European Cybersecurity Site Leader - SOC & CSIRT

IBM

IBM

Amsterdam, Netherlands

Posted on Apr 9, 2026
Introduction

The Security Operations Center (SOC) and Computer Security Incident Response Team (CSIRT) are core components of the CISO organization, responsible for protecting enterprise IT assets through proactive monitoring, rapid detection, and decisive incident response. Together, these teams operate at the frontline of cybersecurity defense, safeguarding the organization in a constantly evolving threat landscape.

Our teams are made up of highly motivated, innovative, and out‑of‑the‑box thinkers who are committed to continuously improving the organization’s security posture. Through collaboration, operational excellence, and a strong culture of learning, the SOC and CSIRT work closely with business and technology partners to detect threats early, respond effectively to incidents, and strengthen resilience across the enterprise.

As the European Cybersecurity Site Leader based in Amsterdam, you will play a critical role in leading these capabilities across the region, with a strong emphasis on CSIRT leadership, incident response excellence, and crisis management, while ensuring seamless integration with SOC operations and alignment to global CISO strategy.

Your role and responsibilities

As the European Cybersecurity Site Leader, you will provide strategic, operational, and people leadership for both the Security Operations Center (SOC) and the Computer Security Incident Response Team (CSIRT), with a primary focus on incident response, investigations, and crisis coordination.

Key responsibilities include:

  • Provide overall site leadership in Amsterdam, Netherlands for the European SOC and CSIRT teams, ensuring operational excellence, resilience, and alignment with global cybersecurity strategy.
  • Lead and mature the CSIRT function, owning end-to-end incident response lifecycle including intake, triage, containment, eradication, recovery, and post-incident reviews.
  • Act as the senior incident response leader during high-severity and crisis incidents, coordinating technical teams, business stakeholders, legal, communications, and executive leadership.
  • Define, implement, and continuously improve incident response processes, procedures, playbooks, and standards in alignment with industry best practices.
  • Oversee SOC operations, ensuring effective threat monitoring, detection, escalation, and handoff between SOC and CSIRT functions.
  • Establish and track KPIs, metrics, and reporting for SOC and CSIRT performance, including incident trends, response effectiveness, and operational health.
  • Build and maintain strong partnerships with Business Information Security Officers (BISOs), IT, Legal, Risk, Privacy, and senior business leaders across Europe and globally.
  • Serve as a trusted advisor and subject matter expert on cybersecurity incidents, threat landscape, and response readiness for executive leadership.
  • Lead talent management activities including hiring, mentoring, performance management, succession planning, and development of high-performing teams.
  • Drive training, exercises, and simulations (e.g., tabletop exercises, crisis drills) to continuously improve incident readiness and team capabilities.
  • Stay current with emerging threats, attacker techniques, industry trends, and regulatory requirements, incorporating insights into operational improvements.
Required education
Bachelor's Degree
Preferred education
Bachelor's Degree
Required technical and professional expertise
  • 10+ years of experience in cybersecurity, with at least 5 years in a people and operational leadership role.
  • Strong hands-on and leadership experience in Computer Security Incident Response (CSIRT) within a large, global enterprise environment.
  • Solid understanding of SOC operations, including threat monitoring, alert triage, escalation, and coordination with incident response teams.
  • Proven experience developing and executing incident response processes, standards, playbooks, and governance models.
  • Demonstrated ability to lead during high-severity incidents and communicate clearly with technical teams and executive stakeholders.
  • Experience managing cross-functional and geographically distributed teams.
  • Strong written and verbal communication skills, with the ability to translate technical findings into business-relevant insights.
  • Knowledge of common threat actors, attack vectors, malware, ransomware, phishing, insider threats, and advanced persistent threats (APTs).
  • Familiarity with security frameworks, standards, and regulatory requirements (e.g., NIST, ISO 27001, incident management best practices).
  • Bachelor’s degree in Computer Science, Information Security, Engineering, or equivalent practical experience.
  • High level of integrity, professionalism, and ability to operate effectively under pressure.
Preferred technical and professional experience
  • Advanced experience in digital forensics, threat hunting, or malware analysis.
  • Prior experience leading or scaling regional or global CSIRT capabilities.
  • Experience with security orchestration and response platforms (e.g., IR platforms, SOAR tools).
  • Strong understanding of cloud security incident response and modern hybrid environments.
  • Relevant professional certifications such as CISSP, CISM, GIAC (GCIH, GCED, GCFA), CISA, or equivalent.
  • Experience delivering incident response training, tabletop exercises, and executive simulations.
  • Exposure to international regulatory environments and breach notification processes.
  • Multilingual capabilities are a plus.

ABOUT BUSINESS UNIT

IBM Systems helps IT leaders think differently about their infrastructure. IBM servers and storage are no longer inanimate - they can understand, reason, and learn so our clients can innovate while avoiding IT issues. Our systems power the world’s most important industries and our clients are the architects of the future. Join us to help build our leading-edge technology portfolio designed for cognitive business and optimized for cloud computing.

YOUR LIFE @ IBM

In a world where technology never stands still, we understand that, dedication to our clients success, innovation that matters, and trust and personal responsibility in all our relationships, lives in what we do as IBMers as we strive to be the catalyst that makes the world work better.

Being an IBMer means you’ll be able to learn and develop yourself and your career, you’ll be encouraged to be courageous and experiment everyday, all whilst having continuous trust and support in an environment where everyone can thrive whatever their personal or professional background.

Our IBMers are growth minded, always staying curious, open to feedback and learning new information and skills to constantly transform themselves and our company. They are trusted to provide on-going feedback to help other IBMers grow, as well as collaborate with colleagues keeping in mind a team focused approach to include different perspectives to drive exceptional outcomes for our customers. The courage our IBMers have to make critical decisions everyday is essential to IBM becoming the catalyst for progress, always embracing challenges with resources they have to hand, a can-do attitude and always striving for an outcome focused approach within everything that they do.

Are you ready to be an IBMer?

ABOUT IBM

IBM’s greatest invention is the IBMer. We believe that through the application of intelligence, reason and science, we can improve business, society and the human condition, bringing the power of an open hybrid cloud and AI strategy to life for our clients and partners around the world.

Restlessly reinventing since 1911, we are not only one of the largest corporate organizations in the world, we’re also one of the biggest technology and consulting employers, with many of the Fortune 500 companies relying on the IBM Cloud to run their business.

At IBM, we pride ourselves on being an early adopter of artificial intelligence, quantum computing and blockchain. Now it’s time for you to join us on our journey to being a responsible technology innovator and a force for good in the world.

IBM is proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, genetics, pregnancy, disability, neurodivergence, age, or other characteristics protected by the applicable law. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status.

OTHER RELEVANT JOB DETAILS

For additional information about location requirements, please discuss with the recruiter following submission of your application.