обновлено 10 дней назад
Cyber Incident Response Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Cyber Incident Response Analyst (Cybersecurity): Protecting Fever’s technology environment by triaging and investigating security alerts across endpoint, identity, SaaS, and cloud sources with an accent on incident response, threat hunting, and detection engineering. Focus on building SOAR automation, conducting containment and forensic investigations, and improving detection rules and response playbooks.
Location: Remote anywhere in Argentina
Company
is a technology platform for discovering and scaling culture and live entertainment experiences, operating across more than 55 countries.
What you will do
- Triage, investigate, classify, and resolve security alerts from EDR, SIEM, CNAPP, identity, and SaaS sources.
- Perform incident response activities including scoping, containment, evidence collection, remote forensics, remediation, and documentation.
- Build, maintain, and optimize SOAR playbooks and automation workflows to reduce manual triage effort.
- Conduct threat hunting across endpoint telemetry, cloud logs, and identity provider audit logs.
- Tune existing detections, reduce false positives, and develop new correlation rules based on emerging threats and incident findings.
- Collaborate with engineering and IT teams, produce incident reports, and improve response procedures, playbooks, severity criteria, and SLAs.
Requirements
- Hands-on SOC or incident response experience covering alert triage, investigation, and incident handling.
- Experience with EDR platforms, SIEM query-based investigation, and SOAR playbook development or maintenance.
- Understanding of MITRE ATT&CK, malware delivery chains, phishing, account takeover, cloud environments, and SaaS or identity logs.
- At least 3 years of experience in security operations, incident response, or a similar hands-on cybersecurity role.
- Fluent written and spoken English is required.
- Strong analytical, problem-solving, documentation, and communication skills.
Nice to have
- Experience with AWS, GCP, or other cloud service providers and their security components.
- Scripting experience with Python, Bash, or similar languages for automation and log parsing.
- Digital forensics, threat intelligence, IOC management, relevant degrees, or blue-team security certifications.
Culture & Benefits
- Employment contract with a base salary and potential performance bonus.
- Home-office work from anywhere in Argentina.
- OSDE 410 medical insurance.
- 40% discount on events and experiences.
- English lessons, Gympass, and opportunities for professional and personal growth.
- International team and a high-growth live entertainment environment.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
10 дней назад
Cyber Defence & Incident Response Engineer (Cybersecurity)
10 дней назад
Senior Cybersecurity Engineer (Cyber Threat Intelligence & Response)
13 дней назад
Cyber Security Analyst (Cybersecurity)
108 000 - 162 000CHF
12 дней назад
24/7 SOC Analyst (Cybersecurity)
11 дней назад
Senior Security Analyst (Cybersecurity)
10 дней назад