Назад
Company hidden
обновлено 2 дня назад

Incident Response Analyst (iGaming)

Формат работы
remote (только Europe)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Serbia/Poland/Armenia +3 еще
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Incident Response Analyst (iGaming): Analyzing security events, investigating suspicious activity, and improving incident response for infrastructure and services with an accent on raw log interpretation, SIEM monitoring, and threat detection. Focus on correlating events across multiple sources, reconstructing incident timelines, tuning detection rules, and reducing MTTR through automation and runbooks.

Location: Remote from Czechia, Serbia, Georgia, Armenia, Kazakhstan, or Poland

Company

hirify.global is a recruitment and talent partner connecting businesses in the IT entertainment and iGaming sectors with specialized professionals.

What you will do

  • Analyze anomalous traffic through WAF, respond to web attacks, and fine-tune security rules.
  • Investigate data leaks and policy violations using DLP and MDM platforms.
  • Monitor and triage SIEM alerts, classify incidents, and prioritize response.
  • Integrate, normalize, parse, and enrich raw log sources in SIEM platforms.
  • Develop detection and correlation rules, dashboards, automation, and incident-response runbooks.
  • Investigate incidents by collecting artifacts, reconstructing timelines, identifying root causes, and contributing to post-mortems.

Requirements

  • 3+ years of experience in Security Operations, SOC, Incident Response, Infrastructure Security, or a similar technical role.
  • Ability to read and interpret raw logs, correlate information from multiple sources, and identify anomalies.
  • Good understanding of Linux, Windows, networking fundamentals, common protocols, and enterprise infrastructure.
  • Hands-on experience with SIEM platforms such as Splunk, plus knowledge of IOC and TTP concepts.
  • Familiarity with Active Directory, Kubernetes, Docker, Terraform, and Ansible.
  • Basic scripting experience with Python, PowerShell, or Bash, along with strong analytical and troubleshooting skills.

Nice to have

  • Experience with WAF, DLP, MDM, EDR/XDR, SOAR, cloud infrastructure, or cloud logs.
  • Experience with threat hunting, network traffic analysis, SIEM detection rules, APIs, or security automation.
  • Participation in Red Team, Blue Team, Purple Team, CTF, or penetration-testing activities.

Culture & Benefits

  • 25 vacation days and 5 family days annually.
  • Flexible start to the workday.
  • Access to a corporate coach, psychologist, internal knowledge base, meetups, workshops, trips, and team-building activities.
  • Ongoing training in new technologies and continuous professional development support.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →