Incident Response Analyst

Remote middle 3 months ago full-time
Apply now →

✓ Drop your CV once, then continue to the employer's application form. Your profile stays here for every recruiter hiring on igamingjobs.

Role in brief

Talentgrator, a recruitment partner for iGaming, seeks a middle-level Incident Response Analyst. This role focuses on protecting iGaming infrastructure by analyzing security incidents, developing detection logic, and enhancing response capabilities. Candidates with 3+ years in IR/SecOps and SIEM experience should apply.

SIEMSplunkELKOpenSearchGraylogPythonBashWiresharkZeek

About the role

This Incident Response Analyst position involves safeguarding iGaming infrastructure and services. The role requires active participation in analyzing anomalous traffic using WAFs, investigating potential data leaks with DLP and MDM tools, and triaging security alerts within SIEM platforms. A core responsibility is to classify incidents, prioritize responses, and ensure timely resolution to protect the integrity of iGaming operations.

A key aspect of the role is to continuously enhance the organization's security posture. This includes integrating new log sources into SIEM, ensuring proper normalization and enrichment, and developing robust detection and correlation rules. The analyst will also be instrumental in creating dashboards to visualize security data and identify trends, contributing to a proactive security environment.

Success in this role means significantly reducing the Mean Time To Respond (MTTR) to security incidents. This is achieved by identifying and addressing bottlenecks in response processes, implementing automation, and creating clear runbooks. The analyst will also conduct thorough investigations, from artifact collection and timeline reconstruction to root cause analysis, and provide actionable recommendations post-incident to prevent recurrence.

Skills that matter here

  • SIEM: The role involves monitoring, triaging, and analyzing alerts within SIEM platforms, as well as integrating new log sources and developing detection rules.
  • Splunk: Hands-on experience with Splunk or similar SIEM platforms is required for incident analysis and detection rule development.
  • Python: Scripting skills in Python are needed for automating incident response processes and improving efficiency.
  • Bash: Bash scripting is utilized for automation tasks to streamline security operations and reduce response times.
  • Wireshark: Understanding network protocols and traffic analysis using tools like Wireshark is essential for conducting security investigations.
  • Zeek: Knowledge of network traffic analysis with Zeek or similar tools is necessary for identifying and responding to threats.

Who this role suits

  • A person with 3+ years in Incident Response or Security Operations who can independently lead investigations.
  • Someone who is proficient in SIEM platforms and can interpret various types of logs (OS, network, application, cloud).
  • An individual who understands attacker tactics (MITRE ATT&CK) and can apply this knowledge to develop detection logic.
  • A candidate who can communicate effectively in Russian at a native level, as this is a requirement for the role.

From the employer

  • Work with WAF to analyze anomalous traffic, respond to web attacks, and fine-tune rules.
  • Work with DLP and MDM to investigate data leaks, analyze policy violations, and collaborate with teams on findings.
  • Monitor and triage alerts in SIEM, analyzing events, classifying incidents, and prioritizing response.
  • Integrate new log sources into SIEM, including normalization, parsing, and enrichment.
  • Develop and improve detection rules, correlation rules, and dashboards.
  • Reduce MTTR by identifying bottlenecks in response processes and implementing automation and runbooks.
  • Participate in incident post-mortems and provide actionable recommendations.
  • Conduct security incident investigations by collecting artifacts, reconstructing timelines, and performing root cause analysis.
  • 3+ years of experience in Incident Response or Security Operations
  • Hands-on experience with SIEM platforms (Splunk, ELK/OpenSearch, Graylog, or similar)
  • Ability to read and interpret logs: OS (Linux/Windows/macOS), network, applications, cloud
  • Understanding of network protocols and traffic analysis (Wireshark, Zeek, etc.)
  • Knowledge of attacker tactics and techniques (MITRE ATT&CK, kill chain, IOC/TTP)
  • Ability to independently lead investigations from alert to final report
  • Scripting skills for automation (Python / Bash)
  • Basic understanding of integrating LLM-based tools
  • Native-level Russian proficiency
  • Nice to Have: Experience with SOAR platforms and building playbooks, Experience with EDR/XDR solutions (CrowdStrike, SentinelOne, etc.), Participation in CTFs, red team / blue team exercises, or pentesting, Experience with cloud logs (AWS CloudTrail, GCP Audit Logs, etc.), Experience integrating security tools via APIs and automating response using LLM.
  • 25 vacation days and 5 family days yearly
  • Flexible start to the workday
  • Support from a professional corporate coach and psychologist
  • Regular internal and external activities, workshops, trips, and corporate events
  • Access to our internal knowledge base, meetups, and team-building activities
  • Ongoing training in new technologies and continuous professional development support.

Questions about this role

What is the remote work policy for this role?

This position is fully remote, allowing candidates to work from any location.

What level of seniority is expected for this position?

This is a middle-level seniority role, requiring 3+ years of experience in Incident Response or Security Operations.

What specific skills are required for this role?

Required skills include hands-on experience with SIEM platforms (Splunk, ELK, OpenSearch, Graylog), ability to interpret logs, understanding of network protocols and traffic analysis (Wireshark, Zeek), knowledge of attacker tactics (MITRE ATT&CK), and scripting skills in Python or Bash. Native-level Russian proficiency is also required.

Apply now →

✓ Drop your CV once, then continue to the employer's application form. Your profile stays here for every recruiter hiring on igamingjobs.

Similar jobs