Job Drop BerlinYOUR WAY INTO BERLIN TECH
Theme
NewsletterLinkedIn
AboutTermsImpressumPrivacy
Browse jobs
Engineering jobs in BerlinProduct jobs in BerlinDesign jobs in BerlinMarketing jobs in BerlinSales jobs in BerlinData jobs in BerlinOperations jobs in BerlinFinance jobs in BerlinCustomer success jobs in BerlinPeople & HR jobs in BerlinEnglish-speaking jobs in BerlinRemote jobs at Berlin startupsStartup internships in BerlinEnglish-speaking working student jobs in BerlinEnglish-speaking junior jobs in BerlinEnglish-speaking fintech jobs in BerlinEnglish-speaking ai & machine learning jobs in BerlinEnglish-speaking senior jobs in Berlin
← HOME

Incident Responder - German speaking

BBaobab Insurance
NEW
Seniority
Midweight
Model
Hybrid
Sector
Fintech
Salary
Undisclosed
Contract
Full-Time

Execute containment and forensic investigation of ransomware, business email compromise and other incidents: preserve evidence, analyse host and identity logs, and develop findings with specialist guidance. Support systems restoration after cyber incidents and work with client IT teams across Windows, Active Directory, Microsoft 365, virtualisation and backup environments.

What you'll do

  • Execute containment and forensic investigation of ransomware, business email compromise and other incidents: preserve evidence, analyse host and identity logs, and develop findings with specialist guidance.
  • Support systems restoration after cyber incidents: assess backups, rebuild servers and endpoints, resolve dependencies and validate services before returning them to use.
  • Work with client IT teams and managed service providers across Windows, Active Directory, Microsoft 365, virtualisation and backup environments.
  • Document technical work and communicate progress, uncertainties and blockers, escalating risks to the lead.
  • Put cutting-edge AI tools to work in investigations, recovery and automation. Experiment with new approaches, validate results and help shape how the team adopts them, while protecting incident data.
  • Improve recovery checklists, scripts and playbooks by sharing lessons from casework.

What you'll need

  • Professional working proficiency in German and English for client discussions, written updates and coordination with international response partners.
  • 2+ years of hands-on experience in IT support, systems administration, recovery or incident response.
  • Experience using SIEM, EDR and forensic tools, such as Windows Defender for Business, Splunk, CrowdStrike, Velociraptor, X-Ways, KAPE, Hayabusa, SOF-ELK or OpenRelik.
  • Basic experience documenting technical work in tickets, change logs or recovery notes.
  • Practical experience using AI tools for technical tasks, such as information extraction, log analysis or agentic workflows.
  • Openness to coaching and feedback, and motivation to develop your security and investigation skills.

Nice to have

  • Strong practical restoration experience, ideally with SMEs or small IT teams.
  • Hands-on troubleshooting and backup or restore knowledge, with willingness to learn unfamiliar technologies.
  • Familiarity with threat hunting and using threat intelligence to guide investigations, prioritize suspicious activity and assess indicators of compromise.

What they offer

  • Flexible work: up to two days per week from home, remaining days in Berlin office
  • 28 vacation days plus Christmas Eve and New Year's Eve
  • Competitive salary and VSOP equity options
  • Subsidized Germany ticket, Wellpass membership, company pension support and corporate benefits
  • Professional development support and Udemy Business access
  • Regular team events across Germany

ABOUT BAOBAB INSURANCE

Fintech · Series A stage

25+ employees

2 more open roles at Baobab Insurance →

SIMILAR OPEN ROLES

More roles like this, every Thursday →

No spam. Unsubscribe anytime.