(Senior) Incident Responder
CANCOM
Aachen, North Rhine-Westphalia
The Role
The position involves analysing and triaging security incidents including root-cause analysis and impact assessment, coordinating remediation for clients, and conducting forensic investigations across Windows, Linux and cloud infrastructures. The role also includes threat hunting, attacker activity tracking across log sources, and participating in 24/7 on-call coverage for critical incidents.
Skills & Experience
Candidates should have strong knowledge of modern IT environments (Windows, Linux, Azure, Active Directory) and forensic artefacts, experience with scenarios such as ransomware, BEC and domain compromise, and proficiency in SIEM, EDR, XSOAR and NIDS tooling. Specialism in at least two areas — such as cloud forensics, mobile forensics, malware analysis or threat intelligence — is expected.
Who It Suits
This role suits an experienced incident responder or DFIR professional who is comfortable operating under pressure, communicating findings at both technical and management levels, and advising enterprise clients. Candidates seeking a senior-level position within a large managed security services environment will find this role well matched to their ambitions.
Typical advertised salary for Incident Response roles in Germany: €81,000–€115,000 (median €87,000 — from 14 recent listings analysed by Forensic Focus).
Learn More/Apply





