Назад
Company hidden
12 дней назад

Senior Security Analyst (AI)

Формат работы
remote (только Bulgaria)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Bulgaria
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Analyst (AI): Leading complex security investigations across endpoint, identity, cloud, and production environments with an accent on incident response, threat hunting, and detection engineering. Focus on coordinating major incidents, investigating novel AI-assisted and supply-chain threats, building analysis tools, and strengthening post-incident defenses.

Location: Sofia, Bulgaria; remote work indicated

Company

hirify.global is a publicly traded technology company headquartered in Boston and operating as a regulated gaming business.

What you will do

  • Lead security investigations across endpoint, identity, cloud, and production environments, including triage, root-cause analysis, containment, and eradication.
  • Act as regional incident commander and coordinate response across IT, Engineering, Legal, HR, and other stakeholders.
  • Investigate incidents without established playbooks by determining required data, building analysis tools, and documenting reusable procedures.
  • Prepare and peer-review case summaries, incident reports, and timelines for technical and executive audiences.
  • Hunt for novel threats, including AI-assisted intrusions and supply-chain compromises, and convert findings into telemetry, detections, and automation.
  • Drive post-incident hardening with Security Engineering and mentor other analysts through case reviews, escalation support, and knowledge sharing.

Requirements

  • At least 6 years of cybersecurity experience, including 4 or more years in incident response, forensics, threat intelligence, or threat hunting.
  • Experience leading major incidents with limited supervision, incomplete information, and time pressure, including leadership briefings and post-incident reporting.
  • Knowledge of attacker behavior, insider threat, MITRE ATT&CK, the Diamond Model, and the kill chain.
  • Hands-on experience with SIEM, EDR/NDR, and CSPM tools.
  • Monitoring and investigation experience across endpoint, identity, SaaS, or CI/CD environments and at least one major cloud platform, such as AWS, Azure, or GCP.
  • Practical scripting skills in Python, PowerShell, or a similar language, plus experience with YARA-L, Sigma, KQL, SPL, or comparable query and detection languages.

Culture & Benefits

  • AI is used to improve customer experiences, operations, decision-making, and innovation.
  • Work spans corporate and production environments in a technology-focused gaming company.
  • A gaming license issued by the appropriate state agency may be required as a condition of employment, with guidance provided where relevant.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →