Company description See more offers
   
 

Cronos Europa - Cybersecurity Incident Responder

We are currently looking for a Cybersecurity Incident Responder to strengthen the Cronos Europa team. The position is based in Brussels.

 

 

Responsibilities

  • Defining incident handling procedures, automation requirements, and playbook logic in alignment with structure and operational needs.
  • Preparation of incident response workflows, automated enrichment steps, and technical documentation to ensure standardized handling across recurring alert types.
  • Handling of cyber security incidents, escalations, ensuring containment and resolution actions are consistently applied.
  • Development and maintenance of Xsoar playbooks, integrations, and automations to streamline alert triage, case enrichment, and cross platform coordination (e.g., Splunk, AWS, Azure Sentinel, Carbon Black Cloud, Sysdig).
  • Coordination and review of playbook updates, incident reports, and cross team coordination to ensure accuracy, compliance.
  • Reporting of key performance metrics (e.g., FP/TP rate, Mtth, escalation rate) and playbook performance (automation coverage, time saved, error reduction).
  • Assistance with training other analysts in playbook usage, incident response methodology, and maintaining documentation in the structure's knowledge base.
  • Interaction with Csirc, Catch analysts, infrastructure teams, and relevant external stakeholders to validate playbook coverage, share threat intelligence, and ensure service alignment with the structure priorities.

 

Profile

  • Very good knowledge of incident response methodologies, Xsoar playbook development, and automation logic for cross platform integration (e.g., Splunk, AWS, Azure Sentinel, Carbon Black Cloud,).
  • Strong experience in handling cybersecurity incidents end to end, including triage, escalation, containment, and resolution in large scale or multinational environments.
  • Ability to design, implement, and adapt incident workflows and automated enrichment steps efficiently and fast, ensuring operational consistency across recurring alert types. Ability to develop in Python.
  • Ability to give business and technical presentations on incident trends, automation performance, and security operations improvements to both technical and non technical stakeholders.
  • Ability to apply high quality standards in incident documentation, KPI reporting, and compliance with structure security frameworks and regulatory requirements.
  • Ability to cope with fast changing technologies used in modern SOC environments, particularly cloud native services (AWS, Azure), EDR solutions (Defender, Carbon Black Cloud), SIEM/Soar platforms, and container security (Sysdig).
  • Very good communication skills with technical and non technical audiences, ensuring accurate translation of technical findings into actionable business context.
  • Analysis and problem solving skills to identify root causes, propose automation improvements, and optimize alert handling workflows for efficiency and precision.
  • Capability to write clear and structured technical documents, including playbook documentation, incident reports, and operational procedures for the structure knowledge base.
  • Ability to participate in technical meetings and good communication skills, ensuring effective coordination with cyber security analysts, infrastructure teams, and external stakeholders.
  • Certification or proven practical experience in relevant technologies such as Palo Alto Cortex Xsoar, Splunk, Microsoft Security (SC 200), AWS Security Specialty, Azure Security Engineer.

 

Why cronos group?

We'll propose you:

  • An attractive salary package
  • A good work-life balance environment
  • The assurance of working in cutting-edge technologies in an entrepreneurial spirit.
  • The opportunity to develop your skills thanks to tailor-made training courses according to your needs
  • A good job in a friendly place

If you wish to integrate a dynamic structure on a human scale while working with the latest technologies, don't wait anymore and join Cronos!

    Company description

    Cronos Europa is an IT and digital communications company uniquely dedicated to serving the European institutions, agencies and bodies.
    From the European Union to EUROCONTROL, we partner with a range of supranational and interinstitutional authorities.
    Our mission is to arm them with the tools they need to thrive in the digital age.
    Every aspect of our organisation is designed to complement their capabilities - from our people to our processes and our premises.
    Our brand combines the expertise of former companies Cronos International and C-Dev, with the creative skills of Inspiiro and the breadth of capabilities of the Cronos Group.
    Today, Cronos Europa employs over 1,000 people in offices across Belgium, Luxembourg and the Netherlands, serving institutions across diverse framework contracts.
    Cronos Europa is part of the Cronos Group, one of the largest IT service providers in the Benelux, employing over 8,000 people across 200 competence centres.
    By leveraging the Group's resources, Cronos Europa can help clients extract value from new and emerging technologies, for everything from Artificial intelligence to Zg Quantum.

    Show full description
    Cronos Europa - Cybersecurity Incident Responder
    Cronos Europa
    Similar offers