← All jobs · More in this country

(Senior) Incident Responder

CANCOM

Hamburg

Hybrid · Senior · Full-time

The Role

The role centres on analysing and managing security incidents, performing root-cause analysis and impact assessments, and coordinating remediation strategies for clients. Day-to-day work includes threat hunting across IT and cloud environments, forensic investigations on Windows, Linux and cloud infrastructure, and working within SIEM, EDR, XSOAR and NIDS toolsets. Participation in 24/7 on-call rotation is required.

Skills & Experience

Candidates need strong knowledge of Windows, Linux, Azure and Active Directory, plus experience handling incidents such as BEC, ransomware and domain compromise. Proficiency with EDR tooling, SIEM analysis and log-source interpretation is essential, along with expertise in at least two specialist areas such as cloud forensics, mobile forensics, macOS IR, malware analysis or threat intelligence.

Who It Suits

This role suits an experienced incident responder or DFIR professional who is comfortable advising both technical teams and management stakeholders under pressure. Those with a structured, solution-oriented mindset and a desire to work across diverse client environments — including cloud and hybrid infrastructures — will thrive here.

Typical advertised salary for Incident Response roles in Germany: €81,000–€115,000 (median €87,000 — from 14 recent listings analysed by Forensic Focus).

Learn More/Apply

Applications are handled entirely by the employer or the original listing site. Forensic Focus aggregates and summarises public listings; details can change after publication — always confirm on the employer's page.

Listed: 2026-09-04