← All jobs · More in this country

IT-Forensiker*in (gn*) Incident Response

Certified Security Operations Center GmbH

Bornheim, North Rhine-Westphalia

Onsite · Mid · Full-time

The Role

This position centres on managing and leading incident response engagements for clients, covering the full lifecycle from initial triage through to containment. Day-to-day work includes conducting digital forensic investigations across endpoints and servers, identifying attack indicators, supporting threat-hunting efforts, and contributing to the continuous improvement of DFIR toolchains and detection methods.

Skills & Experience

Candidates require several years of hands-on experience in incident response and digital forensics, with strong working knowledge of tools such as Autopsy, Volatility, Eric Zimmermann tools, YARA, and Sigma. Familiarity with MITRE ATT&CK, Windows, Linux, and macOS internals, and network protocols is expected. German at C1/C2 level is essential.

Who It Suits

This role suits an experienced forensic investigator who is comfortable taking ownership of complex security incidents and communicating clearly with clients under pressure. Someone who enjoys both deep technical analysis and collaborative work within a SOC blue-team environment, and who is happy working primarily on-site, will thrive here.

Typical advertised salary for Digital Forensics roles in Germany: €51,000–€74,000 (median €51,000 — from 13 recent listings analysed by Forensic Focus).

Learn More/Apply

Applications are handled entirely by the employer or the original listing site. Forensic Focus aggregates and summarises public listings; details can change after publication — always confirm on the employer's page.

Listed: 2026-06-22