Senior Security Incident Responder
techculture GmbH
Berlin
This role sits at the sharp end of cyber incident response, handling live ransomware attacks and business email compromise cases on behalf of mid-sized organisations, with mandates typically driven by cyber insurance requirements. Day to day, the work involves leading technical response operations from initial triage through containment and recovery, conducting detailed log and attack-vector analysis across system, network, and application layers, and delivering clear, actionable guidance to senior stakeholders under pressure. The position also covers developing playbooks, performing post-incident reviews, coordinating between insurers and their policyholders’ IT teams, and contributing to tooling improvements with an emphasis on automation and AI integration. Forensic documentation and report writing for evidential and insurance purposes form a core part of the output. The role suits an experienced incident responder comfortable making rapid technical decisions in high-stakes environments, with a solid background in M365 forensics and a methodical approach to crisis management. Based in Berlin.
Typical advertised salary for Incident Response roles in Germany: €81,000–€115,000 (median €87,000 — from 14 recent listings analysed by Forensic Focus).
Learn More/Apply





