antimalware, IoT security, behavioral analytics, and artificial intelligence and its technology is licensed by more than 180 of the world’s most recognized technology brands. Founded in 2001, Bitdefender has customers in 170+ countries with offices around the world. For more information, visit https://www.bitdefender.com

The Enterprise Support and Services team based in Bucharest is looking for a new enthusiastic member!

As an Incident Response Manager, you will be reporting directly to the Director of Enterprise Support and Services. You will lead the coordination of security incidents affecting our enterprise customers, acting as incident commander from identification through resolution and post-incident review. You will also be the bridge between Enterprise Support and Services and our digital forensics and incident response (DFIR) team, ensuring that incidents flow smoothly between the two organizations, with clear ownership, clean hand-offs and no loss of momentum.

This is a senior position. We are looking for someone who has managed security incidents before and can establish the incident response processes, escalation paths and playbooks that keep response fast and well-coordinated. The right person will be comfortable interfacing with clients and managing intricate and sensitive client relationships, remaining composed and decisive under pressure, and fostering these relationships until resolution has been reached. For our strategic accounts, you will act as a trusted advisor and their voice inside the company during and after an incident.

We expect the ideal candidate to contribute to our positive team culture by sharing our values: outstanding service to our customers, partners, and each other; respect, accountability, and excellence in everything we do.

In this process, you will work closely with the DFIR team, enterprise support engineers and escalation managers, as well as security or sales experts, in a dynamic and competitive environment, which will enrich your experience and broaden your perspective.

Responsibilities

  • Lead the coordination of major security incidents affecting enterprise customers, acting as incident commander from identification through containment, resolution and post-incident review
  • Act as the primary interface between Enterprise Support and Services and the DFIR team, ensuring clear ownership, clean hand-offs and effective collaboration throughout the incident lifecycle
  • Establish and maintain incident response processes, escalation paths and playbooks, and continuously improve them based on lessons learned
  • Act as a trusted advisor and the voice of strategic accounts inside the company during and after security incidents
  • Coordinate containment, eradication and recovery activities together with the DFIR team, the MDR SOC and engineering teams
  • Provide clear, timely and accurate status updates to customers and internal senior stakeholders, tailoring the message to each audience
  • Initiate and manage the hierarchical escalation process for high-severity incidents, engaging senior stakeholders when needed
  • Own the post-incident review process: after-action reports, lessons learned and follow-up actions tracked to closure
  • Support incident readiness through playbook development, tabletop exercises and escalation drills
  • Define, monitor and report on incident management KPIs and SLAs, and use these insights to drive continuous service improvement
  • Participate in an on-call rotation to ensure incident response coverage outside standard business hours
  • Build strong relationships with other internal teams: DFIR, MDR SOC, enterprise support, product delivery, product management and sales
  • Adhere to our company’s values and principles

Technical requirements

Minimum 5 years of professional experience in the following areas:

  • Incident response management, with proven experience running major security incidents end to end
  • Building or maturing incident response processes, playbooks and escalation procedures
  • Working alongside or within DFIR, SOC or security operations teams
  • Good understanding of attacker tactics, techniques and procedures (TTPs) and the MITRE ATT&CK framework
  • IT Service Management and incident management processes (ITIL knowledge is desirable)
  • Strong IT technical background: operating systems, virtualization, networking

Working knowledge of IT security technologies, for example:

  • EDR / XDR
  • SIEM and security monitoring
  • Network security (firewalls, IDS/IPS, VPN)
  • Cloud and email security
  • Threat intelligence and threat hunting

Other requirements

  • Industry-standard incident response certifications – GIAC (e.g., GCIH, GCFA, GNFA) and/or CREST (e.g., CREST Certified Incident Manager) – or equivalent
  • Proven ability to remain composed and lead effectively in high-stress, high-pressure situations
  • Excellent verbal and written communication skills, quick learner, dynamic, energetic and customer-oriented
  • Able to translate technical findings for executive and non-technical audiences
  • Proven ability to lead, influence, and coordinate across functional groups not directly in the reporting structure
  • Experience creating and improving procedures, processes and documentation
  • Experience implementing methodologies to improve customer satisfaction and build strong internal relationships
  • Work independently; receive minimal guidance
  • Experience dealing with international teams and customers
  • Demonstrated strong work ethic
  • Ability to work in a fast-paced environment
  • Availability to participate in an on-call rotation
  • Prior experience working with business applications, like Salesforce, Jira, Office
  • Fluent in both written and spoken Romanian and English
  • French is a plus #LI-SA1
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Bitdefender's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Bitdefender's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Bitdefender's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.