Left arrow iconBack to search

Incident Response Expert (m/f/d) AI-Augmented Cyber Incident Response ID27153-2

C4 Energy GmbH & Co. KG
Posted 20 days ago, valid for 9 days
Location

Düsseldorf, Düsseldorf District, North Rhine-Westphalia

Salary

Competitive

Contract type

Contract

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • The job position is for an Incident Response Expert (m/f/d) with a focus on AI-Augmented Cyber Incident Response, lasting from September 21, 2026, to March 31, 2027.
  • The role requires a minimum of 8 years of experience in incident response, cyber defense operations, or related fields, along with hands-on experience in various incident types such as ransomware and identity compromise.
  • Key responsibilities include developing incident response strategies, creating response playbooks, and providing technical consultation to various teams.
  • Candidates should possess a strong understanding of the Microsoft security stack and relevant certifications, which are beneficial for this role.
  • The position offers a remote work opportunity with a workload of 40 hours per week, and the salary details are not specified in the job listing.

Incident Response Expert (m/f/d) AI-AugmentedCyber Incident Response ID27153-2

 

Duration: 21.09.2026 – 31.03.2027

Volumen: 40h/week

Location: remote

 

Please submit your profiles inEnglish!

 

Project description: “Defending theCastle” is the short-term and immediate phase of our Customers AI threatresilience response. The purpose is to buy time by increasing detection,response, containment and recovery readiness while a broader Phase 2 plan isprepared for the rest of the Business IT units. 

Task description:

-   Conceptual development and structured implementation of the immediateincident response workstream for “Defending the Castle”, focused onAI-augmented attacks that may progress at machine speed.

-   Creation of practical response playbooks and SOPs for identitycompromise, cloud control-plane abuse, endpoint intrusion, lateral movement,ransomware-style disruption and data-impact scenarios.

-   Definition of decision points for containment, escalation, evidencepreservation, communication, legal/regulatory handover and crisis coordination.

-   Provision of technical consultation and recommendations to SOC, threatintelligence, security monitoring, infrastructure, application, Azure,on-premise and resilience teams.

-   Establishment and technical definition of a repeatable operating modelfor response readiness, evidence collection, handover and post-incidentimprovement before end of Q1 2027.

-   Provision of technical consultation to enable fast, consistent andcontrolled response to AI-assisted cyber incidents across hybrid Azure andon-premise landscapes.

-   Predefinition and documentation of roles, triggers, containment options,and communication paths to optimize incident response workflows

-   Development of guidelines to facilitate responder action when criticalthresholds are reached.

-   Conversion of lessons from exercises and response reviews into improvedplaybooks, SOPs and control requirements. 

Quality

-    Technical preparation of scenario walkthroughs for validation by SOC,Cyber Defense,   

legal/compliance, cloud,infrastructure and resilience stakeholders.

-   Assessment of exercise results against time-to-triage, time-to-contain,decision latency and handover quality.

-   Usability testing of playbooks by responders who did not author them.

-   Creation of a Management-ready dashboard for readiness gaps, residualrisks and agreed next actions.

-   Identification and technical gap analysis of existing processes (tooslow, fragmented, undocumented or dependent on informal knowledge) to documentoptimization potential.

-   Transformation of risk discussion Transformation of risk evaluationsinto executable playbooks, technical control frameworks, test protocols,backlog items and management evidence.

-   Provision of a structured handover of a Phase 2 backlog andrecommendations for the broader Business IT resilience plan after Q1 2027.

-   Creation of comprehensive documentation with all results regarding theabove-mentioned tasks with subsequent handover to our customer for review andapproval for further usage.

 

Skills

Pleasesubmit profiles in english for the Incident Response Expert.

•Minimum 8 years in incident response, cyber defense operations, crisismanagement, digital forensics or security operations leadership.

•Hands-on experience responding to identity compromise, ransomware, cloudcompromise, endpoint intrusion and lateral movement incidents.

•Strong understanding of Microsoft security stack, Azure/Entra ID responseactions, EDR isolation, forensic triage and evidence preservation.

•Proven ability to coordinate cross-functional technical and managementstakeholders during high-pressure situations.

•Relevant certifications such as GCIH, GCFA, GNFA, CISSP, CISM, SC-200, AZ-500or equivalent are beneficial.






Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.