Incident Response Analyst
Brak informacji o wynagrodzeniu
MidFull-time
#412107·Dodano 19 dni temu·4
Źródło: TalentgratorTech Stack / Keywords
SecuritySIEMLinuxNetworkingNetworkSplunkCybersecurityActive Directory
Firma i stanowisko
Talentgrator is a recruitment service that connects IT entertainment and iGaming industry businesses with professionals. We support the growth and development of the iGaming ecosystem through a personalized approach tailored to the unique needs of each business.
Wymagania
- 3+ years of experience in Security Operations, SOC, Incident Response, Infrastructure Security, or a similar technical role.
- Ability to read and interpret raw logs and understand system and application event meanings.
- Good understanding of Linux and Windows operating systems.
- Good understanding of networking fundamentals and common network protocols.
- Hands-on experience with SIEM platforms, preferably Splunk or similar.
- Ability to investigate security events by correlating information from different log sources.
- Understanding of common cybersecurity threats, attacker techniques, and IOC/TTP concepts.
- Familiarity with Active Directory and enterprise infrastructure.
- Understanding of Kubernetes and Docker environments.
- Basic scripting experience with Python, PowerShell, or Bash.
- Understanding of Terraform and Ansible for infrastructure automation and configuration management.
- Strong analytical and troubleshooting skills.
Nice to have:
- Experience with WAF, DLP, MDM, EDR/XDR, or similar security technologies.
- Experience with Threat Hunting or Network Traffic Analysis.
- Experience writing or tuning SIEM detection rules.
- Experience with SOAR or security automation.
- Experience with cloud infrastructure and cloud logs.
- Experience with APIs and automation.
- Participation in Red Team, Blue Team, Purple Team exercises, CTFs, or penetration testing.
Obowiązki
- Work with WAF to analyze anomalous traffic, respond to web attacks, and fine-tune rules.
- Work with DLP and MDM to investigate data leaks, analyze policy violations, and collaborate with teams on findings.
- Monitor and triage alerts in SIEM, analyzing events, classifying incidents, and prioritizing response.
- Integrate raw log sources into SIEM, including normalization, parsing, and enrichment.
- Develop and improve detection rules, correlation rules, and dashboards.
- Reduce MTTR by identifying bottlenecks in response processes and implementing automation and runbooks.
- Participate in incident post-mortems and provide actionable recommendations.
- Conduct security incident investigations by collecting artifacts, reconstructing timelines, and performing root cause analysis.
Benefity
- 25 vacation days and 5 family days yearly
- Flexible start to the workday
- Support from a professional corporate coach and psychologist
- Regular internal and external activities, workshops, trips, and corporate events
- Access to internal knowledge base, meetups, and team-building activities
- Ongoing training in new technologies and continuous professional development support
Elastyczne godziny
Talentgrator
16 aktywnych ofert