Remotery

Incident Response Analyst

Posted Jul 27

This is a fully remote position, open to applicants in Czechia, +4 more countries.

📋 Description

• Collaborate with WAF to evaluate unusual traffic patterns, address web threats, and optimize security rules.

• Partner with DLP and MDM to examine data breaches, assess policy infractions, and work jointly with teams on results.

• Oversee and assess alerts in the SIEM system, analyzing occurrences, categorizing incidents, and prioritizing responses.

• Incorporate new log sources into the SIEM, including normalization, parsing, and enrichment processes.

• Create and enhance detection rules, correlation rules, and dashboards.

• Decrease MTTR by pinpointing bottlenecks in response procedures and implementing automation and runbooks.

• Engage in post-incident reviews and offer actionable insights.

• Execute security incident investigations by gathering artifacts, reconstructing timelines, and performing root cause analysis.


⛳️ Requirements

• A minimum of 3 years of experience in Incident Response or Security Operations.

• Practical experience with SIEM platforms (Splunk, ELK/OpenSearch, Graylog, or similar).

• Proficiency in reading and interpreting logs: OS (Linux/Windows/macOS), network, applications, cloud.

• Understanding of network protocols and traffic analysis tools (Wireshark, Zeek, etc.).

• Familiarity with attacker tactics and techniques (MITRE ATT&CK, kill chain, IOC/TTP).

• Capability to independently lead investigations from initial alert to final reporting.

• Scripting abilities for automation (Python / Bash).

• Basic knowledge of integrating LLM-based tools.

• Native-level proficiency in Russian.

• Nice to have:

• Experience with SOAR platforms and developing playbooks.

• Familiarity with EDR/XDR solutions (CrowdStrike, SentinelOne, etc.).

• Engagement in CTFs, red team / blue team exercises, or penetration testing.

• Experience with cloud logs (AWS CloudTrail, GCP Audit Logs, etc.).

• Experience in integrating security tools via APIs and automating responses using LLM.


🏝️ Benefits

• 25 vacation days and 5 family days each year.

• Flexible start times for the workday.

• Access to support from a professional corporate coach and psychologist.

• Participation in regular internal and external activities, workshops, outings, and corporate events.

• Access to our internal knowledge base, meetups, and team-building initiatives.

• Continuous training in new technologies and ongoing professional development support.

People also viewed

Cencora6 hours ago

Engineer III – Cyber Incident Response

IN flagIndia OnlyFull-timeIncident Response Analyst
ApplyView job
Cencora10 hours ago

Engineer II – Cyber Incident Response

IN flagIndia OnlyFull-timeIncident Response Analyst
ApplyView job
Cencora10 hours ago

Engineer II – Cyber Incident Response

IN flagIndia OnlyFull-timeIncident Response Analyst
ApplyView job
Cencora1 day ago

Engineer III – Cyber Incident Response

IN flagIndia OnlyFull-timeIncident Response Analyst
ApplyView job
HBK - Hottinger Brüel & Kjær6 days ago

Vulnerability & Incident Response Analyst

IN flagIndia OnlyFull-timeIncident Response Analyst
ApplyView job
iFoodAug 8

Cybersecurity Incident Response Analyst – Mid-Level

BR flagBrazil OnlyFull-timeIncident Response Analyst
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers