Cyber Security Analyst – Level 3
Finanz Informatik Technologie Service
Stuttgart, Baden-Württemberg
The Role
This senior position holds operational leadership for the most complex and critical security incidents at escalation level three. Day-to-day responsibilities span deep forensic examination of compromised systems, proactive threat hunting, malware analysis, and developing detection rules and use cases in SIEM, EDR and XDR platforms using the MITRE ATT&CK framework.
Skills & Experience
Candidates require three to five years of SOC or incident response experience and proven hands-on knowledge of digital forensics tools such as EnCase, FTK, Volatility, X-Ways, Autopsy or KAPE. Familiarity with Microsoft Sentinel, Splunk, CrowdStrike and Defender for Endpoint is expected. Certifications such as GCFE, GCFA or equivalent GIAC credentials are desirable.
Who It Suits
This role suits an experienced DFIR specialist who thrives in high-pressure environments and is comfortable leading technical response efforts while communicating findings to management and clients. Those who enjoy mentoring colleagues and shaping SOC processes alongside hands-on investigative work will find it particularly rewarding.
Typical advertised salary for Digital Forensics roles in Germany: €51,000–€75,000 (median €51,000 — from 18 recent listings analysed by Forensic Focus).
Compare Digital Forensics salaries in Germany →
Certifications mentioned: GCFA · GCFE — find training for these on the DFIR Training Finder.





