Incident Response Lead (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Incident Response Lead (Cybersecurity): Establishing and expanding the incident response presence in the German market by guiding customers through forensic investigations and security containment with an accent on multi-OS analysis and remediation. Focus on identifying indicators of compromise, evaluating security programs, and ensuring compliance with EU regulatory expectations.
Location: Any location, Germany
Company
is an Active Insurance provider that combines comprehensive insurance coverage with innovative cybersecurity tools to help businesses prevent and mitigate digital risk.
What you will do
- Lead incident response engagements, guiding customers through forensic investigations, containment, and long-term remediation.
- Analyze Windows, Linux, and Mac OS X systems to identify Indicators of Compromise (IOCs) using specialized forensics tools.
- Examine firewall, web, database, and other log sources to identify evidence of malicious activity.
- Provide technical case reporting for both threat researchers and business customers.
- Evaluate customer security programs and recommend enhancements to navigate information security risk.
- Support the growth of the Cyber Incident Response (CIR) presence in Germany as an early in-country hire.
Requirements
- 5+ years of experience in incident response or digital forensics.
- Fluency in both German and English.
- Proficiency with forensics tools (e.g., Velociraptor, Axiom, FTK, SIFT, Volatility) and EDR tools (e.g., CrowdStrike, Sentinel One).
- Deep knowledge of TCP/IP protocols, network assessment, and network traffic capture analysis.
- Familiarity with GDPR and German/EU regulatory considerations regarding data privacy and incident handling.
- Bachelor’s Degree in Computer Science, Information Security, Engineering, or a relevant field.
Nice to have
- Certifications such as GCIH, GCIA, GCFA, GCFE, ACE, EnCE, CFCE, or CISSP.
- Experience with system hardening procedures for Windows, Linux, and Unix.
- Knowledge of offensive tools like Nmap, Nessus, Kali, or Metasploit.
- Scripting skills for the development of security tools and industry frameworks.
- Experience with SCADA/Control systems network security.
Culture & Benefits
- Remote-first, inclusive culture focused on a mission to "Protect the Unprotected".
- 100% public healthcare coverage and statutory pension.
- 30+ paid holidays per year.
- Annual home office stipend.
- Mental and physical health wellness programs.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →