> Markdown version of [/jobs/ext/3380851-manager-incident-response](https://www.wearedevelopers.com/jobs/ext/3380851-manager-incident-response). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Manager Incident Response - **Company:** Eye Security - **Location:** Berlin, Germany - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Cyber Security, Digital Forensics, Scripting - **Published:** September 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d8dae5a5c23e210c ## About the Role * Technical: 6+ years of hands-on incident response / digital forensics experience - the same bar as Staff Incident Response Analyst - with deep, current knowledge of DFIR methodology, EDR platforms, cloud security, and attacker TTPs; able to personally run a complex case, not just sign off on one * Leadership: composure and sound judgement under real pressure, often with incomplete information, during live incidents; strong incident-report writing and a sharp eye for reviewing others' reports; clear, calm, authoritative communication with clients and internal stakeholders during a crisis * People management: proven experience leading or supervising a technical team through high-pressure, time-critical work, with a genuine interest in coaching people and helping them grow; first-line management experience or a strong informal leadership track record * Fluent English; Dutch required for client-facing work Nice-to-have * Background in a CERT, CSIRT, MDR, or DFIR-focused environment * Experience handling cases with legal or regulatory exposure * Scripting/automation experience applied to investigation workflows * Familiarity with compliance frameworks relevant to SMEs (NIS2, ISO 27001, GDPR) ## Description We are looking for a Team Lead Incident Response to join our Security Operations department. You will lead the people who own our most serious cases end to end - coordinating ransomware and business email compromise investigations, doing the forensic work, and being the person on the phone when a client needs a straight answer under real pressure. Your first responsibility is people, not just process. You're a first-line manager distinct from a senior individual contributor, with direct accountability for the performance and development of your team - while carrying enough hands-on DFIR credibility to run the most complex case yourself, or take over one mid-flight, when the situation demands it. What you will do * Lead, coach, and develop the Incident Response team: regular one-to-ones, feedback, and performance/development conversations aligned with Eye's career framework * Lead by doing: manage the caseload and the people, but personally take point on the most complex or highest-profile incidents when needed * Own end-to-end incident response service quality: case intake and coordination, technical execution, client communication, and closure/reporting * Own delivery KPIs (time-to-containment, case-report quality and timeliness, client satisfaction on incident cases) and step in to unblock the team or personally lead a case when targets are at risk * Manage on-call and case-lead rostering and workload across the team, prioritising by severity and client exposure * Act as the senior escalation point and, when needed, incident commander for major incidents - large ransomware, multi-entity BEC, or cases with legal/regulatory exposure * Own quality assurance for incident reporting: set the reporting standard and run structured peer review of case reports before they reach the client * Own and scale automation across the function's casework (evidence collection, timeline building, reporting), partnering with engineering where it makes sense * Drive continuous improvement of IR playbooks, tooling, and process as case volume grows; keep runbooks and SOPs accurate and actually used * Represent Incident Response in cross-functional discussions with SOC, Prevention, Product, Customer Success, and Legal where relevant ## Related Videos - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [AI Space Factories, Hacking Self-Driving Cars & Detecting Deepfakes](https://www.wearedevelopers.com/videos/1812-ai-space-factories-hacking-self-driving-cars-detecting-deepfakes) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Finding IT & Technology English-speaking Jobs in Germany ](https://www.wearedevelopers.com/magazine/446-finding-it-technology-english-speaking-jobs-in-germany) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [The Geometry of Incidents: Connecting User Impact to Architecture](https://www.wearedevelopers.com/magazine/764-the-geometry-of-incidents-connecting-user-impact-to-architecture) - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany) - [Finding Jobs in Germany](https://www.wearedevelopers.com/magazine/375-finding-jobs-in-germany) - [The Biggest German Tech Companies](https://www.wearedevelopers.com/magazine/424-the-biggest-german-tech-companies)