About the Role
As a Senior Incident Response Manager, you will lead critical security incident responses, analyze complex threats, and drive prevention strategies. You will act as a problem solver and mentor, helping clients navigate cyber crises while continuously improving response processes and tools.
Responsibilities
- Lead and manage incident response operations from initial alert to final reporting
- Analyze and contain security incidents across systems, networks, and applications
- Develop and implement remediation plans to limit damage and restore systems
- Create detailed incident reports and forensic documentation
- Coordinate actions between insurers, policyholders, and IT service providers
- Develop and optimize incident response processes and playbooks
- Conduct post-incident analysis and develop preventive measures
- Collaborate with internal IT teams, departments, and external partners
- Maintain and enhance the incident response tool landscape with a focus on automation and AI
Requirements
- Minimum 5 years of experience in incident response, cyber defense, blue teaming, or IT forensics
- Deep operational experience in analyzing, containing, and remediating cybersecurity incidents
- Strong knowledge of current attack techniques like ransomware, phishing, and APTs
- Extensive experience in IT forensics, including malware analysis
- Understanding of network technologies, operating systems (Windows, Linux), and cloud environments (M365, AWS, Azure, Google Cloud)
- Ability to act decisively under high time pressure
- Excellent communication skills for stakeholders ranging from C-level to non-technical staff
- Experience in consulting clients post-incident and developing security concepts
- Fluent German (C1 or native) and good English (B-level minimum)
Skills
- Incident Response
- IT Forensics
- Malware Analysis
- Cyber Defense
- Threat Hunting
- Threat Intelligence
- SIEM
- EDR
- Windows Defender for Business
- Splunk
- CrowdStrike
- Velociraptor
- X-WAYS
- KAPE
- Hayabusa
- SOF-ELK
- OpenRelik
Location
- Germany (Remote-first)
- Berlin (Office in Kreuzberg)
Work Type
- Remote-first
- Full-time
Experience Level
- Senior
Benefits
- Personal learning and conference budget
- Access to books, online courses, and workshops
- Discounted Deutschlandticket for Berlin office
- 50 Euro monthly meal allowance
- Regular team events
About the Company
- Founded in 2017 in Berlin, specializing in protecting companies from cyber threats
- Focus on helping small and medium-sized enterprises identify and minimize digital risks
- Provides holistic cybersecurity including risk assessments, training, and 24/7 emergency support
- Strong partner to the insurance industry, present in approximately every second cyber insurance policy in Germany
- Team of approximately 30 employees from diverse backgrounds
Equal Opportunity
- We respect diversity and inclusion and welcome people with different backgrounds, ideas, styles, and ways of thinking and working.
