IT Security Engineer (Cyber Incident Response and Threat Hunting) - CERT - Group Security (f/m/d)
Deutsche BörseAbout the role
Area of work:
Cyber Emergency Response Team (CERT) is the central unit for Information Security Incident Response. CERT performs his activities in strict cooperation with the Security Operation Center (SOC) and other units within Cyber Defence section, including Cyber Analytics team (responsible for Cyber Threat Detection development), Threat Intel - Threat Hunting team and Cyber Defense Framework unit, responsible also for Purple Teaming activities.
We are looking for a highly motivated and curious Incident Response Engineer with experience in the identification, containment and mitigation of IS incidents. You will be involved in all stages of IS Incident Response at an operational level, as well as in multiple Cyber Defence initiatives, including Threat Hunting program, Digital Forensic, Purple Teaming and SOAR task force, focused on automate detection and remediation and help on building the next generation of security operations and response platform within the Cyber Defense section.
Your responsibilities:
- Lead cyber security incident response engagements covering incident handling and coordination, in-depth technical analysis, and investigation through to recovery
- Develop IR initiatives that improve our capabilities to effectively respond and remediate security incidents (e.g. defining SIEM use-cases, identifying threat hunting hypothesis, promoting red-teaming activities, etc.)
- Perform analysis of logs from a variety of sources (on-premises and cloud-based) identifying potential threats
- Perform root cause analysis and drive implementation of containment and mitigation strategies
- Perform post incident lessons learned, root cause analysis and incident reporting
- Participate in Blue/Red teams exercise to test and improve our monitoring and response capabilities
- Build automation for response and remediation of malicious activity
- Recommend security measures to address cyber threats identified in a proactive-based approach
- Help to improve the CERT process excellence by maintaining information security documentation in line with regulatory requirements
Your profile:
- Previous experience in a CERT or SOC team as well as involvement in IS Incident investigations
- Knowledge of cyber threats and vulnerabilities: how to properly identify, triage, and remediate threats based on threat intelligence as well as on analysis of security events, log data and network traffic
- Expert working knowledge of technical and organizational aspects of information security, e.g., through prior defensive or offensive work experience
- Solid understanding of cyber threats and MITRE ATT&CK framework
- Deliverable-oriented, with strong problem-solving skills and adaptation on complex and highly regulated environment
- Team player willing to cooperate with multiple colleagues across office locations in a cross-cultural environment
- Good report-writing skills to present the findings of inv
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s
Similar roles
Pflege-/Medizinpädagoge (m/w/d) mit Masterabschluss für Lehrtätigkeit
Deutsches Erwachsenen- Bildungswerk gemeinnützige Schulträger-GmbH
Pflegeassistent/Pflegehelfer mit Ausbildung (m/w/a) ab 2.950 EUR/Monat
CURA Seniorenwohn- und Pflegeheime Dienstleistungs GmbH
Pflegefachkraft (m/w/d) / Altenpfleger (m/w/d) / Gesundheits- und Krankenpfleger (m/w/d) S...
Diakonisches Werk Bautzen e.V.