Eye Security logo

Manager, Incident Response

Eye Security

Hybrid
The Hague
Full-time
Manager
Staff
6+ yrs
Salary not listedPosted 1d ago

Real job — pulled straight from Eye Security’s careers page · Verified September 30, 2026 · No reposts.

Job description

Eye Security is hiring a Manager, Incident Response — a full-time, based in The Hague role. Apply directly on Eye Security's careers page below.

Manager Incident Response

Department: Operations

Location: The Hague - hybrid, Berlin - hybrid, Belgium

Employment Type: FullTime

About this role
We are looking for a Team Lead Incident Response to join our Security Operations department. You will lead the people who own our most serious cases end to end — coordinating ransomware and business email compromise investigations, doing the forensic work, and being the person on the phone when a client needs a straight answer under real pressure.
Your first responsibility is people, not just process. You’re a first-line manager distinct from a senior individual contributor, with direct accountability for the performance and development of your team — while carrying enough hands-on DFIR credibility to run the most complex case yourself, or take over one mid-flight, when the situation demands it.


What you will do

  • Lead, coach, and develop the Incident Response team: regular one-to-ones, feedback, and performance/development conversations aligned with Eye’s career framework

  • Lead by doing: manage the caseload and the people, but personally take point on the most complex or highest-profile incidents when needed

  • Own end-to-end incident response service quality: case intake and coordination, technical execution, client communication, and closure/reporting

  • Own delivery KPIs (time-to-containment, case-report quality and timeliness, client satisfaction on incident cases) and step in to unblock the team or personally lead a case when targets are at risk

  • Manage on-call and case-lead rostering and workload across the team, prioritising by severity and client exposure

  • Act as the senior escalation point and, when needed, incident commander for major incidents — large ransomware, multi-entity BEC, or cases with legal/regulatory exposure

  • Own quality assurance for incident reporting: set the reporting standard and run structured peer review of case reports before they reach the client

  • Own and scale automation across the function’s casework (evidence collection, timeline building, reporting), partnering with engineering where it makes sense

  • Drive continuous improvement of IR playbooks, tooling, and process as case volume grows; keep runbooks and SOPs accurate and actually used

  • Represent Incident Response in cross-functional discussions with SOC, Prevention, Product, Customer Success, and Legal where relevant

What you will need

  • Technical: 6+ years of hands-on incident response / digital forensics experience — the same bar as Staff Incident Response Analyst — with deep, current knowledge of DFIR methodology, EDR platforms, cloud security, and attacker TTPs; able to personally run a complex case, not just sign off on one

  • Leadership: composure and sound judgement under real pressure, often with incomplete information, during live incidents; strong incident-report writing and a sharp eye for reviewing others’ reports; clear, calm, authoritative communication with clients and internal stakeholders during a crisis

  • People management: proven experience leading or supervising a technical team through high-pressure, time-critical work, with a genuine interest in coaching people and helping them grow; first-line management experience or a strong informal leadership track record

  • Fluent English; Dutch required for client-facing work

Nice-to-have

  • Background in a CERT, CSIRT, MDR, or DFIR-focused environment

  • Experience handling cases with legal or regulatory exposure

  • Scripting/automation experience applied to investigation workflows

  • Familiarity with compliance frameworks relevant to SMEs (NIS2, ISO 27001, GDPR)

About Eye Security
Eye Security provides cybersecurity with embedded cyber insurance solutions for organisations across Europe. Headquartered in the Netherlands, we combine 24/7 detection and response with hands-on incident response to keep SMEs protected, and we’re growing internationally. When a client’s worst day happens, this is the team that shows up.

Get Manager, Incident Response jobs like this→

New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.

Email me new jobs
Jobs for Humanity logo

Junior Cybersecurity Engineer

Beirut, Beirut Governorate, lb
✓ From careers page· 17h ago
GEICO logo

Senior Manager, Cybersecurity Governance & Assurance

Palo Alto, CA
✓ From careers page· 18h ago
VulnCheck logo

Engineering Manager, Rapid Response

Remote · UK-eligible
✓ From careers page· 18h ago
Copart logo

Detection Engineer

Dallas, TX
✓ From careers page· 18h ago

Frequently asked questions

What skills are required for Manager, Incident Response at Eye Security?

The required skills for Manager, Incident Response at Eye Security include: Cybersecurity, ISO 27001, GDPR, English.

What is the seniority level for Manager, Incident Response at Eye Security?

Manager, Incident Response at Eye Security is a Manager / Staff level position.

How do I apply for Manager, Incident Response at Eye Security?

You can view the full description and apply for Manager, Incident Response at Eye Security on EchoJobs: https://echojobs.io/job/eye-security-manager-incident-response-6wnwj.