Coalition logo
Coalition·

Incident Response Lead, Germany - Coalition

About Coalition

Coalition is the world's first Active Insurance provider designed to help prevent digital risk before it strikes. Founded in 2017, Coalition combines comprehensive insurance coverage and innovative cybersecurity tools to help businesses manage and mitigate potential cyberattacks.

About the Role

As one of our first Cyber Incident Response (CIR) hires in Germany, this role will help establish and expand Coalition’s incident response presence in the market. You will serve customers in Germany and the broader region, requiring fluency in German and English with the ability to communicate technical concepts clearly to diverse audiences.

Key Responsibilities

  • Drive incident response engagements to guide customers through forensic investigations, contain security incidents, and provide remediation recommendations.
  • Coordinate and guide incident response assistance from team members and vendors.
  • Investigate customer data breaches and malicious activity leveraging forensics tools; analyze Windows, Linux, and Mac OS X systems to identify Indicators of Compromise (IOCs); examine firewall, web, database, and other log sources.
  • Provide case reporting across internal and external audiences with appropriate technical detail for threat researchers and business customers.
  • Evaluate customer security programs, technologies, controls, and business environments to recommend enhancements.
  • Provide guidance on solutions to help customers navigate information security risk.
  • Track emerging security practices and contribute to building internal processes and products.
  • Stay abreast of current regulatory environments and industry trends, including Germany- and EU-relevant security and privacy expectations.
  • Support the growth of Coalition’s CIR presence in Germany as an early in-country team member, building trusted relationships with local customers and partners.

Skills and Qualifications

  • Fluency in German and English (Minimum C1 level).
  • Bachelor’s Degree in Computer Science, Information Security, Engineering, or relevant field.
  • 5+ years of incident response or digital forensics (DFIR) experience.
  • Practiced knowledge of network threats, attacks, vectors, exploitation methods, and TTPs.
  • Knowledge of TCP/IP Protocols, network assessment, log analysis, and traffic capture assessment.
  • Experience with tools such as Velociraptor, Axiom, FTK, SIFT, Volatility, ELK, Wireshark, Plaso, or Skadi.
  • Experience with EDR platforms (e.g., CrowdStrike Falcon, Carbon Black, SentinelOne).
  • Knowledge of standard frameworks (NIST, HIPAA, PCI) and familiarity with GDPR/BSI-aligned environments in Germany and the EU.
  • Self-motivated with an entrepreneurial builder mindset and strong cross-functional collaboration skills.
  • Experience deploying tools to AWS and using cloud-based platforms for assessment.
  • Flexibility to support Central European business hours and urgent response scenarios as needed.

Bonus Points

  • Relevant certifications: GCIH, GCIA, GCFA, GCFE, ACE, EnCE, CFCE, CISSP, or similar.
  • Security policy, governance, privacy, or regulatory experience.
  • Experience securing cloud-based platforms (Microsoft Azure, AWS).
  • Hands-on experience with system hardening and offensive tools (Nmap, Nessus, Metasploit, Kali).
  • Scripting skills for security tool development.
  • SCADA/Control systems network experience.

Perks & Benefits

  • 100% public healthcare coverage
  • 30+ paid holidays
  • Annual home office stipend
  • Statutory pension contributions
  • Mental & physical health wellness programs
  • Competitive compensation and career growth opportunities

Timezone overlap

UTC+1–+2

Open to

Germany

Sign in to track applications and earn points.

More roles at Coalition

Similar remote roles