Angajatorii vă vor vedea în baza noastră de date și vor putea singuri să vă ofere locuri de muncă
  • Premium profile
    Nou
  • Căutare locuri de muncă
  • Favorite
  • Conversație
  • Notificările mele
  • Salarii
  • Abonări

Cybersecurity Incident Responder II

Sales Consulting

The Cyber Security Incident Responder is a key player in providing detection, investigation and response to cyber security attacks and threats such as ransomware, spear-phishing, cloud-based attacks, and Advanced Persistent Threats (APTs).

This highly specialized technical subject matter expert position focuses on investigating threats and alerts within large-scale cross-platform environments, performing threat hunting and digital forensics in order to identify intrusions and effectively respond to mitigate security threats on the business.

Key Job Responsibilities

  • Responsible for investigating the incidents escalated by the 24/7 Triage & Monitoring team.

  • Assists the 24/7 Triage & Monitoring team with in-depth investigating cybersecurity alerts raised by a wide variety of security tools like: SOAR, EDR, XDR, IPS/IDS, SIEM, Sandbox, Cloud Security, Email Security, GitLab Security, Container Security.

  • Coordinates incident, response, escalation, and reporting of cybersecurity incidents.

  • Performs technical investigation on complex security incidents to achieve efficient mitigation for active threats and identification of the root cause.

  • Performs quality hands-on technical incident response, log analysis, and threat hunting.

  • Collaborates on various departmental projects that help the organization improve its cyber security posture and achieve its mission/objectives.

  • Collaborates with different CDR stakeholders and vendors to remediate any identified gaps.

  • Define and use CSIRT’s playbooks, runbooks, workflows, operational documentation, and processes. Contributes to the writing and maintenance of all such documents.

  • Looks for opportunities to improve documentation and standardization of CSIRT processes.

  • Owns and delivers on assigned projects (often around improvements to detections, processes and playbooks) while balancing execution and deliveries with operations and IR workload; Supports other team members in projects.

  • Drives continuous improvements of our detection and response capabilities quality and efficiency by identifying and owning improvement areas in the technology, methods, processes (including opportunities around detection tuning and automation).

  • Works on shifts covering 16/5 (Monday to Friday, 7 AM - 10 PM).

  • Offers on-call support during the nights, weekends and public holidays.

Role Qualifications and Requirements

  • This role requires technology subject matter expertise in performing hands-on technical incident response, in-depth technical investigations and Threat Hunting. It is an individual who reads logs, collects technical evidence and puts together the full picture. The ideal candidate is well plugged in the world of hacking and defense and adversary techniques, all with a hands-on keyboard perspective.

  • 3+ years of operational security experience (SOC, Incident Response, Malware Analysis, etc.).

  • Bachelor's Degree OR equivalent experience and relevant certification (such as CompTIA Security+, Network+, CySA+, CCNA, CCNA CyberOps, GCIH, GCFR, GEIR, GCIA, GCFA, GCFE, GSEC, GCED, GREM, OSCP, OSCE, and similar).

  • Experience working independently to detect, handle, investigate and effectively respond to cybersecurity incidents.

  • Ability to assess security incidents quickly and communicate/coordinate a course of action to respond to the incident, while mitigating risk and limiting the impact.

  • Practical experience identifying adversary techniques, tactics, and procedures with enterprise security tools with a demonstrable understanding of modern attacker methodologies.

  • Experience developing and maintaining operations playbooks, runbooks, and operational documentation.

  • Robust understanding of IT fundamentals across networking, system, cloud, virtualization platforms, application layers and advanced understanding of at least one operating system (Windows, Linux, OSX).

  • Good interpersonal and communication skills in order to share knowledge and to communicate effectively with different stakeholders (IT and business partners).

  • Experience with projects or issues of high complexity that require knowledge across multiple technical areas and business units.

  • Highly disciplined and motivated: a self-starter who is able to both work independently or as a member of a team.

  • Demonstrates a Can-Do, delivery-focused and solution-oriented approach (rather than problem-oriented); Flexible, practical, and positive mentality. Is quick to adapt to changing situations.

  • Constantly demonstrates ownership and proactiveness in seeking to improve and optimize in anything related to their and their team’s work.

Oferta de muncă a fost publicată la 29 zile în urmă

Peste 300 000 de români

deja și-au creat profil pe Jooble

Ai obosit să cauți? Începe să muncești!

Creează-ți un profil pe Jooble, iar noi îți vom găsi jobul potrivit ✨

Oferte de muncă similare care v-ar putea interesaÎn baza ofertei de muncă Cybersecurity Incident Responder II din Bucureşti
  •  ...interface between AI teams, GRC, Legal and security leadership, this role drives secure-by-design practices and promotes a strong cybersecurity culture around AI. Role Evolution: The scope of the IT HUB AI Security Analyst role may evolve with the maturity of AI usage... 
    Sugestii
    Contract de muncă

    Equans

    Bucureşti
    4 zile în urmă
  •  ...background across the stack. Your focus topic will be Security Incident Response. You will respond to incidents escalated from various sources and will...  ...quick learner able to adapt quickly to the evolving cybersecurity attack landscape.    Further, you will be owning and... 
    Sugestii
    Full time
    Lucru permanent
    Lucru hibrid

    SAP

    Bucureşti
    9 zile în urmă
  •  ...unit. The CISO organization guarantees information security for our client. The current initiatives are centered on enhancing cybersecurity capabilities across several critical domains: Threat Intelligence, Advanced Persistent Threats (APTs), Red Team Operations,... 
    Sugestii

    Luxoft

    Bucureşti
    2 zile în urmă
  •  ...including regulatory IT audits, SOC engagements, IT internal audits, cybersecurity assurance, IT governance and broader technology-risk...  ...access, change management, system development, IT operations, incident management, backup, recovery and business continuity. Test... 
    Sugestii
    Full time
    Lucru hibrid
    Bucureşti
    O lună în urmă
  •  ...matters. Job Description We are growing our cybersecurity capabilities and are looking for passionate Security...  ..., you will: Monitor, investigate, and respond to security events and incidents Support the implementation and optimization of SIEM... 
    Sugestii
    Full time
    Lucru hibrid

    Endava

    Bucureşti
    8 zile în urmă
  • 8500 lei/luna

     ...Salary: 8.500 - 8.500 RON net per month Requirements: SQL — expert Data Analysis — expert Kibana — good Cybersecurity — strong Customer Support — good Experience with real-time threat detection and bot mitigation for enterprise-scale clients Ability... 
    Full time
    Lucru la distanța
    Lucru în weekend

    Sigma Software

    Bucureşti
    2 luni în urmă
  •  ...security automation strategy that aligns with the bank’s overall cybersecurity objectives. Guide engineers in planning, execution, and...  ...engineering experience with SIEM, Security Orchestrations, and Incident Response, Application Cybersecurity, Vulnerability Management... 
    Full time
    Contract de muncă
    Lucru acasă
    Lucru în weekend
    Bucureşti
    2 luni în urmă
  •  ...HOW ABOUT DRIVING INNOVATION IN EUROPEAN CYBERSECURITY?   The European Cybersecurity Competence Centre (ECCC) is your chance to be part of contributing to the field of cybersecurity competence at the EU level.   Civitta is providing temporary staffing services for... 
    Full time
    Perioadă determinată

    Civitta

    Bucureşti
    2 luni în urmă
  •  ...Who we are looking for We are looking for a Cybersecurity Project Manager with a passion for cybersecurity, project delivery, and working...  ...cybersecurity services that help clients improve resilience, respond to evolving threats, and enable secure digital transformation... 
    Full time
    Lucru hibrid
    Bucureşti
    O lună în urmă
  • About Qualysoft   ·25 years of experience in software engineering, established in Vienna, Austria · Active in Romania since 2007, with office in central Bucharest (Bd. Iancu de Hunedoara 54B) · Delivering End to End IT Consulting Services - From Team Augmentation...
    Full time

    qualysoft

    Bucureşti
    O lună în urmă
  •  ...methodologies, accelerators, and points of view What we offer Join us and become a part of an expert team, working on innovative cybersecurity projects for leading clients around the world. Gain valuable experience with the latest security technologies while driving... 
    Full time
    Work and travel
    Lucru hibrid
    Bucureşti
    2 luni în urmă
  •  ...countries. Day-to-day you will monitor and respond to security events, support our NIS2...  ...; investigate, escalate and coordinate incident response with local IT teams. • Run...  ...offer • A real transition path into cybersecurity – certification budget, structured learning... 
    Full time
    Lucru hibrid

    MAGNAPHARM MARKETING & SALES ROMANIA SRL

    Bucureşti
    27 zile în urmă
  •  ...The job holder is responsible for coordinating and improving cybersecurity incident response, threat hunting, and data analysis to protect and...  ...gaps in analyst effectiveness to management. They will respond to security incidents with higher impacts or in areas without... 
    Lucru hibrid

    Molson Coors

    Bucureşti
    3 ore în urmă
  •  ...Join a high-impact cybersecurity project focused on protecting large-scale digital platforms from automated attacks and malicious activity. We are looking for a Senior DevOps/FinOps Engineer who is passionate about infrastructure optimization, cloud efficiency, and... 

    Sigma Software

    Bucureşti
    5 zile în urmă
  •  ...CrowdStrike's internal Cyber Security Incident Response Team (CSIRT), TIDE...  ...Operations to ensure responders have the detections, data,...  ...rapidly detect, investigate, and respond to security threats. In...  ...and responding to cybersecurity incidents in a SOC, CSIRT, or... 
    Full time
    Lucru hibrid

    Crowdstrike SRL

    Bucureşti
    26 zile în urmă
  •  ...this job: Fresh Graduate from Computer science or related field; Knowledge of databases, operating systems, networking and cybersecurity principles; Strong self-management, organizational, communication and writing skills; Fluent in English; Real drive and... 

