368,611open jobs
9,439companies
50,719added this week
Browse all
Location
Remote/Hybrid (Bucharest, Romania)
Seniority
Senior · 5+ years exp
Overview
Company
Impact
Profile match
Bitdefender is a global cybersecurity leader headquartered in Bucharest, Romania, that delivers advanced threat prevention, detection, and response solutions. Founded in 2001, the company protects millions of consumer, business, and government endpoints across more than 170 countries through its antivirus software, cloud security platforms, and Managed Detection and Response (MDR) services.

Bitdefender is a cybersecurity leader delivering best-in-class threat prevention, detection, and response solutions worldwide. Guardian over millions of consumer, enterprise, and government environments, Bitdefender is one of the industry’s most trusted experts for eliminating threats, protecting privacy, digital identity and data, and enabling cyber resilience. With deep investments in research and development, Bitdefender Labs discovers hundreds of new threats each minute and validates billions of threat queries daily. The company has pioneered breakthrough innovations in antimalware, IoT security, behavioral analytics, and artificial intelligence and its technology is licensed by more than 180 of the world’s most recognized technology brands. Founded in 2001, Bitdefender has customers in 170+ countries with offices around the world. For more information, visit https://www.bitdefender.com

The Enterprise Support and Services team based in Bucharest is looking for a new enthusiastic member!

As an Incident Response Manager, you will be reporting directly to the Director of Enterprise Support and Services. You will lead the coordination of security incidents affecting our enterprise customers, acting as incident commander from identification through resolution and post-incident review. You will also be the bridge between Enterprise Support and Services and our digital forensics and incident response (DFIR) team, ensuring that incidents flow smoothly between the two organizations, with clear ownership, clean hand-offs and no loss of momentum.

This is a senior position. We are looking for someone who has managed security incidents before and can establish the incident response processes, escalation paths and playbooks that keep response fast and well-coordinated. The right person will be comfortable interfacing with clients and managing intricate and sensitive client relationships, remaining composed and decisive under pressure, and fostering these relationships until resolution has been reached. For our strategic accounts, you will act as a trusted advisor and their voice inside the company during and after an incident.

We expect the ideal candidate to contribute to our positive team culture by sharing our values: outstanding service to our customers, partners, and each other; respect, accountability, and excellence in everything we do.

In this process, you will work closely with the DFIR team, enterprise support engineers and escalation managers, as well as security or sales experts, in a dynamic and competitive environment, which will enrich your experience and broaden your perspective.

Responsibilities

  • Lead the coordination of major security incidents affecting enterprise customers, acting as incident commander from identification through containment, resolution and post-incident review
  • Act as the primary interface between Enterprise Support and Services and the DFIR team, ensuring clear ownership, clean hand-offs and effective collaboration throughout the incident lifecycle
  • Establish and maintain incident response processes, escalation paths and playbooks, and continuously improve them based on lessons learned
  • Act as a trusted advisor and the voice of strategic accounts inside the company during and after security incidents
  • Coordinate containment, eradication and recovery activities together with the DFIR team, the MDR SOC and engineering teams
  • Provide clear, timely and accurate status updates to customers and internal senior stakeholders, tailoring the message to each audience
  • Initiate and manage the hierarchical escalation process for high-severity incidents, engaging senior stakeholders when needed
  • Own the post-incident review process: after-action reports, lessons learned and follow-up actions tracked to closure
  • Support incident readiness through playbook development, tabletop exercises and escalation drills
  • Define, monitor and report on incident management KPIs and SLAs, and use these insights to drive continuous service improvement
  • Participate in an on-call rotation to ensure incident response coverage outside standard business hours
  • Build strong relationships with other internal teams: DFIR, MDR SOC, enterprise support, product delivery, product management and sales
  • Adhere to our company’s values and principles

Technical requirements

Minimum 5 years of professional experience in the following areas:

  • Incident response management, with proven experience running major security incidents end to end
  • Building or maturing incident response processes, playbooks and escalation procedures
  • Working alongside or within DFIR, SOC or security operations teams
  • Good understanding of attacker tactics, techniques and procedures (TTPs) and the MITRE ATT&CK framework
  • IT Service Management and incident management processes (ITIL knowledge is desirable)
  • Strong IT technical background: operating systems, virtualization, networking

