Cybersecurity Incident Response & Digital Forensics Manager

Job type:Permanent
Town/City:Hamburg
Region:Hamburg
Sector:Cyber Security
Client Company Type:In-House
Job ref:10144
Post Date:July 23, 2026

About the Role

Cybersecurity Incident Response & Digital Forensics Manager

The Opportunity

If you're done picking up other people's alerts and want to run full investigations from start to finish, this is worth ten minutes of your evening.

You'd join a lean global incident response team as the European anchor, working for a globally recognised medical technology business with a security function that's already mature and properly resourced. The team is in a genuine build phase, with three positions open globally right now.

The Role

L1 and L2 triage sits with an external MSP, so your work starts where theirs stops. You'll lead end-to-end investigations across business email compromise, network intrusion, ransomware, and data breach scenarios, going well beyond what the tooling tells you.

  • Lead full investigations from initial triage handoff through to root cause and closure
  • Build timelines, connect indicators, and think like an investigator rather than a ticket-closer
  • Cover global incidents independently when your APAC and US colleagues are offline
  • Technically direct the external MSP during live incidents
  • Write incident reports that land equally well with engineers and senior stakeholders
  • Help shape IR playbooks, process, and detection capability as the team grows

The Company

You'd be joining a globally recognised medical technology organisation with a well-established, well-funded security function: the kind of setup where IR is treated as a serious discipline, not an afterthought. The global team is small by design, four people, high trust, everyone covers for everyone else. Growth here means investment, not stretch.

What You'll Need

  • A genuine IR or DFIR background, not a SOC analyst profile
  • Hands-on experience investigating BEC, network intrusion, and ransomware incidents
  • Proficiency with Microsoft Defender EDR
  • Confidence working independently and making sound calls under pressure
  • Strong communication skills, able to brief both engineers and senior stakeholders

How to Apply

Your CV doesn't need to be up to date. Send what you have, or just give us a call.

More Jobs from this Recruiter

Hamburg , Hamburg

Cybersecurity Incident Response & Digital Forensics Manager

Cybersecurity Incident Response & Digital Forensics Manager The Opportunity If you're done picking up other people's alerts and want to run full investigations from start to finish, this is worth ten minutes of your evening. You'd join a lean global incident response team as the European anchor, working for a globally recognised medical technology business with a security function that's already mature and properly resourced. The team is in a genuine build phase, with three positions open globally right now. The Role L1 and L2 triage sits with an external MSP, so your work starts where theirs stops. You'll lead end-to-end investigations across business email compromise, network intrusion, ransomware, and data breach scenarios, going well beyond what the tooling tells you. Lead full investigations from initial triage handoff through to root cause and closure Build timelines, connect indicators, and think like an investigator rather than a ticket-closer Cover global incidents independently when your APAC and US colleagues are offline Technically direct the external MSP during live incidents Write incident reports that land equally well with engineers and senior stakeholders Help shape IR playbooks, process, and detection capability as the team grows The Company You'd be joining a globally recognised medical technology organisation with a well-established, well-funded security function: the kind of setup where IR is treated as a serious discipline, not an afterthought. The global team is small by design, four people, high trust, everyone covers for everyone else. Growth here means investment, not stretch. What You'll Need A genuine IR or DFIR background, not a SOC analyst profile Hands-on experience investigating BEC, network intrusion, and ransomware incidents Proficiency with Microsoft Defender EDR Confidence working independently and making sound calls under pressure Strong communication skills, able to brief both engineers and senior stakeholders How to Apply Your CV doesn't need to be up to date. Send what you have, or just give us a call.
Learn More
Munich, Bayern

IT Security Expert - Incident Response

IT Security Expert: Incident Response The Opportunity Tired of firefighting alerts with no say in the strategy behind them? This role gives you ownership of a Data Loss Prevention programme from the ground up, not just a seat monitoring someone else's. The Role You'll take the lead on building out DLP across the business: identifying sensitive data with stakeholders, selecting protective measures, then installing, configuring and integrating the DLP solution into the infrastructure yourself. Beyond that, you'll manage and tune SIEM and DLP rule sets, sharpen detection as new threats emerge, and run regular audits to prove the programme's working. You'll also help build a security-first culture through training and clear guidance, and take on other security projects as they come up. The Company Our client is a well-established, regulated financial services organisation investing seriously in its security maturity. This is a newly-focused mandate rather than a legacy function you're inheriting, so you'll have real scope to shape how DLP is done here, not just follow an existing playbook. What You'll Need Practical experience in IT security, including penetration testing and incident response Solid working knowledge of Windows, Linux and networks Fluent German and English How to Apply Your CV doesn't need to be up to date. Send what you have, or give the MAM Gruppe team a call for a confidential chat about the role. Reach out to richard@mamgruppe.com.
Learn More
Mannheim, Baden-Württemberg

