CareerPlanSign in

Team Lead - Security Incident Response (all genders)

Hamburg, HH, de💼 Full-time🗓 2026-08-06 → 2026-09-27

Core

Lead the Security Incident Response team to protect customer data, corporate assets, and online shop security through incident management, forensics, and threat mitigation.

Role type

Senior Team Lead, Security Incident Response (Blue Team/DFIR)

Builds

Incident response playbooks, automated monitoring/scanning tools, DFIR infrastructure, and AI-integrated security operations.

Domain

Cyber Security, Cloud-Native Environments, Digital Forensics

Deliverable

production ML models | product features | dashboards & analysis | client delivery | infrastructure | physical/clinical work

Required skills

Digital Forensics and Incident Response (DFIR), SIEM management, Python programming, Linux proficiency, Cloud-native security, Threat intelligence analysis, Incident response playbooks creation, Web Application Firewall (WAF) management, Leadership, AI integration in security operations

Preferred skills

SANS/GIAC certifications, OffSec OSIR, HackTheBox/TryHackMe experience, Laravel/PHP knowledge, AWS/GCP experience, Gitlab CI/CD, Terraform/Terragrunt

Technologies

Python, Linux, SIEM, Cloudflare, WAF, AWS, GCP, Gitlab CI/CD, Terraform, Terragrunt, AI/LLMs

Responsibilities

Set up and maintain DFIR tools and infrastructure, Provide first response during security incidents including digital forensics, Maintain and improve SIEM tools, Investigate and respond to security alerts, Create and maintain incident response playbooks, Integrate AI into security operations beyond Q/A chat

Seniority

Senior, hands-on IC with leadership responsibilities

Sourced via smartrecruiters · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.