Working knowledge of IT security technologies, for example:

  • EDR / XDR
  • SIEM and security monitoring
  • Network security (firewalls, IDS/IPS, VPN)
  • Cloud and email security
  • Threat intelligence and threat hunting

Other requirements

  • Industry-standard incident response certifications - GIAC (e.g., GCIH, GCFA, GNFA) and/or CREST (e.g., CREST Certified Incident Manager) - or equivalent
  • Proven ability to remain composed and lead effectively in high-stress, high-pressure situations
  • Excellent verbal and written communication skills, quick learner, dynamic, energetic and customer-oriented
  • Able to translate technical findings for executive and non-technical audiences
  • Proven ability to lead, influence, and coordinate across functional groups not directly in the reporting structure
  • Experience creating and improving procedures, processes and documentation
  • Experience implementing methodologies to improve customer satisfaction and build strong internal relationships
  • Work independently; receive minimal guidance
  • Experience dealing with international teams and customers
  • Demonstrated strong work ethic
  • Ability to work in a fast-paced environment
  • Availability to participate in an on-call rotation
  • Prior experience working with business applications, like Salesforce, Jira, Office
  • Fluent in both written and spoken Romanian and English
  • French is a plus

    #LI-SA1

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,611 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Bucharest
$77k – $140k per year • In office • Full-Time • 2+ years exp • Bachelor's Degree • Berlin
Node JS
TypeScript
JavaScript
Node JS
Prisma
Databases
PostgreSQL
Redis
Frontend
Next.js
Tailwind CSS
tRPC
React.js
Apply
$93k – $140k per year • In office • Full-Time • 3+ years exp
Node JS
TypeScript
JavaScript
Node JS
Nest.JS
AI/ML
LLM
EU AI Act
Frontend
React.js
Cybersecurity
GDPR
Apply
$150k – $220k per year • In office • Full-Time • 10+ years exp
JavaScript
Node JS
TypeScript
Databases
Google BigQuery
Frontend
React.js
DevOps
CI/CD
GCP
Apply
Founding Engineer 1 day ago
$180k – $250k per year • In office • Full-Time • 3+ years exp • New York
Node JS
Python
TypeScript
JavaScript
Node JS
BullMQ
Databases
Redis
AI/ML
AI Agents
LangGraph
LLM
Multimodal AI
LangChain
Anthropic
Deepgram
LiveKit
LLM Guardrails
OpenAI
Text-to-Speech
Frontend
Next.js
React.js
DevOps
Vercel
Apply
$128k – $259k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Denver
JavaScript
TypeScript
Frontend
Angular
Apply
Remote/Hybrid • 2+ years exp • Bachelor's Degree • Bucharest
DevOps
Hyper-V
SLI/SLO/SLA
VMWare
Windows Server
Xen
Apply
$59k – $65k per year (Estimated) • Remote/Hybrid • Bucharest
JavaScript
Node JS
TypeScript
DevOps
CI/CD
Apply
Remote • Bucharest
C++
Rust
Apply
Remote/Hybrid • Internship • Bucharest
Cybersecurity
Defense in Depth
Tcpdump
Wireshark
Apply
Remote/Hybrid • Internship • Bucharest
Cybersecurity
Defense in Depth
Tcpdump
Wireshark
Apply
In office • Internship • 1+ year exp • Bachelor's Degree • Bucharest
Go
JavaScript
Ruby
Scala
Apply
Remote/Hybrid • Full-Time • Bucharest
SQL
Cybersecurity
GDPR
Analytics
Power BI
Tableau
Apply
$17k – $21k per year (Estimated) • Remote/Hybrid • Full-Time • Bucharest
DevOps
Azure
GCP
Incident Management
Splunk
Cybersecurity
Google SecOps
MITRE ATT&CK
Apply
$18k – $22k per year (Estimated) • Remote/Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Bucharest
AI/ML
AI Agents
LLM
DevOps
GCP
Cybersecurity
OWASP Top 10
Apply
Data Analyst 11 hours ago
$38k per year (gross) • Remote/Hybrid • Full-Time • Bachelor's Degree • Bucharest
Python
SQL
AI/ML
Hadoop
DevOps
Azure
Analytics
Power BI
Apply
See all jobs
This is one of many
368,611 more open roles from verified company boards, updated every day.