Incident Response Analyst

Remote middle 1 month ago full-time
SIEMSplunkELKOpenSearchGraylogPythonBashWiresharkZeek
  • Work with WAF to analyze anomalous traffic, respond to web attacks, and fine-tune rules.
  • Work with DLP and MDM to investigate data leaks, analyze policy violations, and collaborate with teams on findings.
  • Monitor and triage alerts in SIEM, analyzing events, classifying incidents, and prioritizing response.
  • Integrate new log sources into SIEM, including normalization, parsing, and enrichment.
  • Develop and improve detection rules, correlation rules, and dashboards.
  • Reduce MTTR by identifying bottlenecks in response processes and implementing automation and runbooks.
  • Participate in incident post-mortems and provide actionable recommendations.
  • Conduct security incident investigations by collecting artifacts, reconstructing timelines, and performing root cause analysis.
  • 3+ years of experience in Incident Response or Security Operations
  • Hands-on experience with SIEM platforms (Splunk, ELK/OpenSearch, Graylog, or similar)
  • Ability to read and interpret logs: OS (Linux/Windows/macOS), network, applications, cloud
  • Understanding of network protocols and traffic analysis (Wireshark, Zeek, etc.)
  • Knowledge of attacker tactics and techniques (MITRE ATT&CK, kill chain, IOC/TTP)
  • Ability to independently lead investigations from alert to final report
  • Scripting skills for automation (Python / Bash)
  • Basic understanding of integrating LLM-based tools
  • Native-level Russian proficiency
  • Nice to Have: Experience with SOAR platforms and building playbooks, Experience with EDR/XDR solutions (CrowdStrike, SentinelOne, etc.), Participation in CTFs, red team / blue team exercises, or pentesting, Experience with cloud logs (AWS CloudTrail, GCP Audit Logs, etc.), Experience integrating security tools via APIs and automating response using LLM.
  • 25 vacation days and 5 family days yearly
  • Flexible start to the workday
  • Support from a professional corporate coach and psychologist
  • Regular internal and external activities, workshops, trips, and corporate events
  • Access to our internal knowledge base, meetups, and team-building activities
  • Ongoing training in new technologies and continuous professional development support.

Similar jobs

Before you apply

  • Legitimate employers never ask you to pay anything to apply or get hired.
  • Guard your ID and bank details. Share them only after you have verified the employer and the offer is real.
  • Do not install software ("test tasks", "screening tools", "video call clients") sent during hiring.
  • Check that the application page's domain really belongs to Talentgrator.