codeby_jobs_bot
Newbie
- 15.04.2026
- 696
- 0
Incident Response Analyst (L2)
Работодатель: Название скрыто (Сфера развлечений)
Зарплата: от 3 000 до 5 500 €
Work format: remote from anywhere in the world or from one of our European offices. The company hires specialists who have already relocated from Russia/Belarus.
We are looking for an Incident Response Analyst (L2) to strengthen our Security Operations team. In this position, you will investigate sophisticated security incidents, process escalations from L1, and contribute to improving our detection and response capabilities.
Purpose of the role
Your core focus will be the investigation of complex cybersecurity incidents, management of L1 escalations, and continuous improvement of SOC detection and incident response processes.
We need a specialist with an incident-driven approach who can dissect attack chains, test hypotheses, and make evidence-based decisions to efficiently detect, analyze, and contain security threats.
Key responsibilities
Required Experience
Nice to have:
Подробнее и отклик → Вакансия Incident Response Analyst (L2), работа в Название скрыто (Сфера развлечений) , удалённо — getmatch
Другие действия:
Агрегировано Codeby Jobs. Источник: getmatch_ru (getmatch.ru). Удаление по запросу: @admin.
Работодатель: Название скрыто (Сфера развлечений)
Зарплата: от 3 000 до 5 500 €
Work format: remote from anywhere in the world or from one of our European offices. The company hires specialists who have already relocated from Russia/Belarus.
We are looking for an Incident Response Analyst (L2) to strengthen our Security Operations team. In this position, you will investigate sophisticated security incidents, process escalations from L1, and contribute to improving our detection and response capabilities.
Purpose of the role
Your core focus will be the investigation of complex cybersecurity incidents, management of L1 escalations, and continuous improvement of SOC detection and incident response processes.
We need a specialist with an incident-driven approach who can dissect attack chains, test hypotheses, and make evidence-based decisions to efficiently detect, analyze, and contain security threats.
Key responsibilities
- Investigate and respond to complex security incidents across the full incident lifecycle.
- Carry out digital forensic investigations, malware analysis, and evidence gathering to establish the scope and root cause of security incidents.
- Examine attack techniques, correlate security events, and reconstruct attack timelines.
- Create and refine SIEM detections, correlation rules, and incident response playbooks.
- Perform threat hunting activities and minimize false positives through detection tuning.
- Automate routine SOC tasks using scripting where applicable.
- Work closely with Infrastructure, Development, IT, and Security teams during incident response.
- Guide and mentor L1 analysts by offering technical support and feedback.
Required Experience
- 3+ years of experience in SOC, Incident Response, DFIR, or MSSP environments.
- Solid knowledge of modern cyber threats, attack techniques, and frameworks such as MITRE ATT&CK and the Cyber Kill Chain.
- Practical experience investigating security incidents, conducting digital forensics, and performing malware analysis.
- Practical experience with SIEM platforms (e.g., Splunk, Wazuh, ClickHouse, Redash), including building complex search queries, correlating events, and analyzing large volumes of security data.
- Confident understanding of enterprise infrastructure, including Windows, Linux, macOS, Active Directory, email systems, Kubernetes, Docker, and databases.
- Experience with automation using Python, PowerShell, or Bash.
- Knowledge of Kubernetes and Docker security concepts.
- Strong analytical thinking, problem-solving abilities, and clear communication in cross-functional settings.
- Intermediate or higher English level.
Nice to have:
- Experience with Threat Hunting, Network Traffic Analysis (NTA), or cloud security (AWS).
- Familiarity with CI/CD and Infrastructure as Code (e.g., Terraform, Ansible).
- Participation in Red Team or Purple Team exercises.
- Industry certifications such as GCIA, GCIH, GCED, OSCP, CEH, or Splunk certifications.
- Familiarity with security frameworks such as NIST.
- Заполнить профиль — получайте подобные вакансии
- Работодатель? Опубликуйте напрямую
Агрегировано Codeby Jobs. Источник: getmatch_ru (getmatch.ru). Удаление по запросу: @admin.