Назад
Company hidden
обновлено 5 дней назад

Incident Response Analyst (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
junior
Английский
b2
Страна
Serbia/Poland/Georgia
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Incident Response Analyst (Cybersecurity): Responding to and investigating security incidents across the company with an accent on alert triage, IoC analysis, log investigation, and incident coordination. Focus on developing alert-verification playbooks, monitoring SLA compliance, automating routine tasks, and analyzing attack techniques using MITRE ATT&CK and Cyber Kill Chain.

Location: Georgia, Poland, or Serbia

Company

hirify.global develops and operates software solutions for the iGaming industry.

What you will do

  • Participate in security incident response and perform initial triage.
  • Investigate alerts, indicators of compromise, logs, and other security data.
  • Coordinate incident-response activities with relevant teams and monitor assigned tasks through completion.
  • Develop and update playbooks and instructions for alert verification.
  • Monitor alerts in line with SLA requirements and propose improvements to security tools and processes.
  • Work a 2-on-2-off schedule with a 12-hour day shift, a 12-hour night shift, and two days off.

Requirements

  • Basic IoC analysis skills using tools such as VirusTotal and AnyRun.
  • Experience with Splunk, ClickHouse, and SQL for simple search queries and result interpretation.
  • Experience with SOAR/IRP and an understanding of current cyber threats and attack methods.
  • Basic programming skills in Python, PowerShell, or Bash, plus junior system-administration knowledge of Linux and Windows.
  • Understanding of the MITRE ATT&CK framework and Cyber Kill Chain, with the ability to analyze large volumes of logs and triage data.
  • Strong communication, analytical thinking, flexibility, proactivity, and ownership.

Nice to have

  • Knowledge of NIST, ISO, Docker, Kubernetes, SIEM correlation rules, NTA, Kafka, ELK, or Graylog.
  • Strong Linux administration, network, host, cloud, malware, or offensive-security experience.
  • Experience with CI/CD, infrastructure as code, log collection and normalization, or endpoint and infrastructure security tools.

Culture & Benefits

  • Private health insurance and sports benefits.
  • Comprehensive mental health program, paid time off, and maternity leave support.
  • Free online English lessons and local language courses.
  • Upskilling, internal workshops, professional conferences, and corporate events.
  • Referral program rewards.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →