# Incident Response Lead

**Company:** [Coalition Security](https://hotfix.jobs/companies/coalition-security)
**Location:** Remote
**Role:** Security Engineering
**Experience:** 5+ years
**Skills:** Incident Response, Digital Forensics, TCP/IP, Network Traffic Analysis, Velociraptor, Ftk, Volatility, Elk, Crowdstrike Falcon, AWS, Nist, GDPR, Windows, Linux, Wireshark
**Posted:** 2026-08-13

> Leads customer incident response and digital forensics engagements, investigating breaches, containing threats, and recommending remediation. Requires 5+ years of experience, strong knowledge of forensic and EDR tools, AWS, security frameworks, and German and English communication.

## Job Description

## Responsibilities

- Drive incident response engagements, guide customers through forensic investigations, contain security incidents, and provide longer-term remediation recommendations.
- Coordinate and guide incident response assistance from team members and vendors.
- Investigate customer data breaches and malicious activity using forensic tools; analyze Windows, Linux, and Mac OS X systems to identify Indicators of Compromise (IOCs); examine firewall, web, database, and other logs for evidence of malicious activity.
- Prepare case reports for internal and external audiences with appropriate technical detail for threat researchers and business customers.
- Evaluate customer security programs, technologies, controls, and business environments; recommend and develop enhancements.
- Recommend solutions to help customers manage information security risk.
- Track emerging security practices and contribute to internal processes and products.
- Stay current on regulatory requirements, industry trends, and Germany- and EU-relevant security and privacy expectations.
- Support the growth of Coalition’s CIR presence in Germany as an early in-country team member, building relationships with local customers and partners.

## Requirements

- Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field.
- 5+ years of incident response or digital forensics experience.
- Practical knowledge of network threat lifecycles, attacks, attack vectors, exploitation methods, and intrusion-set tactics, techniques, and procedures.
- Knowledge of TCP/IP protocols, network assessment, security applications, log analysis, and network-traffic capture assessment.
- Experience with Velociraptor, Axiom, FTK, SIFT, Volatility, ELK, Wireshark, Plaso, Skadi, or comparable forensic, log-analysis, and network-assessment tools.
- Experience with EDR tools such as CrowdStrike Falcon, Carbon Black, or SentinelOne.
- Knowledge of industry frameworks including NIST, HIPAA, and PCI.
- Familiarity with GDPR and German and EU regulatory considerations, including data privacy and incident-handling expectations.
- Strong written and verbal communication skills in both German and English.
- Ability to learn technical concepts, manage multiple tasks and projects, and guide teams of analysts.
- Experience deploying tools to AWS and using cloud platforms for assessment.
- Strong critical-thinking, diagnostic, and troubleshooting skills.
- Customer-oriented approach and ability to communicate technical information to nontechnical audiences.
- Comfort with command-line interfaces and high-priority incident scenarios.
- Knowledge of project management.
- Flexibility to support urgent response needs during Central European business hours.
- Ability to work effectively as an early hire in a new market with a builder mindset and strong cross-functional collaboration.

## Nice-to-Haves

- GCIH, GCIA, GCFA, GCFE, ACE, EnCE, CFCE, CISSP, or similar certification.
- Security policy, governance, privacy, or regulatory experience, including NIST, ISO, HIPAA, or PCI.
- Familiarity with Germany- or EU-relevant security practices and BSI-aligned environments.
- Experience securing cloud platforms such as Microsoft Azure or Amazon AWS.
- Experience with system hardening for Windows, Linux, or Unix.
- Knowledge of Nmap, Nessus, Nexpose, Qualys, Burp, Kali, Metasploit, Meterpreter, or comparable offensive-security tools.
- Scripting experience for security-tool development and industry frameworks.
- SCADA or control-systems network experience.
- Experience contributing thought leadership to the DFIR industry.

## Compensation and Benefits

- 100% public healthcare coverage.
- 30+ paid holidays.
- Annual home-office stipend.
- Statutory pension.
- Mental and physical health wellness programs.
- Competitive compensation and advancement opportunities.

## Similar jobs

- [Senior Security Engineer, Offensive Security](https://hotfix.jobs/jobs/e6f5289c-9cb8-4a13-b321-e0ecc9a54c96) - Docker - Remote - €119k – €170k/yr
- [Senior Security GRC Analyst](https://hotfix.jobs/jobs/b54fb115-3bb7-4d88-8fdc-b7901d26d90d) - Monarch - Remote - $180k – $215k/yr
- [Security Engineer - Product](https://hotfix.jobs/jobs/d32dc9fa-f31b-4fc4-a7c6-eade39acfb64) - Wiz - Berlin, Germany
- [Lead Product GRC Subject Matter Expert](https://hotfix.jobs/jobs/57c937d5-05e3-4033-875a-890645c4aa6b) - Vanta - Remote - $230k – $270k/yr
- [Platform Security Engineer](https://hotfix.jobs/jobs/e556dd76-0f95-4dfa-9d3d-e476f24057c0) - Supabase - Remote

**Apply:** https://hotfix.jobs/jobs/f4e8c3a7-ab6d-4403-b89a-38e5cdac0cb1
**Canonical:** https://hotfix.jobs/jobs/f4e8c3a7-ab6d-4403-b89a-38e5cdac0cb1