Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Incident Response Analyst II (Cybersecurity): Building automation, detections, integrations, and response capabilities for internal cybersecurity operations with an accent on incident investigation, scalable tooling, and cloud-native engineering. Focus on reducing false positives, automating investigative workflows, operationalising threat intelligence, and improving responder effectiveness.
Location: Hybrid in Bucharest, Romania
Company
Cybersecurity company developing an AI-native platform to protect organizations, users, and critical business operations from breaches.
What you will do
- Partner with incident response operations to identify challenges and build scalable security solutions.
- Automate investigative and response workflows to reduce manual effort and accelerate incident handling.
- Design and maintain detections, enrichment pipelines, and response capabilities across diverse technologies and data sources.
- Build integrations between security platforms, cloud services, and internal systems.
- Develop reliable cloud-native tooling using CI/CD, Infrastructure as Code, and modern software engineering practices.
- Improve security visibility, alert quality, and operational efficiency through continuous engineering improvements.
Requirements
- Hands-on experience investigating and responding to cybersecurity incidents in a SOC, CSIRT, or incident response team.
- Software development experience with Python, Go, or another modern programming language.
- Experience building automation, APIs, or systems integrations.
- Experience with AWS, Azure, Google Cloud, or similar cloud platforms.
- Understanding of Linux, networking, authentication, and enterprise security technologies.
- Strong analytical, troubleshooting, and communication skills.
Nice to have
- Experience with CI/CD platforms such as GitLab CI, GitHub Actions, or Jenkins.
- Experience with Docker, Kubernetes, Terraform, or other Infrastructure as Code technologies.
- Knowledge of SIEM, EDR, SOAR, identity, cloud security, security telemetry, or log analytics platforms.
- Familiarity with MITRE ATT&CK, threat hunting, or threat intelligence.
- Experience applying AI or machine learning to security operations and engineering workflows.
Culture & Benefits
- Flexible, autonomous work culture focused on responsible AI adoption, experimentation, and innovation.
- Comprehensive physical and mental wellness programs.
- Competitive vacation, holidays, and paid parental and adoption leave.
- Professional development opportunities for employees at every level.
- Employee networks, local community groups, volunteer opportunities, and a vibrant office environment.
- Compensation and equity awards with benefits provided through a global employment program.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →