обновлено 2 дня назад
Senior Incident Response Analyst (Cybersecurity)
54 000 - 75 000€
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Incident Response Analyst (Cybersecurity): Responding to active customer attacks through L7 web and bot mitigations, L3/L4 DDoS controls, threat containment, and forensic incident response with an accent on live traffic protection, measurable verification, and customer communication. Focus on tuning WAF and bot policies, isolating compromised hosts, preserving evidence, and rolling back or re-scoping mitigations when collateral impact appears.
Location: Hybrid, Lisbon, Portugal. An in-person interview at a office or hub may be required at the offer stage.
Salary: €54,000–€75,000 annual salary for Portugal-based hires, plus eligibility for ’s equity plan.
Company
operates a global network that protects and accelerates Internet applications for customers ranging from individual bloggers to Fortune 500 companies.
What you will do
- Respond to active customer attacks across L7 abuse, bot activity, web scraping, credential stuffing, WAF/API abuse, and L3/L4 DDoS attacks.
- Deploy and tune WAF rules, bot mitigations, rate limits, challenge policies, and flow-based DDoS controls while minimizing collateral impact.
- Contain threats by isolating infected hosts, revoking compromised sessions or identities, stopping data exfiltration, and tracking lateral movement.
- Define mitigation success criteria, validate results through telemetry and KPIs, and immediately roll back or re-scope ineffective changes.
- Support investigation, containment, remediation, and recovery while preserving logs, volatile memory, and disk images for legal, regulatory, or insurance requirements.
- Prepare accurate incident reports and explain technical findings to executive, technical, and engineering customers.
Requirements
- 3+ years of hands-on experience in a SOC, incident response, or detection engineering role.
- Experience deploying mitigations that affect live customer traffic, including WAF actions, DDoS controls, bot mitigations, rate limiting, or challenge policies.
- Strong incident process discipline covering triage, scoping, mitigation, verification, and communication.
- In-depth knowledge of Windows and general knowledge of Unix, Linux, or Mac environments, plus familiarity with AWS, Azure, O365, Google Cloud, and cloud incident response.
- Technical knowledge of TCP/IP, HTTPS, SSH, RDP, SMB, DNS, MITRE ATT&CK, and the NIST Cybersecurity Framework.
- Excellent verbal and written English communication skills, including the ability to explain complex findings to executive and technical clients.
Nice to have
- Experience with WAF, DDoS Protection, Bot Management, API Shield, or equivalent edge platforms.
- Knowledge of bot fingerprinting, behavioral analysis, JA3/JA4, YARA, malware analysis, source code, binary data, and regular expressions.
- Proficiency in Python or Golang and ability to write modular code or remote investigation scripts.
- Familiarity with Bash, IOCs, network-flow and system-log analysis, BGP, OSPF, routers, firewalls, and switches.
Culture & Benefits
- Work within the Cloudforce One REACT organization alongside forensic analysts, threat researchers, detection engineers, and malware analysts.
- Participate in ’s equity plan.
- Contribute to initiatives that protect the free and open Internet, including Project Galileo, the Athenian Project, and 1.1.1.1.
- is committed to equal opportunity, diversity, inclusion, and reasonable accommodations.
Hiring process
- Candidates progressing to the offer stage may be asked to attend an in-person interview at a office or hub.
- The role may require authorization to receive technology controlled under U.S. export laws without sponsorship for an export license.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
5 дней назад
Security Engineer - Incident Response (Cybersecurity)
70 000 - 107 800€
5 дней назад
Security Engineer, Public Sector
164 000 - 342 000$
CrowdStrike
3 дня назад
Analyst I, Falcon Complete GovCloud (Hybrid, St Louis)
85 000 - 120 000$
5 дней назад
Security Engineer, Detection & Response (Cybersecurity)
237 600 - 297 000$
7 дней назад
Senior SOC Analyst (Cybersecurity)
1 день назад
Staff Security Engineer (Cloud Detection & Response)
189 000 - 303 000$