Logo for C4 Group

Incident Response Expert (m/f/d) AI-Augmented Cyber Incident Response ID27153-2

Role overview

Qualifications

  • Minimum 8 years in incident response, cyber defense operations, crisis management, digital forensics or security operations leadership
  • Hands-on experience responding to identity compromise, ransomware, cloud compromise, endpoint intrusion and lateral movement incidents
  • Strong understanding of Microsoft security stack, Azure/Entra ID response actions, EDR isolation, forensic triage and evidence preservation
  • Proven ability to coordinate cross-functional technical and management stakeholders during high-pressure situations

Responsibilities

  • Conceptual development and structured implementation of the immediate incident response workstream for 'Defending the Castle'
  • Creation of practical response playbooks and SOPs for a variety of cyber incidents
  • Definition of decision points for containment, escalation, evidence preservation, communication, and crisis coordination
  • Provision of technical consultation and recommendations to various teams

Key facts

  • Full time
  • Senior (5-10 years)
  • Incident Response Analyst
  • English

Hard skills

About the company

C4 Group logo

C4 Group

Management Consulting

Die C4 Group ist die Mutter der C4 Energy über die alle Beratungsmandate abgewickelt werden. Neben der Energiebranche sind wir außerdem in den Bereichen Finanzen (C4 Finance) und Pharma (C4 Pharma) tätig. Als interdisziplinäres Beratungshaus stehen wir für innovative Lösungen.Wir sind die Spezialisten für die agile Umsetzung digitaler Transformation und deren Herausforderungen. Kurze Wege, übergreifendes Know How, maximale Handlungsfähigkeit zeichnen uns aus. Die besten Spezialisten zu jeder Zeit an jedem Ort.ImpressumC4 Group (C4 Verwaltungsgesellschaft mbH)Inhaltlich verantwortlicher Geschäftsführer gemäß §55 Abs. 2 RStV:Harald BeckKontakt Headquarter:Kattrepelsbrücke 120095 HamburgTelefon: +49 (0)40 522 99 177-0E-Mail (Allgemein): contact-us@c4-group.comE-Mail (Bewerbungen): bewerbung@c4-energy.comRegistereintrag:Eintragung im HandelsregisterRegistergericht: Amtsgericht HamburgRegisternummer: HRB 14667USt-IdNr: DE259101878

Company details

Company typeSME
IndustryManagement Consulting
Company size11 - 50

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Incident Response Expert (m/f/d) AI-Augmented Cyber Incident Response ID27153-2

Duration: 21.09.2026 – 31.03.2027

Volumen: 40h/week

Location: remote

Please submit your profiles in English!

Project description: “Defending the Castle” is the short-term and immediate phase of our Customers AI threat resilience response. The purpose is to buy time by increasing detection, response, containment and recovery readiness while a broader Phase 2 plan is prepared for the rest of the Business IT units. 

Task description:

-   Conceptual development and structured implementation of the immediate incident response workstream for “Defending the Castle”, focused on AI-augmented attacks that may progress at machine speed.

-   Creation of practical response playbooks and SOPs for identity compromise, cloud control-plane abuse, endpoint intrusion, lateral movement, ransomware-style disruption and data-impact scenarios.

-   Definition of decision points for containment, escalation, evidence preservation, communication, legal/regulatory handover and crisis coordination.

-   Provision of technical consultation and recommendations to SOC, threat intelligence, security monitoring, infrastructure, application, Azure, on-premise and resilience teams.

-   Establishment and technical definition of a repeatable operating model for response readiness, evidence collection, handover and post-incident improvement before end of Q1 2027.

-   Provision of technical consultation to enable fast, consistent and controlled response to AI-assisted cyber incidents across hybrid Azure and on-premise landscapes.

-   Predefinition and documentation of roles, triggers, containment options, and communication paths to optimize incident response workflows

-   Development of guidelines to facilitate responder action when critical thresholds are reached.

-   Conversion of lessons from exercises and response reviews into improved playbooks, SOPs and control requirements. 

Quality

-    Technical preparation of scenario walkthroughs for validation by SOC, Cyber Defense,   

legal/compliance, cloud, infrastructure and resilience stakeholders.

-   Assessment of exercise results against time-to-triage, time-to-contain, decision latency and handover quality.

-   Usability testing of playbooks by responders who did not author them.

-   Creation of a Management-ready dashboard for readiness gaps, residual risks and agreed next actions.

-   Identification and technical gap analysis of existing processes (too slow, fragmented, undocumented or dependent on informal knowledge) to document optimization potential.

-   Transformation of risk discussion Transformation of risk evaluations into executable playbooks, technical control frameworks, test protocols, backlog items and management evidence.

-   Provision of a structured handover of a Phase 2 backlog and recommendations for the broader Business IT resilience plan after Q1 2027.

-   Creation of comprehensive documentation with all results regarding the above-mentioned tasks with subsequent handover to our customer for review and approval for further usage.

Skills

Please submit profiles in english for the Incident Response Expert.

• Minimum 8 years in incident response, cyber defense operations, crisis management, digital forensics or security operations leadership.

• Hands-on experience responding to identity compromise, ransomware, cloud compromise, endpoint intrusion and lateral movement incidents.

• Strong understanding of Microsoft security stack, Azure/Entra ID response actions, EDR isolation, forensic triage and evidence preservation.

• Proven ability to coordinate cross-functional technical and management stakeholders during high-pressure situations.

• Relevant certifications such as GCIH, GCFA, GNFA, CISSP, CISM, SC-200, AZ-500 or equivalent are beneficial.



Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Incident Response Analyst Related jobs

Other jobs at C4 Group

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.