Senior Cybersecurity Incident Responder

ZEISS Group
Oberkochen, Germany
27 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Digital Forensics Cloud Platform System Mitre Att&ck Cyber Threat Analysis Cyber Warfare

Job description

In this role, you are a senior technical expert within the Cyber Defense Center and a core member of the Cybersecurity Incident Response Team (CIRT). You support the effective handling of cybersecurity incidents by contributing deep technical expertise, structured analysis, and reliable execution throughout the incident response lifecycle.

  • Acting as a permanent member of the Cybersecurity Incident Response Team (CIRT)
  • Executing and supporting technical incident response activities, including analysis, containment, and recovery
  • Escalating critical technical findings and risks to the Incident Commander
  • Supporting the Incident Commander and Incident Coordinators in the technical execution of incident response activities
  • Providing technical guidance and expertise to other IR roles
  • Collaborating closely with Digital Forensics and Threat Intelligence teams to enable in-depth technical analysis
  • Performing and reporting root cause analysis, incident status, and potential response measures
  • Supplying accurate technical input for internal communication and external reporting to authorities via the Incident Commander
  • Ensuring complete and structured documentation of all incident response activities

Requirements

  • Several years of professional experience in cybersecurity incident response, SOC, DFIR, or cyber defense environments
  • Strong technical knowledge of IT infrastructures, networks, operating systems, and cloud environments
  • Proven experience in handling complex or high-severity cybersecurity incidents
  • Solid understanding of attacker Tactics, Techniques, and Procedures (TTPs) and the ability to identify, analyze, and respond to them in real-world incidents
  • Experience mapping observed activity to frameworks such as MITRE ATT&CK and deriving response or mitigation measures
  • Sound understanding of established incident response frameworks (e.g. NIST, SANS)
  • Ability to communicate technical findings clearly and concisely to different stakeholder groups
  • Structured, reliable, and resilient working style, particularly in critical situations

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on de.indeed.com

Inside ZEISS Group

Culture, engineering, and team stories

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · WWC Europe 2026

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

2:32 min

Introduction to Zeiss and industrial manufacturing hardware

Andreas Kaldun Andreas Kaldun

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

4:27 min

Embracing a new perspective on mobile cyber attacks

Tom Tovar · WWC 2023

Videos

See all

Related articles

See all