
11 - 50 employees
Founded 2008
💼 Consulting
🏥 Healthcare
📦 Logistics
Consulting • Healthcare • Logistics
C4 Group is an IT and management consulting firm that provides recruitment, project and interim management, M&A and post-merger-integration, DevOps & cloud operations, business intelligence and data analytics, SAP/S4 migration, and security & infrastructure services. Founded in 2008, it works primarily with energy, pharmaceutical/life-sciences, and financial-services clients to deliver tailored business, IT and M&A solutions, leveraging strategic partnerships and a consultant network to implement digital transformation projects including AI/ML, RPA, predictive maintenance and energy-optimization use cases.
🕒 4 days ago
Improve your chances of getting an interview by checking your resume score before you apply.

11 - 50 employees
Founded 2008
💼 Consulting
🏥 Healthcare
📦 Logistics
Consulting • Healthcare • Logistics
C4 Group is an IT and management consulting firm that provides recruitment, project and interim management, M&A and post-merger-integration, DevOps & cloud operations, business intelligence and data analytics, SAP/S4 migration, and security & infrastructure services. Founded in 2008, it works primarily with energy, pharmaceutical/life-sciences, and financial-services clients to deliver tailored business, IT and M&A solutions, leveraging strategic partnerships and a consultant network to implement digital transformation projects including AI/ML, RPA, predictive maintenance and energy-optimization use cases.
• Conceptually develop and structurally implement the immediate incident response workstream for “Defending the Castle,” focused on AI-augmented attacks that may progress at machine speed • Create practical response playbooks and SOPs for identity compromise, cloud control-plane abuse, endpoint intrusion, lateral movement, ransomware-style disruption and data-impact scenarios • Define decision points for containment, escalation, evidence preservation, communication, legal/regulatory handover and crisis coordination • Provide technical consultation and recommendations to SOC, threat intelligence, security monitoring, infrastructure, application, Azure, on-premise and resilience teams • Establish and technically define a repeatable operating model for response readiness, evidence collection, handover and post-incident improvement before end of Q1 2027 • Provide technical consultation to enable fast, consistent and controlled response to AI-assisted cyber incidents across hybrid Azure and on-premise landscapes • Predefine and document roles, triggers, containment options and communication paths to optimize incident response workflows • Develop guidelines to facilitate responder action when critical thresholds are reached • Convert lessons from exercises and response reviews into improved playbooks, SOPs and control requirements • Prepare scenario walkthroughs for validation by SOC, Cyber Defense, legal/compliance, cloud, infrastructure and resilience stakeholders • Assess exercise results against time-to-triage, time-to-contain, decision latency and handover quality • Conduct usability testing of playbooks by responders who did not author them • Create a management-ready dashboard for readiness gaps, residual risks and agreed next actions • Identify and technically analyze gaps in existing processes and document optimization potential • Transform risk evaluations into executable playbooks, technical control frameworks, test protocols, backlog items and management evidence • Provide a structured handover of a Phase 2 backlog and recommendations for the broader Business IT resilience plan after Q1 2027 • Create comprehensive documentation of results and hand over materials to the customer for review and approval for further usage
• Minimum 8 years in incident response, cyber defense operations, crisis management, digital forensics or security operations leadership • Hands-on experience responding to identity compromise, ransomware, cloud compromise, endpoint intrusion and lateral movement incidents • Strong understanding of Microsoft security stack, Azure/Entra ID response actions, EDR isolation, forensic triage and evidence preservation • Proven ability to coordinate cross-functional technical and management stakeholders during high-pressure situations • Relevant certifications such as GCIH, GCFA, GNFA, CISSP, CISM, SC-200, AZ-500 or equivalent are beneficial • Profiles must be submitted in English
• Contract duration: 21.09.2026 – 31.03.2027 • 40 hours per week • Remote work
Apply Now