    Forvis Mazars Romania

    Bucureşti
    O lună în urmă
  •  ...]. ~ Strong understanding of [cloud platforms (e.g., Azure, AWS, GCP), microservices architecture, API design, data modeling, cybersecurity principles, enterprise integration patterns, DevOps practices]. ~ Proficiency in [architectural design tools (e.g., ArchiMate,... 
    Full time

    Bunge Romania

    Bucureşti
    O lună în urmă
  •  ...providing modern cutting-edge infrastructure that supports a better future. Role purpose: We are looking for a SCADA Network & Cybersecurity Engineer to design, configure and commission secure OT networks for SCADA/Substation Automation Systems used in electrical... 
    Full time
    Lucru la distanța

    E-INFRA

    Bucureşti
    15 zile în urmă
  •  ...cycles is an advantage; Practical experience with security incident response and statutory incident notification to regulatory...  ...implement new processes. Your future role We are looking for a Cybersecurity Manager to take ownership of NIS2 compliance across our in-... 
    Full time
    Contract de muncă
    Lucru hibrid
    Lucru acasă
    Bucureşti
    14 zile în urmă
  •  ...connected territories. EQUANS has built a mature, group-wide cybersecurity governance aligned with ISO 27001: 2022, ANSSI directives (...  ..., cloud security (Azure, AWS), vulnerability management, incident detection and data protection. ~3. Project & business engagement... 
    Contract de muncă
    Lucru hibrid

    Equans

    Bucureşti
    27 zile în urmă
  •  ...specialized for more than 20 years in IT infrastructures (networks, automation, cloud, observability, AI, data, collaboration, and cybersecurity). As a leading player in automated networks and an orchestrator of our clients’ infrastructures, we support large enterprises,... 
    Lucru hibrid

    CNS Communications

    Bucureşti
    2 luni în urmă
  •  ...critical--and at risk--business applications have been neglected for far too long. Onapsis eliminates this blind spot by providing cybersecurity solutions dedicated to business-critical applications. Whether running on premises, in the cloud, or in a hybrid environment,... 
    Lucru hibrid

    Onapsis

    Bucureşti
    13 zile în urmă
  •  ...architecture, and applying System Engineering techniques Specifying and managing system requirements, including RAM, safety, cybersecurity, and V&V needs Interfacing with the Product team System Application Architect and Subsystem Architects to ensure alignment... 
    Full time

    Alstom

    Bucureşti
    O lună în urmă
  •  ...role provides a hybrid way of working with an onsite presence of 2 days/week. Key Job Responsibilities and Duties Provide cybersecurity, IT risk, and regulatory compliance advice to platform owners, development teams, and business functions, in line with internal... 
    Full time
    Lucru hibrid

    BOOKING HOLDINGS ROMANIA SRL

    Bucureşti
    13 zile în urmă
  •  ...For our partner, a company specializing in the development of innovative cybersecurity software solutions, we are looking for an experienced Project Manager to join their team in Bucharest. Requirements Previous experience in similar roles, with experience working... 
    Contract de muncă

    HR Gold

    Bucureşti
    O zi în urmă
  •  ...will directly enhance the Bank's ability to detect, respond to, and recover from security incidents, fortifying our defences through an adaptive, agile,...  ...track record of 5+ years of progressive experience in cybersecurity program or project management, with significant... 
    Full time
    Lucru hibrid
    Lucru la distanța
    Lucru în weekend
    Bucureşti
    O lună în urmă
  •  ...Assist the stakeholders with security knowledge across the delivery lifecycle (from code to production) Take ownership over cybersecurity tasks Ability to work with cybersecurity policies, procedures and processes and propose improvements Coordinate and lead the... 
    Full time
    Lucru hibrid

    Endava

    Bucureşti
    7 zile în urmă
  •  ...motivated and enthusiastic DevSecOps Engineers who want to impact cybersecurity by continuing to advance, maintain, and enhance our platform...  ...for penetration testing activities. Security Operations & Incident Response: Collaborate with cross-functional teams to... 
    Full time
    Lucru hibrid

    Onapsis

    Bucureşti
    7 zile în urmă
  • 22000 - 26000 lei/luna

     ...Firmware-Over-the-Air (FOTA) solutions ~ Strong background in communication technologies such as LTE, BLE, OpenThread, MQTT, and cybersecurity ~ Practical experience with Yocto Linux ~ Experience in debugging and troubleshooting embedded systems, including software... 
    Contract de muncă

    Sigma Software

    Bucureşti
    2 luni în urmă
  •  ...thinking back to the team and our clients What we offer Join us and become a part of an expert team, working on innovative cybersecurity projects for leading clients around the world. Gain valuable experience with the latest security technologies while driving... 
    Full time
    Work and travel
    Lucru hibrid
    Bucureşti
    2 luni în urmă