Project Lead Incident Response

Location Zwolle / The Hague – Minimum 32 hours per week.

The Computer Emergency Response Team needs you

No organization is immune from a cyber incident. The damage that an IT Security incident can cause can be enormous. Not only the financial damage but certainly the reputational damage is sometimes considerable. It is not always possible to prevent an incident, but it is possible to limit the damage as much as possible and to investigate the cause of the incident properly. In doing so, acting quickly and accurately is of great importance. NFIR’s CERT is on standby 24/7 for its clients to address any IT Security incident. The Project Lead role is indispensable to manage these projects. Is this challenge for you? Then read on quickly.

Job Description

It’s eleven o’clock at night and your phone rings. A call is placed on NFIR’s Incident Response emergency number and you are on picket duty. After a brief telephone triage, you assess that you need to contact the other CERT members on picket duty because the client needs NFIR’s help immediately. After assembling the CERT team, you will leave for the client to supervise the intake and take care of the assignment confirmation and other formalities. The CERT team consists of digital forensics, ethical hackers and technical support colleagues who all have experience in Incident Response. So as a Project Lead Incident Response, you will be responsible for keeping a multidisciplinary team performing optimally under pressure. As a leader, you will apply your subject matter, project management and communication skills. You have to keep the overview and communicate information from the CERT to the client in clear language. You are able to prioritize, weigh interests and do not hesitate to engage in a difficult conversation with the client. A Project Lead Incident Response knows how to quickly oversee a crisis situation and is decisive. During this process, you will ensure that the goal of the Incident Response team is achieved as quickly as possible: to minimize the impact of the cyber incident as quickly as possible so that the continuity of the organization is no longer at risk. After triage, containment and securing, you will continue the digital forensics investigation and provide periodic updates to the client and monitor the progress of the project. NFIR helps organizations in both the public and private sectors. Is this challenge for you? If so, read the job requirements below and in which organization you will end up!

Function requirements

  • You are able to maintain an overview of an Incident under pressure;
  • You have a minimum of 10 years of work experience of which 5 years have been communicated at C-level;
  • You speak the CERT technical language and have knowledge of IT infrastructures;
  • You have experience working in and/or leading a multidisciplinary team;
  • You have experience with cyber incidents;
  • You are used to working in stressful situations;
  • You have excellent communication skills;
  • Irregular working hours (picket duty) are not a problem for you;
  • Education & Certifications: relevant HBO/WO education;
  • You have relevant project management experience;
  • You are in possession of a driver’s license.

Work in a vibrant and professional team

When you join NFIR, you will join a young and energetic team composed of diverse backgrounds and areas of expertise. NFIR is a fast growing Dutch company where the passion for IT-Security is huge, but the drive to help clients is even bigger. Even in an era of working from home, that energy is palpable and new colleagues quickly feel in place. We want you to have a great time but also to develop personally. We offer plenty of training opportunities and we promise you; no day will be the same at NFIR. At NFIR, you will work in a professional and informal environment. All employees have Chief of Police approval, we hold a POB license and have ISO27001 certification. Our clients are served by the very best IT Security specialists who work competently and procedurally. A team of specialists that you can be a part of. In addition to hard work, there is also time for relaxation and fun team outings. Do you still have doubts? Read our attractive terms of employment below.

Terms of employment

NFIR applies a salary in line with the market, based on education and experience. The fringe benefits are also very well regulated (lease car, telephone, laptop, pension and various training possibilities).

Got excited about this vacancy? Or do you have questions and/or remarks? If so, please contact Arwi van der Sluijs at

* Acquisition in response to this vacancy is not appreciated.

"*" indicates required fields

Geïnteresseerd of vragen? Laat je gegevens achter en we bellen jou. Je kunt ook direct solliciteren op "Project Lead Incident Response".

Accepted file types: pdf, Max. file size: 20 MB.
Accepted file types: pdf, Max. file size: 20 MB.
This field is for validation purposes and should be left unchanged.


De volgende 30 minuten van cruciaal belang​!

De eerste 30 minuten na een cyber security incident zijn cruciaal omdat snelle reactie de schade kan beperken, verdere verspreiding van de aanval kan voorkomen en essentieel bewijsmateriaal veiliggesteld kan worden voor onderzoek en herstel.

Onze Computer Emergency Response Teams (CERT) staan 24/7 klaar om bedrijven en organisaties te ondersteunen bij IT-beveiligingsincidenten.

Heeft uw bedrijf professionele hulp nodig bij een beveiligingsincident? 


The next 30 minutes are crucial!

The first 30 minutes after a cyber security incident are crucial because rapid response can limit damage, prevent further spread of the attack and secure essential evidence for investigation and recovery.

Our Computer Emergency Response Teams (CERT) are available 24/7 to support businesses and organizations during IT security incidents.

Does your company need professional help with a security incident?