Incident Response Lead
Leads customer incident response and digital forensics engagements, investigating breaches, containing threats, and recommending remediation. Requires 5+ years of experience, strong knowledge of forensic and EDR tools, AWS, security frameworks, and German and English communication.
About the job
Responsibilities
- Drive incident response engagements, guide customers through forensic investigations, contain security incidents, and provide longer-term remediation recommendations.
- Coordinate and guide incident response assistance from team members and vendors.
- Investigate customer data breaches and malicious activity using forensic tools; analyze Windows, Linux, and Mac OS X systems to identify Indicators of Compromise (IOCs); examine firewall, web, database, and other logs for evidence of malicious activity.
- Prepare case reports for internal and external audiences with appropriate technical detail for threat researchers and business customers.
- Evaluate customer security programs, technologies, controls, and business environments; recommend and develop enhancements.
- Recommend solutions to help customers manage information security risk.
- Track emerging security practices and contribute to internal processes and products.
- Stay current on regulatory requirements, industry trends, and Germany- and EU-relevant security and privacy expectations.
- Support the growth of Coalition’s CIR presence in Germany as an early in-country team member, building relationships with local customers and partners.
Requirements
- Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field.
- 5+ years of incident response or digital forensics experience.
- Practical knowledge of network threat lifecycles, attacks, attack vectors, exploitation methods, and intrusion-set tactics, techniques, and procedures.
- Knowledge of TCP/IP protocols, network assessment, security applications, log analysis, and network-traffic capture assessment.
- Experience with Velociraptor, Axiom, FTK, SIFT, Volatility, ELK, Wireshark, Plaso, Skadi, or comparable forensic, log-analysis, and network-assessment tools.
- Experience with EDR tools such as CrowdStrike Falcon, Carbon Black, or SentinelOne.
- Knowledge of industry frameworks including NIST, HIPAA, and PCI.
- Familiarity with GDPR and German and EU regulatory considerations, including data privacy and incident-handling expectations.
- Strong written and verbal communication skills in both German and English.
- Ability to learn technical concepts, manage multiple tasks and projects, and guide teams of analysts.
- Experience deploying tools to AWS and using cloud platforms for assessment.
- Strong critical-thinking, diagnostic, and troubleshooting skills.
- Customer-oriented approach and ability to communicate technical information to nontechnical audiences.
- Comfort with command-line interfaces and high-priority incident scenarios.
- Knowledge of project management.
- Flexibility to support urgent response needs during Central European business hours.
- Ability to work effectively as an early hire in a new market with a builder mindset and strong cross-functional collaboration.
Nice-to-Haves
- GCIH, GCIA, GCFA, GCFE, ACE, EnCE, CFCE, CISSP, or similar certification.
- Security policy, governance, privacy, or regulatory experience, including NIST, ISO, HIPAA, or PCI.
- Familiarity with Germany- or EU-relevant security practices and BSI-aligned environments.
- Experience securing cloud platforms such as Microsoft Azure or Amazon AWS.
- Experience with system hardening for Windows, Linux, or Unix.
- Knowledge of Nmap, Nessus, Nexpose, Qualys, Burp, Kali, Metasploit, Meterpreter, or comparable offensive-security tools.
- Scripting experience for security-tool development and industry frameworks.
- SCADA or control-systems network experience.
- Experience contributing thought leadership to the DFIR industry.
Compensation and Benefits
- 100% public healthcare coverage.
- 30+ paid holidays.
- Annual home-office stipend.
- Statutory pension.
- Mental and physical health wellness programs.
- Competitive compensation and advancement opportunities.
Skills
Incident Response, Digital Forensics, TCP/IP, Network Traffic Analysis, Velociraptor, Ftk, Volatility, Elk, Crowdstrike Falcon, AWS, Nist, GDPR, Windows, Linux, Wireshark
Similar jobs
Security Engineering jobsSenior offensive security engineer responsible for penetration testing, adversary emulation, exploit development, threat modeling, and security automation across cloud, container, SaaS, and AI/ML systems. Requires at least 3 years of security engineering experience, strong development skills, and hands-on offensive security expertise.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Security Engineer responsible for threat modeling, security reviews, vulnerability management, cloud and Kubernetes security, and detection and response across products and production infrastructure. Requires 7+ years of cloud security experience and hands-on expertise with IAM, infrastructure as code, automation, and security tooling.
Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.