Incident Response Lead, Germany (m/w/d)*
Core
Lead Cyber Incident Response engagements for customers in Germany, guiding forensic investigations, containment, and remediation.
Role type
Senior Incident Response Lead (Digital Forensics & Incident Response)
Builds
Forensic investigations, incident containment strategies, and remediation recommendations for enterprise clients.
Domain
Cybersecurity, Digital Forensics, Incident Response
Deliverable
client delivery
Required skills
Incident response, digital forensics, network threat lifecycle analysis, log analysis, EDR tool usage, cloud assessment, regulatory compliance (GDPR/NIST)
Preferred skills
GCIH/GCFA/CISSP certifications, offensive security tools, system hardening, scripting, SCADA experience
Technologies
Velociraptor, Axiom, FTK, SIFT, Volatility, ELK, WireShark, Plaso, Skadi, CrowdStrike Falcon, Carbon Black, Sentinel One, AWS, Nmap, Nessus, Qualys, Burp, Kali, Metasploit
Responsibilities
Guide customers through forensic investigations and incident containment; analyze Windows, Linux, and Mac OS X systems for IOCs; examine logs to identify malicious activity; provide case reporting to technical and business audiences; evaluate customer security programs and recommend enhancements; track emerging security practices and build internal processes; support the growth of the CIR presence in Germany.
Seniority
Senior, hands-on IC with leadership responsibilities