Job Openings Cyber Incident Training officer

About the job Cyber Incident Training officer

About REST Solution

REST Solution is an IT services and cybersecurity partner providing end-to-end, 24/7 support to help businesses manage their IT infrastructure, support users, migrate to the cloud, strengthen cybersecurity, and implement proactive monitoring and response. The company works as an extension of its customers' IT and security teams, with a focus on reliable operations, responsive service, and scalable support across multiple countries.

REST Solution's services include managed IT, 24/7 helpdesk, 24/7 infrastructure monitoring through its NOC, infrastructure maintenance, cloud and infrastructure projects, cybersecurity engineering, vulnerability management, SOC and CSIRT services, and governance and compliance support. REST Solution is ISO 27001 certified, reflecting its commitment to structured information security practices and operational resilience.

Founded in 2015, REST Solution supports international organizations through a global operating model, with multiple locations worldwide, multilingual support capabilities, and customer-centric service delivery. Its purpose is reflected in its motto: We take care of your IT, you REST.

Role Overview

Within the Group's CERT (Computer Emergency Response Team), this hybrid role combines two complementary dimensions:

When there is no on-going incident of severity medium and more, the role is to be a Cyber Incident Training officer within the CERT, focused on preparation, training, and continuous improvement of the response to major cyber incidents.

When there is an on-going incident of severity medium and more. The role turns in to be a Cyber incident Secretary within the tactical crisis unit—under the authority of the Incident Response Lead and serves directly the cause of the incident. The role is responsible for ensuring updated logbook, tracking the action plan with the Incident Response Team, elaborate communication plans, structuring information flow, ensuring the full traceability of decisions, actions, and key discussion points throughout the crisis.

Duties and Responsibilities

A. Cyber incident – Crisis coordinator/secretary within the tactical cell:

1. Crisis Log Maintenance

Chronologically record all events, decisions, alerts, and actions from the activation of the crisis management team until its deactivation.
Note the participants, the times of situation updates, decisions made, and contextual information.


2. Crisis Management Document Production

Draft regular situation updates (hourly or daily summaries).
Produce decision records (who decided what, when, and on what basis).
Update action tracking spreadsheets (who does what, deadlines, and status).


3. Information Dissemination and Sharing

Ensure targeted distribution of documents to identified stakeholders (management, business units, legal, communications, CISO, service providers, etc.).
Contribute to filtering and structuring information flows.


4. Support for the organization of the cell

Participate in organizing status meetings (agenda, materials, timing).
These activities are non-exhaustive and can evolve according to operational needs.

B. Cyber incident training officer within CERT team:

1. Design and facilitation of cyber crisis exercises: Create and facilitate tabletop exercises (TTX) and other simulations of major cyber incidents to assess and improve team preparedness.


2. Training and awareness:

Produce and disseminate educational materials (presentations, guides, online modules) regarding incident response and cyber crisis management.


Design and facilitate training sessions and workshops to help employees identify and report potential threats.


Promote cybersecurity best practices.

3. Cross-functional contribution to the Cyber Defense Center and CERT:


Participate in cross-functional collaboration activities within the Cyber Defense Center (information sharing, practice harmonization, joint projects).


Contribute to projects, improvements, and compliance efforts related to the CERT (tools, processes, metrics, reporting).


Ensure alignment with standards and best practices (e.g., ENISA, NIST, ISO 22301/27035, sector-specific guidelines).

Qualifications and Skills

Minimal Operational experience in cybersecurity (2 years), ideally close from CERT, CSIRT, SOC, or incident response function.


Not being a Technical expert, but having a good understanding of cyber-attacks, IT system architectures, and detection, investigation, and remediation mechanisms.


Being flexible in the working hours if requested when CRISIS occurs (Extra-working hours are always compensated).


Ability to rapidly analyze Chaotic situations, identify key elements, key actors, and communicate findings clearly, reliably, and in a structured manner.


Proficiency in incident management practices, including maintaining crisis logs, tracking actions, documenting decisions, and preserving evidence.


Ability to work under pressure with rigor, precision, and discretion.


Strong ability to synthesize information, excellent organizational skills, and meticulous attention to detail.


Excellent communication and presentation skills, with the ability to convey complex information clearly and effectively.


Proven ability to develop and deliver engaging training content and simulations.


Strong analytical and problem-solving skills.


You have a good understanding of information security incident management processes and methodologies (e.g.: ISO 27035, NIST framework or SANS 6-steps).


You master oral and written English in a professional context.

Qualities

Meticulousness, neutrality, and discretion.
High stress tolerance.
Ability to prioritize.
Ability to work under pressure without compromising accuracy.
Autonomy and proactive behavior
Excellent verbal and written communication
Analysis and synthesis capacity