Mach aus dieser Rolle ein Vorstellungsgespräch — ein Lebenslauf und ein Anschreiben, die darauf ausgerichtet sind, was dieser Arbeitgeber sucht.
Forensic Focus Limited in Hamburg is seeking an experienced incident responder to analyse and manage security incidents, perform root-cause analysis and coordinate remediation for clients.
You will conduct threat hunting across IT and cloud environments, perform forensic investigations on Windows, Linux and cloud infrastructure, and operate within SIEM, EDR, XSOAR and NIDS toolsets; on-call rotation is required.
The role centres on analysing and managing security incidents, performing root-cause analysis and impact assessments, and coordinating remediation strategies for clients. Day-to-day work includes threat hunting across IT and cloud environments, forensic investigations on Windows, Linux and cloud infrastructure, and working within SIEM, EDR, XSOAR and NIDS toolsets. Participation in 24/7 on-call rotation is required.
Candidates need strong knowledge of Windows, Linux, Azure and Active Directory, plus experience handling incidents such as BEC, ransomware and domain compromise. Proficiency with EDR tooling, SIEM analysis and log-source interpretation is essential, along with expertise in at least two specialist areas such as cloud forensics, mobile forensics, macOS IR, malware analysis or threat intelligence.
This role suits an experienced incident responder or DFIR professional who is comfortable advising both technical teams and management stakeholders under pressure. Those with a structured, solution-oriented mindset and a desire to work across diverse client environments - including cloud and hybrid infrastructures - will thrive here.