(Senior) Incident Responder
CANCOM
Hamburg
The Role
The role centres on analysing and managing security incidents, performing root-cause analysis and impact assessments, and coordinating remediation strategies for clients. Day-to-day work includes threat hunting across IT and cloud environments, forensic investigations on Windows, Linux and cloud infrastructure, and working within SIEM, EDR, XSOAR and NIDS toolsets. Participation in 24/7 on-call rotation is required.
Skills & Experience
Candidates need strong knowledge of Windows, Linux, Azure and Active Directory, plus experience handling incidents such as BEC, ransomware and domain compromise. Proficiency with EDR tooling, SIEM analysis and log-source interpretation is essential, along with expertise in at least two specialist areas such as cloud forensics, mobile forensics, macOS IR, malware analysis or threat intelligence.
Who It Suits
This role suits an experienced incident responder or DFIR professional who is comfortable advising both technical teams and management stakeholders under pressure. Those with a structured, solution-oriented mindset and a desire to work across diverse client environments — including cloud and hybrid infrastructures — will thrive here.
Typical advertised salary for Incident Response roles in Germany: €81,000–€115,000 (median €87,000 — from 14 recent listings analysed by Forensic Focus).
Learn More/Apply





