Senior Incident Response & Digital Forensics Consultant (m/w/d)

NVISO
Frankfurt am Main

Who are we?

It all starts with the mission: NVISO is here to protect European society from potentially devastating cyber attacks! This means we offer cyber security services to private and governmental organizations to help them better prepare for, prevent, detect and respond to cyber security incidents.

All of this is built on four fundamental values that define who we are: We are Proud, We Break Barriers, We Care and No BS!

Tasks

As our Senior Incident Response Consultant (m/w/d) , you will support the NVISO incident response team (CSIRT) in responding to a wide range of cyber incidents. In addition to incident response and forensic engagements, you will work closely with the rest of the team to build & automate incident response processes, analytical capabilities, including threat hunting. You act as Incident Lead by setting investigative questions, delegating technical analysis tasks, and steer containment and eradication strategies. You produce high-quality forensic and executive reports to present findings to technical stakeholders and executives. You occasionally peer-review case notes, artifacts, and draft reports.

Your responsibilities

  • Perform host forensics (Magnet AXIOM Cyber, X-Ways, Autopsy), network forensics (Wireshark, tshark), memory forensics (Volatility, MemProcFS), and log analysis , including cloud telemetry (Microsoft 365/Azure, AWS, Google Cloud/Workspace), in support of cyber incident investigations.
  • Lead single-system forensic analysis and contribute meaningfully to complex intrusions, including those with lateral movement, perform timeline analysis of compromised hosts and conduct live response artifact capture, volatile data collection, containment to support eradication and recovery efforts.
  • Perform basic malware triage of executables and malicious scripts (static and behavioral) to inform containment and eradication strategies.
  • Lead customer calls during incidents and contribute to cyber crisis management, and deliver status reports, planning for containment, eradication and recovery efforts, and input to executive-ready communications.
  • Support improvement projects related to automation in digital forensics and further develop NVISO tools and incident response processes.
  • Perform threat hunting engagements within customer environments, including technical planning, requirements definition, execution, and reporting.
  • Assist in other engagements such as tabletop exercises, incident and forensic readiness assessments, and threat-intelligence-related briefings.

Requirements

  • You hold citizenship in one of the 32 NATO member states.
  • 4+ years of hands-on experience, including acting as an incident response case lead.
  • Strong knowledge of cyber intrusion analysis, incident response, digital forensics on Windows/MacOS/Unix, with demonstrated expertise in memory forensics (Volatility, MemProcFS), timeline analysis (e.g., MFTECmd, KAPE, Plaso/Timesketch), and disk forensics (Magnet AXIOM Cyber, X-Ways, Autopsy).
  • Proficiency with live response tooling (e.g., Velociraptor, GRR Rapid Response, EDR live response) and coordinating remediation actions.
  • Up-to-date on the latest cybersecurity threats and attacker TTPs.
  • Excellent analytical and problem-solving skills with an eye for detail in documentation.
  • Effective communication and interpersonal skills to work collaboratively with clients and cross-functional teams.
  • Ability to remain calm during crisis situations and prioritize effectively under pressure.
  • Language: German and English at C1+ proficiency for client-facing work across DACH.

Your availability

  • We have an On-call rotation, typically one week per month.

Travel

  • Some limited travel within DE/AT/CH (~10–20%) for onsite response, workshops, and stakeholder meetings.

Benefits

At NVISO, we care. We are committed to offering you a highly competitive remuneration package including financial and non-financial components:

  • Working and learning from the best people in the European cyber security industry. We have multiple SANS Instructors working at NVISO, our staff has presented at popular hacking conferences (BlackHat, BruCON, OWASP, etc) and all of our technical staff can acquire deep technical security certifications (GSE, GXPN, GREM, GCFA, OSCP, etc);
  • An entrepreneurial and agile company, where you will be stimulated and supported in driving new initiatives (either through internal innovation or by improving our service offering), without losing sight of having fun!
  • Regular team-building and fun events;
  • Our commitment to coach and counsel you and help you grow; each employee receives a personal coach within the team, whose role is to ensure your well-being and helps you grow in your career!
  • A training budget of 10,000 EUR plus 10 days paid time off rolling over two years;
  • An annual gross base salary between 69,000 EUR and 87,000 EUR, depending on your experience;
  • Flexible working hours and home office possibilities (incl. working abroad options within the EU);
  • Reimbursement of Deutschlandticket + BahnCard 50 1st Class;
  • Business Bike Leasing;
  • Company Pension Scheme;
  • 30 holidays.

Disclaimer on the Use of AI Tools in the Application Process

Please be aware that the creation and submission of application documents (e.g. CV, cover letter, case studies, etc.) using AI-powered tools is only permitted to a limited extent .

Our expectations:

Application documents must authentically reflect your own qualifications, personality, and motivation.

The use of AI for supportive purposes (e.g. spell-checking, improving wording) is acceptable.

Fully generated application documents created by AI without personal adaptation or review are not permitted.

