Incident Response Lead

Coalition

Confirmed live yesterday High trust
Remote

Quick summary

Work type
Remote
Location
Germany
Posted
41 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

How this pay compares to similar roles

Similar $175k
$123k most similar roles pay here $219k

This listing doesn't post a salary. Most similar roles pay $140,000–$210,087.

Based on 240 similar postings.

Employer

About Coalition

Coalition is a cyber insurance and security company that combines comprehensive cyber insurance coverage with active risk management tools to help organizations prevent and respond to cyber incidents. Industry: Cyber Insurance & Risk Management

Coalition currently has 21 open roles on FindRole.

Most-posted roles

View all roles at Coalition

At a glance

TL;DR · Incident Response Lead

Incident Response Lead, Germany (m/w/d) joins the Cyber Incident Response team as an early in-country hire to establish and expand the regional presence. This role involves leading incident response engagements, conducting forensic investigations into data breaches, and providing remediation guidance for customers across Germany and the broader region. The successful candidate will analyze Windows, Linux, and Mac OS X systems to identify indicators of compromise while evaluating customer security programs and infrastructure. Key technical requirements include proficiency with tools such as Velociraptor, Axiom, FTK, SIFT, Volatility, ELK, WireShark, Plaso, Skadi, and EDR platforms like CrowdStrike Falcon or Sentinel One. Candidates must possess a Bachelor’s degree in a relevant field, fluency in German and English, and deep knowledge of TCP/IP protocols, NIST frameworks, GDPR regulations, and cloud-based assessment on AWS.

What you'll do

  • Lead incident response engagements to guide customers through forensic investigations and containment of security incidents.
  • Investigate data breaches by analyzing Windows, Linux, and Mac OS X systems using forensics tools.
  • Analyze firewall, web, and database logs to identify evidence of malicious activity and indicators of compromise.
  • Provide technical case reports for threat researchers and tailored risk management guidance for business customers.
  • Evaluate customer security programs and infrastructure to recommend improvements and long-term remediation strategies.
  • Track emerging security practices to build internal processes and improve company products.
  • Monitor German and EU regulatory environments to ensure compliance with local security and privacy expectations.
  • Build and maintain trusted relationships with local customers and partners to grow the regional presence.

What we're looking for

  • Fluency in German and English at a minimum C1 level.
  • Bachelor’s Degree in Computer Science, Information Security, Engineering, or a related field.
  • 5+ years of experience in incident response or digital forensics.
  • Proficiency with forensic tools such as Velociraptor, Axiom, FTK, SIFT, Volatility, ELK, WireShark, Plaso, and Skadi.
  • Experience with EDR tools like CrowdStrike Falcon, Carbon Black, or Sentinel One.
  • Knowledge of TCP/IP protocols, network assessment, and security frameworks such as NIST, HIPAA, and PCI.
  • Familiarity with GDPR and German/EU regulatory considerations regarding data privacy and incident handling.
  • Experience deploying tools to AWS and familiarity with cloud-based platforms for assessment.

More like this

Similar roles

Incident Response Coordinator

Global Payments (TSYS)

Alpharetta, GA 44 days ago
Incident Response NIST CSF GDPR AWS JIRA Linux Unix Windows ITIL Penetration Testing Web Application Assessment Secure Coding Root Cause Analysis
2+ yrs exp

Cyber Defense Response Analyst II

CME Group

Chicago, IL 15 days ago $93,900$156,500
Digital Forensics Incident Response Malware Analysis Python Pandas REST APIs AWS GCP Azure Q Radar Sentinel Splunk Chronicle ArcSight KAPE EnCase Cellebrite FTK Magnet Axiom Autopsy Ghidra Ida Pro PEStudio x64dbg SIEM

CISO Cybersecurity Forensic Analyst

IBM

26 days ago
Digital Forensics Incident Response SIEM EDR Crowdstrike Microsoft Defender for Endpoint Python PowerShell EnCase FTK Autopsy X-Ways Axiom ELK SIFT Plaso IBM Cloud AWS Azure Linux Windows
3+ yrs exp

CISO Cybersecurity Forensic Analyst

IBM

26 days ago
Digital Forensics Incident Response SIEM EDR Crowdstrike Microsoft Defender for Endpoint Python PowerShell EnCase FTK Autopsy X-Ways Axiom ELK SIFT Plaso IBM Cloud AWS Azure Linux Windows
3+ yrs exp

CISO Cybersecurity Forensic Analyst

IBM

9 days ago
Digital Forensics Incident Response SIEM EDR Crowdstrike Microsoft Defender for Endpoint Python PowerShell EnCase FTK Autopsy X-Ways Axiom ELK SIFT Plaso IBM Cloud AWS Azure Linux Windows Mac
3+ yrs exp