View all jobs

IT Security Incident Response Expert - September 2026

  • remote, remote

For on of our clients in the energy industry, we are looking for a freelance IT Security Incident Response Expert


Project name: Defending the Castle
 
Project description: “Defending the Castle” is the short-term and immediate phase of the client’s AI threat resilience response. The purpose is to buy time by increasing detection, response, containment and recovery readiness while a broader Phase 2 plan is prepared for the rest of the Business IT units.

Tasks:
  • Conceptual development and structured implementation of the immediate incident response workstream for “Defending the Castle”, focused on AI-augmented attacks that may progress at machine speed.
  • Creation of practical response playbooks and SOPs for identity compromise, cloud control-plane abuse, endpoint intrusion, lateral movement, ransomware-style disruption and data-impact scenarios.
  • Definition of decision points for containment, escalation, evidence preservation, communication, legal/regulatory handover and crisis coordination.
  • Provision of technical consultation and recommendations to SOC, threat intelligence, security monitoring, infrastructure, application, Azure, on-premise and resilience teams.
  • Establishment and technical definition of a repeatable operating model for response readiness, evidence collection, handover and post-incident improvement before end of Q1 2027.
  • Provision of technical consultation to enable fast, consistent and controlled response to AI-assisted cyber incidents across hybrid Azure and on-premise landscapes.
  • Predefinition and documentation of roles, triggers, containment options, and communication paths to optimize incident response workflows
  • Development of guidelines to facilitate responder action when critical thresholds are reached.
  • Conversion of lessons from exercises and response reviews into improved playbooks, SOPs and control requirements.
  • Technical preparation of scenario walkthroughs for validation by SOC, Cyber Defense, legal/compliance, cloud, infrastructure and resilience stakeholders.
  • Assessment of exercise results against time-to-triage, time-to-contain, decision latency and handover quality.
  • Usability testing of playbooks by responders who did not author them.
  • Creation of a Management-ready dashboard for readiness gaps, residual risks and agreed next actions.
  • Identification and technical gap analysis of existing processes (too slow, fragmented, undocumented or dependent on informal knowledge) to document optimization potential.
  • Transformation of risk discussion Transformation of risk evaluations into executable playbooks, technical control frameworks, test protocols, backlog items and management evidence.
  • Provision of a structured handover of a Phase 2 backlog and recommendations for the broader Business IT resilience plan after Q1 2027.
  • Creation of comprehensive documentation with all results regarding the above-mentioned tasks with subsequent handover to client for review and approval for further usage.

Required skills:
  • Minimum 8 years in incident response, cyber defense operations, crisis management, digital forensics or security operations leadership.
  • Hands-on experience responding to identity compromise, ransomware, cloud compromise, endpoint intrusion and lateral movement incidents.
  • Strong understanding of Microsoft security stack, Azure/Entra ID response actions, EDR isolation, forensic triage and evidence preservation.
  • Proven ability to coordinate cross-functional technical and management stakeholders during high-pressure situations.
  • Relevant certifications such as GCIH, GCFA, GNFA, CISSP, CISM, SC-200, AZ-500 or equivalent are beneficial

Start: ASAP
Duration: till end of March 2027
Capacity: 40h/week
Location: Remote