Incident Response Expert (m/f/d)
Project Period: 21 September 2026 to 31 March 2027
Location: Germany Remote
Workload: 40 hours per week
Project Overview
We are looking for a highly experienced Incident Response Expert to support an immediate cyber threat resilience initiative focused on strengthening detection, response, containment and recovery readiness.
The project addresses increasingly sophisticated and AI assisted cyber attacks that can develop at machine speed. The objective is to establish practical and repeatable incident response capabilities that enable fast, consistent and controlled action across hybrid Azure and on premise environments.
Responsibilities
Develop and implement the immediate Incident Response workstream for AI assisted cyber attacks
Create practical incident response playbooks and SOPs covering identity compromise, cloud compromise, endpoint intrusion, lateral movement, ransomware and data impact scenarios
Define clear decision points and procedures for containment, escalation, evidence preservation, communication and crisis coordination
Provide expert technical guidance to SOC, Cyber Defence, Threat Intelligence, Security Monitoring, Infrastructure, Application, Azure, On Premise and Resilience teams
Define a repeatable operating model for incident response readiness, evidence collection, handover and post incident improvement
Establish roles, triggers, containment options and communication paths to improve incident response workflows
Develop clear guidelines to support responders when critical incident thresholds are reached
Analyse lessons learned from exercises and incident reviews and translate them into improved playbooks, SOPs and security controls
Support scenario walkthroughs and exercises with technical and management stakeholders
Assess response exercises against metrics such as time to triage, time to contain, decision latency and handover quality
Conduct usability testing of playbooks with responders who were not involved in creating them
Identify gaps and inefficiencies in existing incident response processes and develop recommendations for improvement
Translate risk assessments into executable playbooks, technical control requirements, test protocols and actionable backlog items
Prepare management ready reporting covering readiness gaps, residual risks and recommended next steps
Develop and hand over recommendations and a Phase 2 backlog for the broader cyber resilience programme
Ensure comprehensive documentation and structured handover of all project results
Requirements
Minimum 8 years of professional experience in incident response, cyber defence operations, crisis management, digital forensics or security operations leadership
Strong hands on experience responding to security incidents involving identity compromise, ransomware, cloud compromise, endpoint intrusion and lateral movement
Strong understanding of the Microsoft security ecosystem
Hands on experience with Azure and Entra ID incident response and remediation actions
Experience with EDR based endpoint isolation and containment
Strong knowledge of forensic triage and evidence preservation
Experience working across hybrid Azure and on premise environments
Proven ability to coordinate technical and management stakeholders during high pressure security incidents
Strong understanding of incident response processes, crisis coordination and security operations
Ability to develop practical, actionable playbooks and SOPs rather than purely conceptual documentation
Excellent analytical and problem solving skills
Strong communication skills and the ability to work effectively with both technical and senior management stakeholders
Certifications such as GCIH, GCFA, GNFA, CISSP, CISM, SC-200, AZ-500 or equivalent are advantageous