Skip to main content
Coalition

Incident Response Lead - Germany (m/w/d)*

RemoteGermany only
Published
Role
Security
Experience
Lead
Salary not disclosed
Check eligibility

Open to DE only. Set where you work from to check your eligibility.

No BS summary

Incident Response Lead based in Germany; early in-country hire to build Coalition's CIR presence. Requires 5+ years incident response or digital forensics experience and fluency in German and English (min C1). Hands-on with forensic tools, EDRs and cloud-based assessments (AWS).

Core skills

Velociraptor/VolatilityCrowdStrike Falcon/Carbon Black/Sentinel One

Required skills

AxiomFTKSIFTELKWiresharkPlasoSkadiAWSTCP/IP

Optional skills

GCIHGCIAGCFAGCFEACEEnCECFCECISSP

Optional languages

German C1},{

What you'll do

  • Drive incident response engagements to guide our customers through forensic investigations, contain security incidents, and provide guidance on longer term remediation recommendations.
  • Coordinate and guide incident response assistance from team members and vendors.
  • Investigate customer data breaches and malicious activity leveraging forensics tools; analyze Windows, Linux, and Mac OS X systems to identify Indicators of Compromise (IOCs); examine firewall, web, database, and other log sources to identify evidence of malicious activity.
  • Provide case reporting as required across internal and external audiences with the appropriate technical level of detail for threat researchers and/or business customers.
  • Support the growth of Coalition’s CIR presence in Germany as an early in-country team member, helping build trusted relationships with local customers and partners.

What they require

  • Fluency in German and English (Minimum C1).
  • Bachelor’s Degree in Computer Science, Information Security, Engineering, or other relevant subjects.
  • 5+ years of incident response or digital forensics experience.
  • Demonstrated knowledge of the lifecycle of network threats, attacks, attack vectors, and methods of exploitation; knowledge of intrusion set tactics, techniques, and procedures; knowledge of TCP/IP protocols, network assessment and log/network traffic capture assessment.
  • Familiarity with GDPR and awareness of German and EU regulatory considerations, including data privacy and incident handling expectations; experience deploying tools to AWS and using cloud-based platforms for assessment.

Benefits

  • 100% public healthcare coverage
  • 30+ paid holidays
  • Annual home office stipend
  • Statutory pension
  • Mental & physical health wellness programs

provincial political party in Quebec, Canada

🇺🇸 United StatesInsuranceStartupcoalitionavenirquebec.org/
Salary not disclosed