Incident Response Analyst
Remote
middle
1 month ago
full-time
- Work with WAF to analyze anomalous traffic, respond to web attacks, and fine-tune rules.
- Work with DLP and MDM to investigate data leaks, analyze policy violations, and collaborate with teams on findings.
- Monitor and triage alerts in SIEM, analyzing events, classifying incidents, and prioritizing response.
- Integrate new log sources into SIEM, including normalization, parsing, and enrichment.
- Develop and improve detection rules, correlation rules, and dashboards.
- Reduce MTTR by identifying bottlenecks in response processes and implementing automation and runbooks.
- Participate in incident post-mortems and provide actionable recommendations.
- Conduct security incident investigations by collecting artifacts, reconstructing timelines, and performing root cause analysis.
- 3+ years of experience in Incident Response or Security Operations
- Hands-on experience with SIEM platforms (Splunk, ELK/OpenSearch, Graylog, or similar)
- Ability to read and interpret logs: OS (Linux/Windows/macOS), network, applications, cloud
- Understanding of network protocols and traffic analysis (Wireshark, Zeek, etc.)
- Knowledge of attacker tactics and techniques (MITRE ATT&CK, kill chain, IOC/TTP)
- Ability to independently lead investigations from alert to final report
- Scripting skills for automation (Python / Bash)
- Basic understanding of integrating LLM-based tools
- Native-level Russian proficiency
- Nice to Have: Experience with SOAR platforms and building playbooks, Experience with EDR/XDR solutions (CrowdStrike, SentinelOne, etc.), Participation in CTFs, red team / blue team exercises, or pentesting, Experience with cloud logs (AWS CloudTrail, GCP Audit Logs, etc.), Experience integrating security tools via APIs and automating response using LLM.
- 25 vacation days and 5 family days yearly
- Flexible start to the workday
- Support from a professional corporate coach and psychologist
- Regular internal and external activities, workshops, trips, and corporate events
- Access to our internal knowledge base, meetups, and team-building activities
- Ongoing training in new technologies and continuous professional development support.
Similar jobs
IAM Engineer (Security Team)
Talentgrator · Remote
1 month ago
View →
Middle Information Security Access Specialist
GR8 Tech · Remote
1 month ago
View →
Application Support Specialist
Full · Remote
$18k - $30k
2 months ago
View →
AI Security Engineer
Playtech · Remote
16 days ago
View →
Release Engineer
Spribe · Remote
16 days ago
View →
Automation-first SEO Operator / Technical SEO
3SNET · Remote
1 month ago
View →