IT-Forensiker*in (gn*) Incident Response
Certified Security Operations Center GmbH
Bornheim, North Rhine-Westphalia
The Role
This position centres on managing and leading incident response engagements for clients, covering the full lifecycle from initial triage through to containment. Day-to-day work includes conducting digital forensic investigations across endpoints and servers, identifying attack indicators, supporting threat-hunting efforts, and contributing to the continuous improvement of DFIR toolchains and detection methods.
Skills & Experience
Candidates require several years of hands-on experience in incident response and digital forensics, with strong working knowledge of tools such as Autopsy, Volatility, Eric Zimmermann tools, YARA, and Sigma. Familiarity with MITRE ATT&CK, Windows, Linux, and macOS internals, and network protocols is expected. German at C1/C2 level is essential.
Who It Suits
This role suits an experienced forensic investigator who is comfortable taking ownership of complex security incidents and communicating clearly with clients under pressure. Someone who enjoys both deep technical analysis and collaborative work within a SOC blue-team environment, and who is happy working primarily on-site, will thrive here.
Typical advertised salary for Digital Forensics roles in Germany: €51,000–€74,000 (median €51,000 — from 13 recent listings analysed by Forensic Focus).
Learn More/Apply





