Incident Response Security Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Incident Response Security Engineer (Cybersecurity): Strengthen EDR/XDR and DLP configurations, define SIEM detections, automate triage and playbooks with an accent on security event detection, enrichment, and incident response automation. Focus on integrating SIEM/SOAR, defining runbooks, and collaborating on security engineering activities.
Full remote position, considering candidates located in Italy, Spain or UK.
Company
Leading online motor insurance provider using data and tech since 2015, trusted by over 5 million drivers in Italy, expanding to UK and Spain.
What you will do
- Strengthen EDR/XDR and DLP configurations.
- Define new automatic detections of security events in SIEM.
- Improve automatic enrichment and integration with SIEM/SOAR.
- Automate security alerts triage and Incident Response playbooks.
- Define runbooks for Incident Response.
- Collaborate on Security Engineering team activities.
Requirements
- Hands-on experience with SIEM and SOAR platforms.
- Hands-on experience with Crowdstrike or similar EDR/XDR solutions.
- Hands-on experience with MDM solutions.
- Hands-on experience in AWS and K8s (EKS) security.
- Proficiency in scripting and programming languages (e.g., Python, Rust).
- Availability in on-call shifts for 24x7 security support.
- Strong English communication skills.
- Self-motivated with strong problem-solving skills.
- Experience in Agile environment.
Nice to have
- Certifications such as GCIH, GCFA, GREM, GCIA.
- Experience with Google Chronicle.
- Experience with Web Application Firewall (e.g., Cloudflare).
- Proficiency in CI/CD and IaC (e.g., Python Pulumi).
- Knowledge of Cloud Control Frameworks (CIS, CSA, NIST).
- Web and mobile app security knowledge.
- Experience in security research, bug bounties or CTFs.
Culture & Benefits
- Full flexibility: work from home, office, or hybrid; work from anywhere up to 30 days a year.
- Learning resources, mentorship, tailored growth plan.
- Private healthcare, gym discounts, wellbeing and mental health support.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →