Incident Response Lead
Job type:Permanent
Town/City:Frankfurt
Region:Hessen
Sector:Cyber Security
Client Company Type:In-House
Job ref:7579
Post Date:November 26, 2025
Meet Our Recruiter
Josh Mooney
Principal Consultant - Cyber Security
About the Role
Incident Response Lead
Location: Frankfurt
Our client is seeking an experienced and highly motivated Incident Response Lead to join their cybersecurity team. In this senior-level role, you will support the Incident Response Lead in directing, coordinating, and managing all aspects of cybersecurity incidents across the organisation. You will help shape incident response strategy, oversee complex investigations, and guide a global team of analysts and engineers to ensure rapid, effective, and consistent response to threats.
Key Responsibilities:
- Assist the Incident Response Lead in managing the full lifecycle of cyber incidents, including detection, triage, investigation, containment, eradication, and recovery.
- Act as second-in-command and escalation point for major or complex security incidents.
- Lead incident response activities during critical events, ensuring alignment with established protocols and reporting requirements.
- Coordinate cross-functional teams (Security Operations, Engineering, Legal, Compliance, Communications, etc.) to ensure effective and timely incident handling.
- Oversee incident documentation, root-cause analysis, and preparation of post-incident reports for senior leadership.
- Develop and refine incident response processes, playbooks, and standard operating procedures to enhance organizational readiness.
- Provide mentorship and technical guidance to incident responders, analysts, and other cybersecurity team members.
- Perform proactive threat hunting, adversary analysis, and forensic investigations to identify security weaknesses.
- Monitor evolving threat landscapes and support the implementation of tools, techniques, automation, and technologies that strengthen incident response capabilities.
- Contribute to regulatory, audit, and compliance efforts related to cybersecurity and incident reporting requirements in the EU and Germany.
- Support training and tabletop exercises to maintain high readiness and maturity across the incident response program.
Qualifications:
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field (or equivalent professional experience).
- 6+ years of experience in cybersecurity, with at least 3 years in incident response, digital forensics, or threat detection.
- Strong understanding of security operations, SIEM tools, EDR/XDR platforms, and forensic methodologies.
- Experience coordinating technical teams during complex or high-severity incidents.
- Excellent analytical and problem-solving skills, with the ability to remain calm and decisive under pressure.
- Knowledge of industry frameworks (e.g., NIST, MITRE ATT&CK, ISO 27035).
- Fluent in English; working proficiency in German preferred.
- Professional certifications such as GCIH, GCIA, GCFA, CISM, CISSP, or similar.
- Experience working in regulated industries (e.g., finance, critical infrastructure).
- Familiarity with cloud environments (AWS, Azure, GCP) and hybrid architectures.
What We Offer:
- Competitive compensation and benefits package.
- Career growth opportunities within a global cybersecurity organization.
- A dynamic, collaborative environment with cutting-edge security technologies.
- Hybrid working options and modern office space in central Frankfurt.