обновлено 5 дней назад
Incident Response Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Incident Response Analyst (Cybersecurity): Responding to and investigating security incidents across the company with an accent on alert triage, IoC analysis, log investigation, and incident coordination. Focus on developing alert-verification playbooks, monitoring SLA compliance, automating routine tasks, and analyzing attack techniques using MITRE ATT&CK and Cyber Kill Chain.
Location: Georgia, Poland, or Serbia
Company
develops and operates software solutions for the iGaming industry.
What you will do
- Participate in security incident response and perform initial triage.
- Investigate alerts, indicators of compromise, logs, and other security data.
- Coordinate incident-response activities with relevant teams and monitor assigned tasks through completion.
- Develop and update playbooks and instructions for alert verification.
- Monitor alerts in line with SLA requirements and propose improvements to security tools and processes.
- Work a 2-on-2-off schedule with a 12-hour day shift, a 12-hour night shift, and two days off.
Requirements
- Basic IoC analysis skills using tools such as VirusTotal and AnyRun.
- Experience with Splunk, ClickHouse, and SQL for simple search queries and result interpretation.
- Experience with SOAR/IRP and an understanding of current cyber threats and attack methods.
- Basic programming skills in Python, PowerShell, or Bash, plus junior system-administration knowledge of Linux and Windows.
- Understanding of the MITRE ATT&CK framework and Cyber Kill Chain, with the ability to analyze large volumes of logs and triage data.
- Strong communication, analytical thinking, flexibility, proactivity, and ownership.
Nice to have
- Knowledge of NIST, ISO, Docker, Kubernetes, SIEM correlation rules, NTA, Kafka, ELK, or Graylog.
- Strong Linux administration, network, host, cloud, malware, or offensive-security experience.
- Experience with CI/CD, infrastructure as code, log collection and normalization, or endpoint and infrastructure security tools.
Culture & Benefits
- Private health insurance and sports benefits.
- Comprehensive mental health program, paid time off, and maternity leave support.
- Free online English lessons and local language courses.
- Upskilling, internal workshops, professional conferences, and corporate events.
- Referral program rewards.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →