Please mention DailyRemote when applying
Match your resume skills with our AI powered skill match!
The expert will develop and implement an AI-augmented incident response workstream to enhance threat resilience and containment capabilities. They will also create practical response playbooks and provide technical consultation to various security and infrastructure teams.
Incident Response Expert (m/f/d) AI-Augmented
Cyber Incident Response ID27153-2
Duration: 21.09.2026 – 31.03.2027
Volumen: 40h/week
Location: remote
Please submit your profiles in
English!
Project description: “Defending the
Castle” is the short-term and immediate phase of our Customers AI threat
resilience response. The purpose is to buy time by increasing detection,
response, containment and recovery readiness while a broader Phase 2 plan is
prepared for the rest of the Business IT units.
Task description:
- Conceptual development and structured implementation of the immediate
incident response workstream for “Defending the Castle”, focused on
AI-augmented attacks that may progress at machine speed.
- Creation of practical response playbooks and SOPs for identity
compromise, cloud control-plane abuse, endpoint intrusion, lateral movement,
ransomware-style disruption and data-impact scenarios.
- Definition of decision points for containment, escalation, evidence
preservation, communication, legal/regulatory handover and crisis coordination.
- Provision of technical consultation and recommendations to SOC, threat
intelligence, security monitoring, infrastructure, application, Azure,
on-premise and resilience teams.
- Establishment and technical definition of a repeatable operating model
for response readiness, evidence collection, handover and post-incident
improvement before end of Q1 2027.
- Provision of technical consultation to enable fast, consistent and
controlled response to AI-assisted cyber incidents across hybrid Azure and
on-premise landscapes.
- Predefinition and documentation of roles, triggers, containment options,
and communication paths to optimize incident response workflows
- Development of guidelines to facilitate responder action when critical
thresholds are reached.
- Conversion of lessons from exercises and response reviews into improved
playbooks, SOPs and control requirements.
Quality
- Technical preparation of scenario walkthroughs for validation by SOC,
Cyber Defense,
legal/compliance, cloud,
infrastructure and resilience stakeholders.
- Assessment of exercise results against time-to-triage, time-to-contain,
decision latency and handover quality.
- Usability testing of playbooks by responders who did not author them.
- Creation of a Management-ready dashboard for readiness gaps, residual
risks and agreed next actions.
- Identification and technical gap analysis of existing processes (too
slow, fragmented, undocumented or dependent on informal knowledge) to document
optimization potential.
- Transformation of risk discussion Transformation of risk evaluations
into executable playbooks, technical control frameworks, test protocols,
backlog items and management evidence.
- Provision of a structured handover of a Phase 2 backlog and
recommendations for the broader Business IT resilience plan after Q1 2027.
- Creation of comprehensive documentation with all results regarding the
above-mentioned tasks with subsequent handover to our customer for review and
approval for further usage.
Skills
Please
submit profiles in english for the Incident Response Expert.
•
Minimum 8 years in incident response, cyber defense operations, crisis
management, digital forensics or security operations leadership.
•
Hands-on experience responding to identity compromise, ransomware, cloud
compromise, endpoint intrusion and lateral movement incidents.
•
Strong understanding of Microsoft security stack, Azure/Entra ID response
actions, EDR isolation, forensic triage and evidence preservation.
•
Proven ability to coordinate cross-functional technical and management
stakeholders during high-pressure situations.
•
Relevant certifications such as GCIH, GCFA, GNFA, CISSP, CISM, SC-200, AZ-500
or equivalent are beneficial.
Stop the endless job search. Our AI finds and applies to the best jobs for you.
Featuring 213,895+ Jobs in Software Development
Answer easy questions
213,895+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”