Incident Response Analyst

Posted 5 days ago

This is a fully remote position, open to applicants in Georgia.

📋 Description

• Engage in the response to security incidents.

• Conduct primary incident response actions and perform triage.

• Execute and oversee tasks assigned based on planning outcomes.

• Create and revise playbooks for alert verification.

• Monitor alerts in accordance with service level agreements (SLA).

• Propose improvements for security tools and processes.

• Address and investigate security incidents throughout the organization.

• Coordinate incident responses with relevant teams.

• Assist in ensuring prompt and effective resolution of incidents.

• Work a 2-on-2-off shift pattern, comprising a 12-hour day shift followed by a 12-hour night shift, and then two days off.


⛳️ Requirements

• Fundamental skills in analyzing indicators of compromise (IoC) using publicly available tools (e.g., VirusTotal, AnyRun).

• Experience with Splunk, Clickhouse, or SQL, including writing basic search queries and interpreting results.

• Familiarity with SOAR/IRP tools.

• General knowledge of current cyber threats and primary attack techniques.

• Basic programming proficiency in Python, PowerShell, or Bash for automating regular tasks.

• Understanding of operating systems (Linux/Windows) at a junior system administrator level.

• Knowledge of the MITRE ATT&CK framework and the Cyber Kill Chain.

• Capability to analyze and process substantial volumes of data, including logs and triage.

• Strong communication and collaboration skills, particularly in teamwork during incident response.

• Analytical and adaptable mindset; capable of constructing logical sequences, making informed decisions, and proposing solutions independently.

• Proactive attitude and ownership of responsibilities, including accountability for decisions and outcomes, learning from feedback, and pursuing professional growth.

• Nice to have: Familiarity with information security best practices (NIST, ISO).

• Nice to have: Basic understanding of Docker and Kubernetes, along with their monitoring capabilities.

• Nice to have: Experience in writing correlation rules in SIEM.

• Nice to have: Familiarity with NTA tools.

• Nice to have: Experience with online reputation services (e.g., VT, AnyRun, IPAbuseDB).

• Nice to have: Background in developing alert-verification instructions or information security incident response scenarios.

• Nice to have: Experience with technologies like Kafka, ELK, Graylog, etc.

• Nice to have: Strong Linux system administration skills.

• Nice to have: Expertise in analysis and investigation of network, host, and cloud environments.

• Nice to have: Comprehensive understanding of attack pipelines (MITRE ATT&CK Framework, Cyber Kill-Chain).

• Nice to have: Familiarity with CI/CD, software development lifecycle, and Infrastructure-as-Code (Terraform/Ansible, etc.).

• Nice to have: Proficiency in automation using Bash/PowerShell or Python.

• Nice to have: Experience with log collection, delivery, and normalization processes.

• Nice to have: Strong knowledge of open-source endpoint and infrastructure security tools, such as Audit.d, Sysmon, AppArmor, and SELinux.

• Nice to have: Basic skills in static and dynamic malware analysis.

• Nice to have: Experience in offensive security practices (penetration testing, red teaming).


🏝️ Benefits

• Private health insurance.

• Sports benefits.

• Comprehensive Mental Health Program.

• Complimentary English lessons (online).

• Local language classes.

• Paid time off.

• Support for maternity leave.

• Rewards for the referral program.

• Opportunities for upskilling, internal workshops, and attendance at professional conferences and corporate events.

People also viewed

InetumSep 4

Analista de Respuesta a Incidentes SOC – 24/7

PT flagPortugal OnlyFull-timeIncident Response Analyst
ApplyView job
C4 GroupSep 3

Incident Response Expert, AI-Augmented Cyber Incident Response

DE flagGermany OnlyFreelanceIncident Response Analyst
ApplyView job
CencoraAug 21

Engineer III – Cyber Incident Response

IN flagIndia OnlyFull-timeIncident Response Analyst
ApplyView job
CencoraAug 20

Engineer II – Cyber Incident Response

IN flagIndia OnlyFull-timeIncident Response Analyst
ApplyView job
CencoraAug 20

Engineer II – Cyber Incident Response

IN flagIndia OnlyFull-timeIncident Response Analyst
ApplyView job
CencoraAug 19

Engineer III – Cyber Incident Response

IN flagIndia OnlyFull-timeIncident Response Analyst
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers