Назад
Company hidden
2 дня назад

Incident Response Analyst (Cybersecurity)

Формат работы
remote (только Europe)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Serbia/Poland/Georgia
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Incident Response Analyst (Cybersecurity): Investigating complex security incidents and handling L2 escalations within the Security Operations team with an accent on digital forensics, malware analysis, and threat detection. Focus on improving SIEM rules, automating SOC workflows, and collaborating across infrastructure and development teams to contain security threats.

Location: Must be based in Georgia, Poland, or Serbia

Company

hirify.global is a leading international tech company providing innovative software solutions for the iGaming industry.

What you will do

  • Investigate and respond to complex security incidents throughout the entire lifecycle.
  • Perform digital forensic investigations, malware analysis, and evidence collection to determine root causes.
  • Analyze attack techniques, correlate security events, and reconstruct attack timelines.
  • Develop and improve SIEM detections, correlation rules, and incident response playbooks.
  • Conduct threat hunting activities and reduce false positives through detection tuning.
  • Automate repetitive SOC activities using scripting and mentor L1 analysts.

Requirements

  • 3+ years of experience in SOC, Incident Response, DFIR, or MSSP environments.
  • Strong command of Russian and intermediate or higher English level.
  • Hands-on experience with SIEM platforms, writing complex search queries, and investigating large volumes of security data.
  • Solid understanding of enterprise infrastructure including Windows, Linux, macOS, Active Directory, Kubernetes, and Docker.
  • Proficiency in automation using Python, PowerShell, or Bash.
  • Deep knowledge of modern cyber threats and frameworks like MITRE ATT&CK and Cyber Kill Chain.

Nice to have

  • Experience with Threat Hunting, Network Traffic Analysis, or cloud security (AWS).
  • Familiarity with CI/CD and Infrastructure as Code (Terraform, Ansible).
  • Participation in Red Team or Purple Team exercises.
  • Industry certifications such as GCIA, GCIH, GCED, OSCP, or CEH.

Culture & Benefits

  • Private health insurance and comprehensive mental health program.
  • Sports benefits and paid time off.
  • Free online English lessons and local language courses.
  • Opportunities for upskilling, internal workshops, and professional conferences.
  • Supportive environment with maternity leave and referral program rewards.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →