Role in brief
SOFTSWISS is seeking a Middle Incident Response Analyst for their Security Operations team. This role focuses on detecting, investigating, and responding to security incidents, alongside improving SOC processes and automation. It is suitable for a specialist with experience in SIEM, EDR, and SecOps processes who can balance security with system performance.
About the role
This role involves hands-on work within the Security Operations team, primarily focused on incident response. The analyst will be responsible for identifying, investigating, and addressing security incidents. A key part of the job is to implement corrective actions following any security breaches.
The position also requires continuous improvement of the Security Operations Center's processes and automation. The goal is to enhance the speed and effectiveness of threat mitigation. This means contributing to a security framework that is both robust and efficient.
Success in this role means not only effectively responding to incidents but also understanding system specifics to ensure security measures do not hinder performance. The ideal candidate will integrate security practices seamlessly into existing systems, maintaining operational balance.
The annual salary for this position ranges from $51,750 to $86,250.
Skills that matter here
- Splunk: This tool will be used for Security Information and Event Management (SIEM), aiding in the analysis of security events.
- Clickhouse: This database technology will likely support data analysis related to security incidents or system performance.
- Gitlab: This platform may be used for version control of security automation scripts or process documentation.
- Python: This programming language will be utilized for scripting and automating SOC processes and response mechanisms.
- ELK: This stack (Elasticsearch, Logstash, Kibana) will be employed for log management and analysis during incident investigations.
- Wazuh: This security platform will be used for endpoint detection and response (EDR), intrusion detection, and security monitoring.
Who this role suits
- A person with a practical, hands-on approach to cybersecurity.
- Someone who enjoys investigating problems and finding solutions.
- An individual who can balance security requirements with operational performance needs.
- A professional committed to continuous improvement of security processes.
From the employer
- Upgrade SOC processes & response automation;
- Respond to cybersecurity incidents;
- Investigate security incidents and instigate remedial measures to address breaches;
- Immerse yourself in the specifics of systems and processes to achieve a balance of security and performance.
- Practice with SIEM, EDR, IDS/IPS, IRP/SOAR events analysis;
- Familiarity with SecOps processes, i.e., monitoring, triaging, investigating, and threat intelligence;
- More than one year of experience as an information security engineer/analyst;
- Strong investigative and analytical problem-solving skills;
- Intermediate or higher English level.
- Private insurance (depending on contract type);
- Paid gym membership;
- Comprehensive Mental Health Program;
- Free English lessons (online);
- Local language courses;
- +1 day off per calendar year;
- Referral program rewards;
- Upskilling, internal workshops, and participation in professional conferences and corporate events.
Questions about this role
What is the remote work policy for this role?
This is a fully remote position, allowing the successful candidate to work from any location.
What level of experience is required for this position?
This is a middle-seniority role, requiring more than one year of experience as an information security engineer or analyst.
What are the core responsibilities of this Incident Response Analyst role?
Key responsibilities include upgrading SOC processes, responding to and investigating cybersecurity incidents, and implementing remedial measures while balancing security with system performance.