Cyber Incident Responder

Ellis IT

Deutschland

Hybrid

EUR 52.000 - 70.000

Vollzeit

Vor 11 Tagen
Bewerbungsgenerator

Eine komplette Bewerbung in einer Minute — maßgeschneiderter Lebenslauf und Anschreiben, versandbereit.

Schaffe es an den ATS-Filtern vorbei

Benefits dieser Stelle

Hybrid work model
Immediate start

Zusammenfassung

Ellis IT is seeking an experienced security professional for a permanent incident response role. You will lead containment and remediation during active breaches for diverse clients, blending remote and onsite engagement.

You will collect, analyse logs from diverse sources including Office 365 telemetry, perform disk and memory forensics, and conduct malware analyses to guide remediation under time pressure.

Qualifikationen

  • 4+ years hands-on cybersecurity operations experience.
  • Knowledge of Cyber Kill Chain and MITRE ATT&CK.
  • Understanding of defence-in-depth architectures.
  • Experience with incident handling, threat hunting, and threat intelligence workflows.
  • Proficiency with HIDS/IDS/IPS, SIEMs, AD controllers, and firewalls.
  • Experience with cloud environments: Azure, Office 365, AWS, GCP.

Aufgaben

  • Lead emergency incident response activities, delivering containment, mitigation and remediation actions against active threats.
  • Coordinate initial response efforts remotely and onsite, organising teams and resources to stabilise affected customer environments.
  • Collect, correlate, and analyse logs from servers, firewalls, IDS/IPS platforms, SIEMs, and cloud telemetry, including Office 365.
  • Carry out forensic acquisitions of disks, memory, mobile devices, and other relevant data sources while preserving evidentiary integrity.
  • Perform malware analysis to determine scope, behaviour, and remediation paths.

Kenntnisse

Cybersecurity operations
MITRE ATT&CK
Cyber Kill Chain
SIEMs
HIDS/IDS/IPS
Active Directory
Firewalls
Azure
Office 365
AWS
GCP

Jobbeschreibung

Role overview

This permanent position places an experienced security professional at the centre of cyber incident response, supporting law firms, corporate organisations, and law enforcement clients during active breaches and compromises. The work blends remote and onsite engagement, calling for someone who can lead containment efforts, perform digital forensics, and translate technical findings into clear, actionable guidance under time pressure.

Responsibilities
  • Lead emergency incident response activities, delivering containment, mitigation, and remediation actions against active threats.
  • Coordinate initial response efforts both remotely and onsite, organising teams and resources to stabilise affected customer environments.
  • Collect, correlate, and analyse logs from servers, firewalls, intrusion detection systems, traffic flows, and host systems, with a particular emphasis on Office 365 telemetry.
  • Carry out forensic acquisitions of disks, volatile memory, mobile devices, and other relevant data sources while preserving evidentiary integrity.
  • Perform malware analysis to determine scope, behaviour, and effective remediation paths.
Requirements
  • At least four years of hands-on experience in cybersecurity operations.
  • Demonstrated command of frameworks such as the Cyber Kill Chain and MITRE ATT&CK, alongside broader security intelligence concepts.
  • Solid grasp of enterprise-grade security controls and defence-in-depth architectures.
  • Practical experience with incident handling, threat hunting, and threat intelligence workflows.
  • Proficiency working with HIDS, IDS/IPS platforms, SIEMs, Active Directory controllers, and firewalls.
  • Working knowledge of cloud environments spanning Microsoft Azure, Office 365, Amazon Web Services, and Google Cloud.
Benefits and work setup
  • Permanent, full-time role based in Manchester, United Kingdom, with an immediate start.
  • Salary range of £45,000 to £60,000, dependent on experience.
  • Mix of remote and onsite client engagement, with exposure to a varied portfolio of legal, corporate, and public-sector cases.
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

(Senior) Incident Responder
(Senior) Incident Responder

Forensic Focus Limited • Aachen

Hybrid
EUR 85.000 - 110.000
(Senior) Incident Responder
(Senior) Incident Responder

Forensic Focus Limited • Hamburg

Hybrid
EUR 55.000 - 75.000
Senior Consultant IT Forensik Incident Response
Senior Consultant IT Forensik Incident Response

Forensic Focus Limited • Berlin

Hybrid
EUR 60.000 - 100.000
Cybersecurity Incident Response & Digital Forensics Manager
Cybersecurity Incident Response & Digital Forensics Manager

MAM Gruppe • Hamburg

Vor Ort
EUR 90.000 - 130.000
Senior Consultant Cyber – Digital Forensic Incident Response
Senior Consultant Cyber – Digital Forensic Incident Response

Forensic Focus Limited • Leipzig

Vor Ort
EUR 60.000 - 90.000
Senior Cybersecurity Engineer | Cyber Threat Intelligence & Response (Fully Remote)
Senior Cybersecurity Engineer | Cyber Threat Intelligence & Response (Fully Remote)

Xplor • Deutschland

Hybrid
EUR 70.000 - 110.000
Parental leave
Volunteer days
LinkedIn Learning
+4
Senior Consultant Digital Forensics & Incident Response – Forensics
Senior Consultant Digital Forensics & Incident Response – Forensics

Forensic Focus Limited • Hamburg

Vor Ort
EUR 60.000 - 90.000
Senior Digital Forensics and Incident Response Consultant
Senior Digital Forensics and Incident Response Consultant

Forensic Focus Limited • Ettlingen

Hybrid
EUR 55.000 - 85.000
Manager Digital Forensics & Incident Response (DFIR) – Cyber Security
Manager Digital Forensics & Incident Response (DFIR) – Cyber Security

Forensic Focus Limited • Düsseldorf

Vor Ort
EUR 70.000 - 110.000
Senior Cyber Analyst
Senior Cyber Analyst

Methods • Deutschland

Hybrid
EUR 95.000 - 130.000
Autonomy to develop skills
Exciting project work
Strong leadership
+4