Incident Responder

Baobab Risk Solutions
Berlin, Germany
2 days ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Shift work
Languages
English, German
Job source

Tech stack

Microsoft Windows Active Directory Backup Devices Information Extraction Log Analysis Security Information and Event Management Virtualization Technology Forensic Toolkit Break Fix Cybercrime Splunk

Job description

  • Execute containment and forensic investigation of ransomware, business email compromise and other incidents: preserve evidence, analyse host and identity logs, and develop findings with specialist guidance.
  • Support systems restoration after cyber incidents: assess backups, rebuild servers and endpoints, resolve dependencies and validate services before returning them to use.
  • Work with client IT teams and managed service providers across Windows, Active Directory, Microsoft 365, virtualisation and backup environments.
  • Document technical work and communicate progress, uncertainties and blockers, escalating risks to the lead.
  • Put cutting-edge AI tools to work in investigations, recovery and automation. Experiment with new approaches, validate results and help shape how the team adopts them, while protecting incident data.
  • Improve recovery checklists, scripts and playbooks by sharing lessons from casework.

Requirements

  • Professional working proficiency in German and English for client discussions, written updates and coordination with international response partners.
  • 2+ years of hands-on experience in IT support, systems administration, recovery or incident response.
  • Experience using SIEM, EDR and forensic tools, such as Windows Defender for Business, Splunk, CrowdStrike, Velociraptor, X-Ways, KAPE, Hayabusa, SOF-ELK or OpenRelik. (These are examples; experience with comparable tools is equally relevant.)
  • Basic experience documenting technical work in tickets, change logs or recovery notes.
  • Practical experience using AI tools for technical tasks, such as information extraction, log analysis or agentic workflows.
  • Openness to coaching and feedback, and motivation to develop your security and investigation skills.

Languages

  • German - business fluent
  • English - business fluent

Requirements that give you an edge

  • Strong practical restoration experience, ideally with SMEs or small IT teams.
  • Hands-on troubleshooting and backup or restore knowledge, with willingness to learn unfamiliar technologies.
  • Familiarity with threat hunting and using threat intelligence to guide investigations, prioritize suspicious activity and assess indicators of compromise.

Benefits & conditions

  • Flexible work options - work from home for up to two days a week and join us in our office in Berlin for the remaining two days
  • 28 Vacation Days - plus Christmas Eve & New Year’s Eve
  • Competitive Compensation - Attractive salary & equity options
  • Financial Support - subsidized Germany ticket and Wellpass membership, company pension support and corporate benefit access
  • Continuous Learning - Support for your professional growth and development, both internally and through access to the Udemy Business platform
  • Team & Social Events - Regular team events to get the entire team together from across Germany
  • Challenging & Supportive Culture - Work with motivated colleagues in an environment where you can grow, achieve, and enjoy the journey
  • Long-Term Growth - A stable career path in a fast-growing company
  • Welcoming Team - A people-first culture where joy at work and future prospects come first

About the company

Welcome to Baobab Risk Solutions - Your Partner for the Cyber Security of Tomorrow! The digital world is growing - and with it, the threat of cyber attacks. Every successful attack not only jeopardizes businesses but also undermines trust in our connected society. At Baobab Risk Solutions, we are committed to making the digital world safer - proactively, sustainably, and with cutting-edge technology. Our mission: to protect companies from cyber threats before they arise, contributing to a more secure digital future. Shape the digital security of tomorrow with us. Join a team that doesn’t just watch but actively protects. Your ideas and commitment can make all the difference. If that’s not enough, here’s more:

  • Flexible Working: With your MacBook, you can work from home two days per week and work in our modern office in Berlin the remaining days.
  • Attractive Compensation: Competitive salary and VSOP options.
  • Growth & Career: Grow with us - in a dynamic company with clear advancement opportunities.
  • and many more benefits.

Baobab Risk Solutions - Growing together. Making the digital world safer, together.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

56 sec

Taking the leap into desktop and mobile applications

Brian Morrison · Coffee With Developers

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all