0Senior Cybersecurity Incident Responder (f/m/d)
ZEISS | Germany | 73xxx Oberkochen (Baden-Württemberg) | Permanent position | Full time | Published since: 04.03.2026 on stepstone.de

Senior Cybersecurity Incident Responder (f/m/d)

Branch: Electrical engineering Branch: Electrical engineering


Step out of your comfort zone, excel and redefine the limits of what is possible. That's just what our employees are doing every single day – in order to set the pace through our innovations and enable outstanding achievements. After all, behind every successful company are many great fascinating people. In a spacious modern setting full of opportunities for further development, ZEISS employees work in a place where expert knowledge and team spirit reign supreme. All of this is supported by a special ownership structure and the long-term goal of the Carl Zeiss Foundation: to bring science and society into the future together. Join us today. Inspire people tomorrow. Diversity is a part of ZEISS. We look forward to receiving your application silence of gender, nationality, ethnic and social origin, religion, philosophy of life, disability, age, sexual orientation or identity. Apply now! It takes less than 10 minutes. .

Your tasks • Your profile • What we offer

Welcome to ZEISS – a company that combines innovation and responsibility! Our corporate functions are various and make a decisive contribution to the orientation strategic and sustainable success of ZEISS.

Corporate Information Technology (CIT) is the central part of the company's strategy, developing and implementing innovative security solutions to enhance efficiency and competitiveness in the Carl Zeiss Group. By working closely with various business units, CIT ensures that technological advancements and digital transformations are seamlessly integrated into business processes. Your role: In this role, you are a senior technical expert within the Cyber Defense Center and a core member of the Cybersecurity Incident Response Team (CIRT). You support the effective handling of cybersecurity incidents by contributing deep technical expertise, structured analysis, and reliable performance throughout the incident response lifecycle. Acting as a permanent member of the Cybersecurity Incident Response Team (CIRT)

Executing and technical supporting incident, including analysis, containment, and recovery

Escalating critical technical findings and risks to the Incident Commander

Supporting the Incident Commander and Incident Coordinators in the technical execution of incident response activities

Providing technical guidance and expertise to other IR roles

Collaborating close with Digital Forensics and Threat Intelligence teams to enable in-depth technical analysis

Performing and root reporting cause analysis, incident status and potential response measures

Supplying accurate technical input for internal communication and external reporting to authorities via the Incident Commander

Ensuring complete and structured documentation of all incident response

Several years of professional experience in cybersecurity incident response, SOC, DFIR, or cyber defense environments

Strong technical knowledge of IT infrastructures, networks, operating, and cloud environments

Proven experience in handling complex or high-severity cybersecurity incidents

Solid understanding of attacker Tactics, Techniques, and Procedures (TTPs) and the ability to identify, analyze, and respond to them in real-world incidents

Experience mapping observed activity to frameworks search as MITRE ATT&CK and deriving response or mitigation measures

Sound understanding of established incident response frameworks (e.g. NIST, SANS)

Ability to communicate technical findings clearly and concisely to different stakeholder groups

Structured, reliable, and resilient working style, especially in critical situation

Location

ava ZEISS
73447  Oberkochen (Baden-Württemberg)
Germany

The text of this ad was translated from German into English using an automatic translation system and may contain semantic and lexical errors. Therefore, it should be used for introductory purposes only. For more detailed information, see the original text of the ad at the link below.

For more information read the original ad

Permanent link to this ad

Ad Id