SOC Lead

SOC Lead Ready to Build Something That Doesn't Exist Yet? Most SOC roles ask you to maintain. This one asks you to create. A global industrial technology business, over 175 years old and still innovating, has made cyber security a boardroom priority. They're building their CDC from the ground up, and they need a Lead who can architect the entire function: strategy, processes, automation, tooling, and a team of analysts to back it up. This is a rare opportunity to put your name on something. No inherited processes. No legacy decisions to unpick. Just a clear mandate, executive backing, and the freedom to do it right. What You'll Be Doing You'll take end-to-end ownership of the CDC — defining how it operates, how it scales, and how it matures. Day to day, that means: Designing and owning all CDC processes, SOPs, runbooks, and playbooks — building from scratch, not from a template Leading an automation-first approach: implementing and continuously improving SOAR capabilities to cut manual workload and sharpen response times Developing the CDC roadmap with a clear eye on regulatory requirements including NIS2 and ISO 27001 Acting as incident manager for critical events — staying strategic, not getting pulled into the weeds Integrating OT security requirements into centralised monitoring alongside IT environments Selecting, optimising, and managing the security technology stack — SIEM, SOAR, XDR Leading, mentoring, and developing a team of 3–5 security analysts Reporting CDC performance to senior leadership through meaningful KPIs (MTTD, MTTR) The Company You'll be joining a global industrial technology business with a 175-year track record of innovation. The organisation operates across IT and OT environments at scale — which means the security challenges here are genuinely complex, and the investment behind this function is real. Cyber security has moved firmly onto the executive agenda. You'll have the organisational weight behind you to build this properly. What You'll Need Solid experience in a SOC, CDC, or Information Security leadership environment A process-first mindset — you think in workflows, not just incidents Hands-on experience with SOAR platforms and an instinct for automation Familiarity with SIEM and XDR tooling Working knowledge of relevant frameworks and standards — NIST, SANS, ISO/IEC 27001, NIS2 Experience leading and developing security analysts Business-level German and strong English — you'll need both Comfortable with on-call responsibilities and major incident availability How to Apply You can apply directly through this page, or reach out to the consultant listed in this advert if you'd prefer a conversation first. Your CV doesn't need to be polished or up to date — send what you have. If this sounds like the right move, we'd rather hear from you early than not at all.
Learn More
Munich, Bayern

Security Analyst

Security Analyst Location: Munich Our client is seeking a Security Analyst to support security testing and research activities across embedded and hardware-focused technology environments. This role focuses on vulnerability analysis, embedded software security and the evaluation of advanced security concepts within modern product ecosystems. Key Responsibilities: Perform security assessments and vulnerability analysis for embedded systems and connected devices. Support hardware and software-focused security testing activities. Contribute to security reviews, technical evaluations and risk assessments. Assist with the development of security testing methods and analysis techniques. Collaborate with international engineering and research teams on security-related initiatives. Support internal knowledge sharing and technical consulting activities. Evaluate emerging technologies and approaches related to embedded and product security. Your Profile: Degree in Computer Science, Engineering or a related technical field. Experience within embedded systems, security testing or security research environments. Understanding of embedded software, hardware security or cryptographic concepts. Familiarity with vulnerability analysis and security assessment methodologies. Experience with programming languages such as C, Java or low-level technologies would be advantageous. Strong analytical and troubleshooting skills. Collaborative and solution-oriented working style. Fluent German and English language skills. What’s on Offer? Opportunity to work on advanced security and embedded technology topics. International and collaborative working environment. Flexible hybrid working model. Long-term technical development opportunities.
Learn More

Latest Blogs

View all blogs