Demo

Incident response

Stott and May
Brussells, MO Full Time
POSTED ON 1/10/2026
AVAILABLE BEFORE 2/16/2026
Job Description

Cybersecurity Incident Responder / SOAR Automation Specialist

Contract type: Freelance / B2B

Location: Brussels, Belgium

Work mode: Mainly onsite (90–100%)

Duration: Long-term assignment - up to 3 years project

Eligibility: EU nationality required

Role Overview

A large, highly regulated international client is seeking a Cybersecurity Incident Responder with SOAR/XSOAR automation expertise to support and enhance its security operations capability.

The role is hands-on and operational, combining end-to-end incident response with the design, development, and optimisation of automated incident handling workflows. The successful consultant will work closely with SOC analysts, cyber defence teams, infrastructure teams, and external stakeholders in a high-maturity security environment.

Key Responsibilities

  • Handle cybersecurity incidents end-to-end, including triage, investigation, escalation, containment, and resolution.
  • Define and maintain incident response procedures, automation requirements, and playbook logic aligned with operational needs.
  • Design, develop, and maintain SOAR / Cortex XSOAR playbooks, integrations, and automated enrichment workflows.
  • Integrate SOAR workflows with security platforms such as SIEM, EDR, and cloud services.
  • Ensure consistent and standardised handling of recurring alert types through automation and documented workflows.
  • Coordinate incident response activities with SOC teams, cyber defence units, infrastructure teams, and relevant stakeholders.
  • Produce high-quality incident reports, technical documentation, and operational procedures for the internal knowledge base.
  • Track and report on operational KPIs (e.g. MTTH, escalation rate, false/true positive ratio, automation coverage).
  • Support training and knowledge transfer for analysts on incident response methodologies and playbook usage.
  • Continuously identify opportunities to improve detection quality, automation efficiency, and response effectiveness.

Required Skills & Experience

  • University degree (Bachelor’s or Master’s) in IT, Cybersecurity, or a related field.
  • Minimum 10 years of experience in IT/cybersecurity, with strong focus on incident response and SOC operations.
  • Proven hands-on experience with SOAR platforms, preferably Palo Alto Cortex XSOAR.
  • Strong experience designing and maintaining automated incident response playbooks and enrichment workflows.
  • Solid programming/scripting experience, particularly Python, for automation and integration purposes.
  • Practical experience with:
  • SIEM platforms (e.g. Splunk, Azure Sentinel)
  • EDR solutions (e.g. Microsoft Defender, Carbon Black Cloud)
  • Cloud environments (AWS and/or Azure)
  • Exposure to container security solutions is a plus
  • Strong understanding of incident response methodologies and best practices.
  • Experience working in large, complex, or multinational environments.
  • Excellent analytical and problem-solving skills, with the ability to identify root causes and propose automation improvements.
  • Ability to communicate clearly with both technical and non-technical stakeholders.
  • High standards for documentation, reporting, and operational consistency.

Certifications (Required / Highly Preferred)

  • Relevant cybersecurity certifications (minimum 2), such as:
  • Palo Alto Cortex XSOAR
  • Splunk
  • Microsoft Security (e.g. SC-200)
  • AWS Security Specialty
  • Azure Security Engineer
  • Other recognised incident response or cloud security certifications

Salary.com Estimation for Incident response in Brussells, MO
$151,877 to $185,001
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Incident response?

Sign up to receive alerts about other jobs on the Incident response career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$115,647 - $153,495
Income Estimation: 
$186,685 - $265,377
Income Estimation: 
$173,252 - $220,888
Income Estimation: 
$152,958 - $200,151
Income Estimation: 
$115,647 - $153,495
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Stott and May

  • Stott and May Scarsdale, NY
  • Job Description Founding Product & Operations Manager Company: Confidential Early-Stage Tech Startup Location: Hybrid (NY preferred) or Remote (U.S.) Compe... more
  • 14 Days Ago

  • Stott and May Bloomfield, CT
  • Job Description IT Audit Manager (ERP) – Hybrid (On-Site/Remote) – Bloomfield, NJ Skills – IT Audit, ERP, SAP, SAP S/4 HANA, SAP S/4 Implementations, S/4 F... more
  • 5 Days Ago

  • Stott and May Los Angeles, CA
  • Job Description Senior Data Scientist – Product & Recommendations About The Role We’re looking for a Senior Data Scientist to take full ownership of how da... more
  • 5 Days Ago

  • Stott and May Menlo Park, CA
  • Job Description We’re partnering with a cutting-edge AI startup building next-generation infrastructure to power large-scale, intelligent systems. Their mi... more
  • 5 Days Ago


Not the job you're looking for? Here are some other Incident response jobs in the Brussells, MO area that may be a better fit.

  • Nationwide IT Services Arlington, VA
  • Incident Responder / Incident Response Coordinator Location: Onsite – Arlington, VA or Mechanicsburg, PA Clearance Requirement: Active Secret Clearance Emp... more
  • 23 Days Ago

  • Telos Corp. Tysons, VA
  • Job Title Incident Response Associate Principal Job Description The most security-conscious organizations trust Telos Corporation to protect their vital IT... more
  • 1 Month Ago

AI Assistant is available now!

Feel free to start your new journey!