
Incident Response Analyst
Posted Jul 27

Posted Jul 27
This is a fully remote position, open to applicants in Czechia, +4 more countries.
• Collaborate with WAF to evaluate unusual traffic patterns, address web threats, and optimize security rules.
• Partner with DLP and MDM to examine data breaches, assess policy infractions, and work jointly with teams on results.
• Oversee and assess alerts in the SIEM system, analyzing occurrences, categorizing incidents, and prioritizing responses.
• Incorporate new log sources into the SIEM, including normalization, parsing, and enrichment processes.
• Create and enhance detection rules, correlation rules, and dashboards.
• Decrease MTTR by pinpointing bottlenecks in response procedures and implementing automation and runbooks.
• Engage in post-incident reviews and offer actionable insights.
• Execute security incident investigations by gathering artifacts, reconstructing timelines, and performing root cause analysis.
• A minimum of 3 years of experience in Incident Response or Security Operations.
• Practical experience with SIEM platforms (Splunk, ELK/OpenSearch, Graylog, or similar).
• Proficiency in reading and interpreting logs: OS (Linux/Windows/macOS), network, applications, cloud.
• Understanding of network protocols and traffic analysis tools (Wireshark, Zeek, etc.).
• Familiarity with attacker tactics and techniques (MITRE ATT&CK, kill chain, IOC/TTP).
• Capability to independently lead investigations from initial alert to final reporting.
• Scripting abilities for automation (Python / Bash).
• Basic knowledge of integrating LLM-based tools.
• Native-level proficiency in Russian.
• Nice to have:
• Experience with SOAR platforms and developing playbooks.
• Familiarity with EDR/XDR solutions (CrowdStrike, SentinelOne, etc.).
• Engagement in CTFs, red team / blue team exercises, or penetration testing.
• Experience with cloud logs (AWS CloudTrail, GCP Audit Logs, etc.).
• Experience in integrating security tools via APIs and automating responses using LLM.
• 25 vacation days and 5 family days each year.
• Flexible start times for the workday.
• Access to support from a professional corporate coach and psychologist.
• Participation in regular internal and external activities, workshops, outings, and corporate events.
• Access to our internal knowledge base, meetups, and team-building initiatives.
• Continuous training in new technologies and ongoing professional development support.
Cencora
Cencora
Cencora
Cencora
Get handpicked remote jobs straight to your inbox weekly.