
Incident Response Analyst
Posted 5 days ago

Posted 5 days ago
This is a fully remote position, open to applicants in Georgia.
• Engage in the response to security incidents.
• Conduct primary incident response actions and perform triage.
• Execute and oversee tasks assigned based on planning outcomes.
• Create and revise playbooks for alert verification.
• Monitor alerts in accordance with service level agreements (SLA).
• Propose improvements for security tools and processes.
• Address and investigate security incidents throughout the organization.
• Coordinate incident responses with relevant teams.
• Assist in ensuring prompt and effective resolution of incidents.
• Work a 2-on-2-off shift pattern, comprising a 12-hour day shift followed by a 12-hour night shift, and then two days off.
• Fundamental skills in analyzing indicators of compromise (IoC) using publicly available tools (e.g., VirusTotal, AnyRun).
• Experience with Splunk, Clickhouse, or SQL, including writing basic search queries and interpreting results.
• Familiarity with SOAR/IRP tools.
• General knowledge of current cyber threats and primary attack techniques.
• Basic programming proficiency in Python, PowerShell, or Bash for automating regular tasks.
• Understanding of operating systems (Linux/Windows) at a junior system administrator level.
• Knowledge of the MITRE ATT&CK framework and the Cyber Kill Chain.
• Capability to analyze and process substantial volumes of data, including logs and triage.
• Strong communication and collaboration skills, particularly in teamwork during incident response.
• Analytical and adaptable mindset; capable of constructing logical sequences, making informed decisions, and proposing solutions independently.
• Proactive attitude and ownership of responsibilities, including accountability for decisions and outcomes, learning from feedback, and pursuing professional growth.
• Nice to have: Familiarity with information security best practices (NIST, ISO).
• Nice to have: Basic understanding of Docker and Kubernetes, along with their monitoring capabilities.
• Nice to have: Experience in writing correlation rules in SIEM.
• Nice to have: Familiarity with NTA tools.
• Nice to have: Experience with online reputation services (e.g., VT, AnyRun, IPAbuseDB).
• Nice to have: Background in developing alert-verification instructions or information security incident response scenarios.
• Nice to have: Experience with technologies like Kafka, ELK, Graylog, etc.
• Nice to have: Strong Linux system administration skills.
• Nice to have: Expertise in analysis and investigation of network, host, and cloud environments.
• Nice to have: Comprehensive understanding of attack pipelines (MITRE ATT&CK Framework, Cyber Kill-Chain).
• Nice to have: Familiarity with CI/CD, software development lifecycle, and Infrastructure-as-Code (Terraform/Ansible, etc.).
• Nice to have: Proficiency in automation using Bash/PowerShell or Python.
• Nice to have: Experience with log collection, delivery, and normalization processes.
• Nice to have: Strong knowledge of open-source endpoint and infrastructure security tools, such as Audit.d, Sysmon, AppArmor, and SELinux.
• Nice to have: Basic skills in static and dynamic malware analysis.
• Nice to have: Experience in offensive security practices (penetration testing, red teaming).
• Private health insurance.
• Sports benefits.
• Comprehensive Mental Health Program.
• Complimentary English lessons (online).
• Local language classes.
• Paid time off.
• Support for maternity leave.
• Rewards for the referral program.
• Opportunities for upskilling, internal workshops, and attendance at professional conferences and corporate events.
Inetum
C4 Group
Cencora
Cencora
Get handpicked remote jobs straight to your inbox weekly.