Incident Response Expert
Michael Page
Düsseldorf, North Rhine-Westphalia
The Role
This contract position centres on designing and implementing a comprehensive incident response operating model. Day-to-day work includes developing playbooks and SOPs for scenarios such as ransomware, identity compromise and cloud control plane abuse, conducting technical gap analyses, running IR exercises, and producing management dashboards on readiness gaps and residual risks.
Skills & Experience
Candidates need at least eight years in incident response, cyber defence or security operations, with hands-on experience handling ransomware, endpoint intrusions and cloud compromise. Strong knowledge of the Microsoft Security stack, Azure and Entra ID is essential. Certifications such as GCIH, GCFA, GNFA, CISSP, SC-200 or AZ-500 are advantageous.
Who It Suits
This role suits a seasoned IR practitioner comfortable advising both technical teams and senior stakeholders during critical incidents. Fluency in German and English is required. The fully remote engagement runs until end of Q1 2027, making it ideal for an experienced contractor seeking a structured, high-impact project assignment.
Typical advertised salary for Incident Response roles in Germany: €81,000–€115,000 (median €87,000 — from 14 recent listings analysed by Forensic Focus).
Compare Incident Response salaries in Germany →
Certifications mentioned: GCFA · GNFA · GCIH · CISSP — find training for these on the DFIR Training Finder.





