RingCentral logo

Incident response Lead

RingCentral

València, Valencian Community, SpainHybridJobNo compensation foundPosted 1w agoVerified open 3 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
No compensation found
Location
València, Valencian Community, SpainHybrid
Work Authorization
Not specified

Job overview

RingCentral is hiring an Incident response Lead. RingCentral seeks an Incident Response Lead to protect the organization, its customers, and services by identifying, assessing, containing, investigating, communicating, and resolving cybersecurity incidents in a disciplined, evidence‑based manner.

Key focus areas include Lead major security incidents with clarity, authority, and control from declaration to resolution, Identify and declare security incidents while assessing scope, attacker behavior, and technical impact, and Contain active threats, eradicate root causes, and restore impacted production services.

Important skills include Cyber Security, Incident Response, Digital Forensics, Threat Detection, Technical Analysis, and Root Cause Analysis. Preferred (not required): NIST Incident Response Guidance, ISO/IEC 27035, SANS Incident Handling Practices, and MITRE ATT&CK.

Skills & qualifications

RequiredNice to have

Skills

Cyber SecurityIncident ResponseDigital ForensicsThreat DetectionTechnical AnalysisRoot Cause AnalysisProblem ManagementCloud Platform SystemNIST Incident Response GuidanceISO/IEC 27035SANS Incident Handling PracticesMITRE ATT&CKCloud PlatformsContainersEnterprise Identity SystemsNetworksCustomer-Facing ApplicationsIncident Response PlaybooksSeverity ModelsReporting StandardsTabletop ExercisesEnglish

Qualifications

Significant Professional Experience in Cybersecurity or Related DisciplineExperience Leading Complex Cybersecurity IncidentsExperience Coordinating Containment Eradication Recovery Impact AssessmentExperience Communicating Security Incidents to Senior LeadershipExperience Leading or Facilitating Root Cause AnalysesExperience Tracking Corrective Actions Through CompletionPractical Experience With Modern Production EnvironmentsAbility to Participate in on-Call or Major-Incident Escalation ArrangementExperience Responding to Incidents Involving Customer Data or Personal DataExperience Developing Incident Response Playbooks Severity Models Reporting Standards Tabletop ExercisesStrong Written and Spoken EnglishRelevant Certifications May Include GCIH GCFA GCFE CISSP CISM or Equivalent Practical Experience

Benefits

Medical Insurance
Dental Insurance
Vision Insurance

Full job description

RingCentral is a global leader in agentic voice AI–powered business communications, delivering an integrated platform for business phone, SMS, contact center, workforce engagement management, video collaboration, and messaging. As the communications layer connecting businesses and customers, RingCentral is the front door of business communication and is in the advantageous position to apply AI at every phase of the conversation journey — before, during, and after each interaction. Our agentic AI portfolio includes autonomous voice-first AI agents that automate calls, assist in the moment, and analyze every interaction – enabling businesses to work smarter, respond faster, and connect more meaningfully with their customers.

Role mission Protect the organisation, its customers, and its services by ensuring that potential and confirmed cybersecurity incidents are identified, assessed, contained, investigated, communicated, and resolved in a timely, disciplined, and evidence-based manner.

Responsibilities

  • Incident Leadership & Control : Ensure major security incidents are led with absolute clarity, authority, and control, establishing a structured response environment from declaration to resolution.

  • Declaration, Scoping & Technical Analysis: Ensure security incidents are identified and declared consistently, while accurately assessing incident scope, attacker behavior, and technical impact.

  • Threat Containment, Eradication & Recovery: Contain active security threats before additional harm occurs, eradicate root causes, and safely restore impacted production services.

  • Stakeholder Facilitation & Multi-Audience Communication : Deliver transparent, decision-useful reporting to executives, governance teams and cross-functional partners throughout the incident lifecycle.

  • Root Cause Analysis (RCA) & Problem Management: Facilitate meaningful Root Cause Analyses that look beyond surface-level symptoms to produce tangible, long-term security improvements.

  • Corrective Action & Continuous Capability Improvement: Ensure corrective actions are fully completed and verified—not merely recorded—to continuously elevate the overall incident response capability.

Required experience

  • Significant professional experience in cybersecurity, incident response, security operations, digital forensics, threat detection, or a closely related discipline.

  • Demonstrated experience leading complex cybersecurity incidents involving multiple technical and business teams.

  • Experience coordinating containment, eradication, recovery, and impact assessment activities.

  • Experience communicating security incidents to senior leadership.

  • Experience leading or facilitating root cause analyses.

  • Experience tracking corrective actions through completion.

  • Practical experience working with modern production environments, such as cloud platforms, containers, enterprise identity systems, networks, or customer-facing applications.

  • Ability to participate in an on-call or major-incident escalation arrangement.

  • Experience responding to incidents involving customer data or personal data.

  • Experience developing incident response playbooks, severity models, reporting standards, and tabletop exercises.

  • Strong written and spoken English.

Would be a plus

  • Familiarity with NIST incident response guidance, ISO/IEC 27035, SANS incident handling practices, MITRE ATT&CK, or comparable frameworks.

  • Relevant certifications may include GCIH, GCFA, GCFE, CISSP, CISM, or equivalent practical experience.

What we offer

  • Well-coordinated professional team;
  • Breakfast in the office 4 days a week;
  • Cutting edge technologies, interesting and challenging tasks, dynamic project, great opportunities for self-realization, professional and career growth;
  • Flexible working hours and opportunity for a hybrid work;
  • Job placement and payment of salary take place according to the labor code, as well as vacation; sick lists are paid at 100% of full pay;
  • Medical Insurance, including Dental and Vision;
  • Life Insurance;
  • Vacation 23 days.

You've read the whole posting — now see how you match it.