Under no circumstances may NVISO information, data, or documents be uploaded to or processed by external AI tools.

We reserve the right to exclude applications from the selection and interview process that are clearly created primarily or exclusively by AI and show no recognizable personal input.

The purpose of this policy is to ensure a fair and transparent recruitment process and to obtain an authentic impression of our applicants.

Veröffentlicht am 2026-04-21

Empfohlene Jobs

Praktikum Cyber Security & IT Risk Management (w/m/d) - Ingenieur, Risk / Compliance Management

PwC Deutschland
Frankfurt am Main

Join our Community of Solvers Für unseren Geschäftsbereich Risk & Regulatory suchen wir dich zum nächstmöglichen Zeitpunkt als Praktikant Cyber Security & IT Risk Management (w/m/d). Das erwart…

Details Anzeigen
Veröffentlicht am 2026-04-17

Elektriker in der Industriemontage mit Entwicklungsperspektive (m/w/d)

Hapeko
Frankfurt am Main

Das Unternehmen HAPEKO ist der erste Ansprechpartner für Fach- und Führungskräfte in Deutschland. Schwerpunkt der Tätigkeit ist das Schaffen von Verbindungen zwischen Spezialisten und Führungskräf…

Details Anzeigen
Veröffentlicht am 2026-04-07

Inbetriebnehmer (m/w/d) SPS-Steuerungen - IT, Qualitätsmanagement

MGA Ingenieurdienstleistungen GmbH
Frankfurt am Main

Auf diese Aufgaben dürfen Sie sich freuen: Sie führen Inbetriebnahmen von Maschinen für die Nahrungs- und Genussmittelindustrie am Endmontageort in aller Welt durch. Ihre Aufgaben reichen vom e…

Details Anzeigen
Veröffentlicht am 2026-04-05

Mitarbeiter Service Desk (m/w/d) im Finanzsektor - hybrides Arbeiten (Remote & Präsenz)

Frankfurt am Main

Sind Sie ein IT-Profi auf der Suche nach neuen, anspruchsvollen Herausforderungen? Möchten Sie mit Ihrer Arbeit einen echten Unterschied machen? Dann haben wir die perfekte Gelegenheit für Sie! U…

Details Anzeigen
Veröffentlicht am 2026-03-17

Servicekraft in Vollzeit oder Teilzeit / Aushilfe

Dicke Butz
Frankfurt am Main

Wir bei Dicke Butz sind davon überzeugt, dass Essen für die Menschen mehr bedeutet als nur Nahrung zu sich zu nehmen. Es ist Genuss, Geschmack, Lebensgefühl und Identifikation. Davon möchten wir ein …

Details Anzeigen
Veröffentlicht am 2026-04-18

Interim Tax Experte Fokus Quellensteuer (m/w/d)

Frankfurt am Main

hinzugefügt 24/03/2026 Interim Tax Experte Fokus Quellensteuer (m/w/d) Spannendes Unternehmen Firmenprofil Das Unternehmen ist im Bereich Financial Services tätig. Aufgabengebiet Sich…

Details Anzeigen
Veröffentlicht am 2026-03-24

Senior Wirtschaftsprüfung / Audit (w/m/d)

Ernst & Young
Frankfurt am Main

Are you ready to shape your future with confidence? Gemeinsam die Welt jeden Tag ein bisschen besser machen. Für diesen Anspruch setzen wir bei EY alles in Bewegung und gehen als Team „all in“. Sch…

Details Anzeigen
Veröffentlicht am 2025-09-26

Das Deutsche Bank Praktikum (d/m/w) im Bereich Strategic Transformation & CAO for C&AFC­­,­­ Team Content Management & Development im Chief Operating Office für Compliance & Anti-Financial Crime (COO C&AFC) 2026

Deutsche Bank
Frankfurt am Main

e-fellows.net Stellenmarkt Jobs & Praktika suchen Informationen zur Anzeige: Das Deutsche Bank Praktikum (d/m/w) im Bereich Strategic Transformation & CAO for C&AFC, Team Content Management & …

Details Anzeigen
Veröffentlicht am 2025-09-04

Linux Administrator (m/w/d) - hybrides Arbeiten - hybrides Arbeiten (Remote & Präsenz)

Frankfurt am Main

Linux Administrator (m/w/d) gesucht – Werden Sie ein wichtiger Teil unserer IT-Infrastruktur! Sind Sie ein erfahrener Linux-Administrator (m/w/d) mit Begeisterung für die Wartung und Optimierung ko…

Details Anzeigen
Veröffentlicht am 2026-03-26

Zentralist / Operator (m/w/d) Sicherheitsleitstelle 20€/Std.

Securitas Deutschland
Frankfurt am Main

Unternehmensbeschreibung Jeden Tag sorgen unsere über 20.000 Heldinnen und Helden des Alltags  dafür, dass sich Menschen in Deutschland sicherer fühlen. Wir bei Securitas kümmern uns um dich – we…

Details Anzeigen
Veröffentlicht am 2026-04-09