> Markdown version of [/jobs/ext/434701-cybersecurity-engineer-incident-response-lead](https://www.wearedevelopers.com/jobs/ext/434701-cybersecurity-engineer-incident-response-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # CyberSecurity Engineer, Incident Response Lead - **Company:** Mistral AI - **Location:** Paris, France (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Cloud Computing, Cloud Engineering, Cyber Security, Digital Forensics, Intrusion Detection and Prevention, Python (Programming Language), Google Cloud, Mitre Att&ck, Kubernetes, Hardware Infrastructure - **Published:** June 24, 2026 - **Apply:** https://fr.indeed.com/viewjob?jk=8ea5c69668f84aff ## About the Role Do you have experience in Python?, * Significant experience leading complex incident response and digital forensics investigations in cloud-native, technology, or similarly high-stakes environments. * Demonstrated ability to take command during critical incidents and coordinate multidisciplinary teams under pressure. * Strong knowledge of cloud and container forensics, including environments such as AWS, GCP, Kubernetes, and on-premises infrastructure. * Hands-on experience with endpoint forensics, ideally including macOS environments. * Strong understanding of attacker behaviors, investigation methodologies, evidence handling, and the MITRE ATT&CK framework. * Experience building incident response runbooks, forensic workflows, tabletop exercises, and post-incident review practices. * Ability to automate investigative or response workflows using Python, Go, or similar languages. * Excellent written and verbal communication skills, with the ability to communicate clearly with engineers, legal teams, executives, and other stakeholders. * A calm, methodical, and pragmatic approach, combined with a strong sense of ownership. * Experience mentoring others or helping build an incident response capability is highly valued. ## Description Mistral AI is looking for a senior Incident Response and Digital Forensics specialist to lead our incident response capability across a complex, rapidly evolving AI ecosystem. Reporting to the SOC Lead, you will take end-to-end ownership of major security incidents, from initial investigation and containment through remediation and post-incident improvement. During critical events, you will act as the incident commander, bringing structure, sound judgment, and calm leadership to high-pressure situations. This is a hands-on, player-coach position combining deep technical investigations with capability building. You will help define our incident response methodology, forensic tooling, runbooks, exercises, and post-mortem practices. As the organization grows, the role may also offer opportunities to build and lead a dedicated incident response team., * Own the incident response lifecycle for high-severity security events, including triage, investigation, containment, remediation, recovery, and post-incident review. * Act as incident commander, coordinating technical teams and key stakeholders during complex security incidents. * Build, maintain, and test incident response runbooks covering Mistral's most important risk scenarios. * Develop and operate forensic capabilities across cloud, containerized, on-premises, and endpoint environments. * Preserve, collect, and analyze digital evidence using rigorous and repeatable forensic methodologies. * Partner with SOC and Detection Engineering teams to strengthen detection-to-response workflows and improve investigative readiness. * Design and facilitate tabletop exercises with engineering, legal, communications, and leadership stakeholders. * Lead blameless post-mortems and ensure lessons learned translate into durable technical and organizational improvements. * Define clear incident communication and escalation practices for both technical and non-technical stakeholders. * Contribute to the long-term development of Mistral's incident response function, with the potential to mentor or lead future team members. ## Related Videos - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Cloud Run- the rise of serverless and containerization](https://www.wearedevelopers.com/videos/106-cloud-run-the-rise-of-serverless-and-containerization) - [Instant KAI Sandboxes with vCluster: Multi-Tenant, Multi-Scheduler GPU Sharing](https://www.wearedevelopers.com/videos/100333-instant-kai-sandboxes-with-vcluster-multi-tenant-multi-scheduler-gpu-sharing) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)