- Location
- HBP (Amsterdam - Haarlerbergpark), Netherlands
- Type
- Full-time
- Seniority
- Senior
- Education
- Bachelor
- Source
- Workday
Description
Senior Incident Responder
When a major cyber incident hits ING, you are the person people turn to.
As a Senior Incident Responder within ING's Global CSIRT (Security Defence Centre), you lead the response to significant cyber incidents, coordinate stakeholders across business and technology teams, and help protect one of Europe's largest financial institutions. Beyond incident handling, you shape our response capabilities, mentor other responders, and work closely with national and international security communities to strengthen ING's resilience against emerging threats.
The Global CISO organization of ING is responsible for assisting ING’s management, business and other tribes in providing customer-friendly services in a safe and secure way. Business leaders and CISO are jointly responsible for bank-wide security. CISO is mandated to drive required change in all domains, business and IT. Within CISO, the Security Defence Center (SDC) is responsible for security incident response and management as the Global CSIRT organization of ING.
The Team:
The senior security incident responder leads and assists the team in being prepared for major security incidents as part of an international team based in multiple countries, as one of a few senior incident responders. As part of this task, the senior incident responder acts as the operational lead for the Incident Response squad on a rotational basis, coordinating day-to-day activities and ensuring effective handling of security incidents.
With deep expertise in security incident response, the senior incident responder provides the squad with the knowledge and skills needed to fulfill its shared purpose: mitigating cyber and insider threats as quickly as possible to minimize business impact for ING every day.
Key Responsibilities
The senior incident responder is:
Leading large and major security incidents within the organization, taking risk-based decisions to contain and mitigate impact, and escalating where needed.
Coordinates the daily Incident Response squad on an intermittent basis, sharing this responsibility with other senior incident responders.
Defines, reviews and updates response plans and capabilities based on the current threat landscape to ensure response readiness.
Contributes to Security Incident Response Testing, both technical and tabletop assessments.
Working independently and with teams to mitigate security incidents.
Expert in security response tooling, preferably highly skilled in modern EDR and SOAR solutions.
Working knowledge of modern AI-assisted response techniques, including practical experience with AI capabilities and agentic architectures to support faster analysis, automation, decision-making, and overall incident response effectiveness.
Identifying functional and non-functional requirements from stakeholders, aimed at providing high-quality response for ING’s application and infrastructure landscape.
Mentors other medior and junior incident responders.
Supporting development of the vision and roadmap for the security detection and response services of CISO (which are aligned with the overall vision and roadmap for the department).
Collaborates with sector peers, government bodies and trusted security communities to improve response readiness and threat awareness.
Maintaining relations within the global and local security teams.
Reporting on progress of activities to the Head of SDC.
Audit & Compliance
Work with the Head of SDC to ensure compliance of the security incident response services.
How to succeed
We hire smart people like you for your potential. Our biggest expectation is that you’ll stay curious. Keep learning. Take on responsibility. In return, we’ll back you to develop into an even more awesome version of yourself.
Bachelor's degree in cybersecurity, computer science or a comparable degree.
8-10 years’ professional experience within Incident Response or related Security Operations teams and relevant information security experience, ideally in large, complex or regulated organisations.
Subject matter expert in the area of security incident response.
Excellent understanding of IT platforms, networking, cloud and application log data.
Strong knowledge of current security technologies and emerging trends in the area of security detection or monitoring.
Strong knowledge of cloud response capabilities.
Good oral and written communication skills.
Ability to simplify complexity and drive operational excellence.
Ability to support yourself and other team members in professional and soft skills development.
Good computer forensics skills (Windows, Linux, macOS, Cloud).
Professional working proficiency in both Dutch and English.
Demonstrable experience in a financial environment is a plus.
Rewards and benefits
We want to make sure that it’s possible for you to strike the right balance between your career and your private life. Find out more about our employment conditions.
The benefits of working with us at ING include:
- 25-28 vacation days depending on contract
- Pension scheme
- 13th month salary
- 8% Holiday payment
- Hybrid working
- Personal growth and challenging work with endless possibilities
- An informal working environment with innovative colleagues
About us
Curious about how ING empowers people and businesses to move forward?
Discover what we do and what we can offer you.
Questions?
Please visit our Frequently Asked Questions section to find some answers on questions you might have.
Contact the recruiter attached to the advertisement. Want to apply directly? Please upload your CV and motivation letter by clicking the ‘Apply’ button.