Security Incident Responder (m/w/d)
techculture GmbH
Berlin
The Role
Practitioners lead technical responses to active cyber incidents, primarily ransomware and business email compromise cases, on behalf of mid-sized organisations. Day-to-day work spans log analysis, attack vector investigation, containment planning, system recovery, and producing forensic reports that support insurance claim resolution.
Skills & Experience
The role requires several years of hands-on incident response experience, with strong capability across system, network, and application-level analysis. Familiarity with Microsoft 365 environments is essential. Experience developing playbooks, conducting post-incident reviews, and working with automation and AI-assisted tooling is also expected.
Who It Suits
This position suits an experienced responder who thrives under pressure, enjoys leading complex engagements end to end, and communicates clearly with both technical teams and senior business stakeholders. Those comfortable operating at the intersection of cyber insurance, IT forensics, and rapid crisis management will find it a strong fit.
Typical advertised salary for Incident Response roles in Germany: €81,000–€115,000 (median €86,000 — from 10 recent listings analysed by Forensic Focus).
Learn More/Apply





