> Markdown version of [/jobs/ext/392937-senior-security-incident-responder](https://www.wearedevelopers.com/jobs/ext/392937-senior-security-incident-responder). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Incident Responder - **Company:** Allianz SE - **Location:** München, Germany (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Data Analysis, Business Software, CompTIA Security+, Cyber Security, Continuous Integration, Linux, DevOps, Python (Programming Language), Windows PowerShell, Shell Script, Software Engineering, Systems Architecture, Software Vulnerability Management, Scripting, Malware, Cyber Threat Analysis, Information Technology, Web Technologies, Cyber Warfare, Golang - **Published:** June 18, 2026 - **Apply:** https://de.indeed.com/viewjob?jk=728a4dc553605d54 ## About the Role Do you have experience in Shell Scripting?, Do you have a Master's degree?, * University degree (Master's preferred) in Computer Science, Cyber Security, or a related field. * Extensive work experience in Incident Response, including managing complex environments; expertise in IT Forensics, Malware Analysis, or Vulnerability Management is a plus. * Comprehensive technical expertise in system architecture with broad proficiency in key IT security technologies: Linux and Windows, Active Directory / Entra ID, web technologies, email, networking, cryptography, and widely used DevOps tools. * Software engineering and scripting skills: Python, Golang, Shell scripting, PowerShell, CI/CD, and database management. * Strong understanding of technical and organisational aspects of information security, demonstrated through prior defensive or offensive work experience. * In-depth knowledge of fundamental attack concepts: terminology, tools, tactics, techniques, and procedures (TTPs). * Exceptional analytical and problem-solving mindset with the ability to collect, structure, analyse, and communicate large amounts of information with precision and attention to detail. * Excellent communication and interpersonal skills in English (fluent, written and spoken, including security terminology); willingness to participate in on-call shifts. Relevant certifications (e.g. SANS/GIAC, GCIH, GNFA, GCFA, GREM, GCFE, GIME), CompTIA Security+, CISSP, CISA, or CISM) are a plus but not mandatory. ## Description The Incident Response cluster within the Allianz Cyber Defense Center (ACDC) is a team of dedicated Incident Responders with the mission to limit the impact of security incidents on Allianz's global infrastructure. We coordinate the response to cybersecurity incidents, conduct investigations across the Allianz Group, and are actively involved in strategic security projects. As a Senior Security Incident Responder, you play a key role in this team: you lead complex incident response activities, bring deep technical expertise, and make a significant contribution to continuously improving our security posture and internal capabilities. What you do: * Coordinate and own security incident response activities in a heterogeneous, multi-cultural, and geographically distributed environment - engaging all relevant technical and non-technical stakeholders across all phases of an incident. * Acquire and analyze data from various sources during incident response activities and report on findings in a clear, actionable manner. * Conduct incident reviews, identify improvement potentials, and support the implementation of improvements - including updating guidelines, runbooks, and internal processes. * Actively contribute to enhancing ACDC's internal toolset through new ideas on functionality and features, as well as by developing automation scripts and custom tooling. * Analyse complex attack patterns and threat actors, derive technical insights, and provide recommendations to improve Allianz's detection and defence capabilities. * Collaborate closely with internal teams - including Threat Intelligence, Vulnerability Management, and Business Applications Teams - as well as external partners to ensure holistic and coordinated incident response. * Participate in on-call shifts and contribute to the ACDC team's 24/7 availability, ensuring rapid response to critical security incidents at any time. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [Finding IT & Technology English-speaking Jobs in Germany ](https://www.wearedevelopers.com/magazine/446-finding-it-technology-english-speaking-jobs-in-germany) - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany) - [Finding Jobs in Germany](https://www.wearedevelopers.com/magazine/375-finding-jobs-in-germany) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Data Analyst Salary Germany](https://www.wearedevelopers.com/magazine/277-data-analyst-salary-germany) - [Jobs in Germany for Americans](https://www.wearedevelopers.com/magazine/423-jobs-in-germany-for-americans)