
Incident Response Expert, AI-Augmented Cyber Incident Response
Posted Sep 3

Posted Sep 3
This is a fully remote position, open to applicants in Germany.
• Conceptually design and implement the immediate incident response workstream for “Defending the Castle,” concentrating on AI-augmented attacks that may occur at machine speed.
• Develop actionable response playbooks and SOPs addressing identity compromise, cloud control-plane abuse, endpoint intrusion, lateral movement, ransomware-style disruption, and data-impact scenarios.
• Establish decision points for containment, escalation, evidence preservation, communication, legal/regulatory handover, and crisis coordination.
• Offer technical consultation and recommendations to SOC, threat intelligence, security monitoring, infrastructure, application, Azure, on-premise, and resilience teams.
• Create and technically define a repeatable operating model for response readiness, evidence collection, handover, and post-incident enhancement before the end of Q1 2027.
• Provide technical guidance to ensure a swift, consistent, and controlled response to AI-assisted cyber incidents across hybrid Azure and on-premise environments.
• Predefine and document roles, triggers, containment options, and communication paths to enhance incident response workflows.
• Develop guidelines to facilitate responder actions when critical thresholds are reached.
• Transform lessons learned from exercises and response evaluations into improved playbooks, SOPs, and control requirements.
• Prepare scenario walkthroughs for validation by SOC, Cyber Defense, legal/compliance, cloud, infrastructure, and resilience stakeholders.
• Evaluate exercise results against time-to-triage, time-to-contain, decision latency, and handover quality.
• Conduct usability testing of playbooks with responders who were not involved in their creation.
• Create a management-ready dashboard highlighting readiness gaps, residual risks, and agreed next steps.
• Identify and technically analyze gaps in existing processes and document opportunities for optimization.
• Transform risk evaluations into actionable playbooks, technical control frameworks, test protocols, backlog items, and management evidence.
• Provide a structured handover of a Phase 2 backlog along with recommendations for the broader Business IT resilience plan after Q1 2027.
• Compile thorough documentation of results and hand over materials to the customer for review and approval for further use.
• A minimum of 8 years in incident response, cyber defense operations, crisis management, digital forensics, or security operations leadership.
• Hands-on experience in addressing identity compromise, ransomware, cloud compromise, endpoint intrusion, and lateral movement incidents.
• Strong knowledge of the Microsoft security stack, Azure/Entra ID response actions, EDR isolation, forensic triage, and evidence preservation.
• Proven capability to coordinate cross-functional technical and management stakeholders in high-pressure environments.
• Relevant certifications such as GCIH, GCFA, GNFA, CISSP, CISM, SC-200, AZ-500, or equivalent are advantageous.
• Profiles must be submitted in English.
• Contract duration: 21.09.2026 – 31.03.2027.
• 40 hours per week.
• Remote work.
SOFTSWISS
Inetum
Cencora
Cencora
Get handpicked remote jobs straight to your inbox weekly.