Incident Response Analyst
Tasks
- Analyze MDM policy violations
- Analyze anomalous traffic for web attacks
- Analyze logs from operating systems networks and applications
- Analyze policy violations and collaborate on findings
- Build detection logic
- Classify and prioritize incidents
- Collect forensic artifacts and reconstruct timelines
- Conduct incident investigations
- Create dashboards
- Develop detection rules and correlation rules
- Fine-tune WAF rules
- Integrate and normalize log sources in SIEM
- Investigate data leaks with DLP
- Investigate security incidents
- Monitor and triage SIEM alerts
- Participate in incident post mortems and recommend improvements
- Perform network traffic analysis
- Perform root cause analysis
- Reduce MTTR with automation and runbooks
- Reduce response time
Perks/Benefits
- Continuous professional development support
- Corporate coaching
- Family days
- Flexible start time
- Internal workshops and events
- Ongoing training
- Paid vacation days
- Psychologist support
- Team-building activities
- Trips and corporate events
Skills/Tech-stack
AWS CloudTrail | Audit Logs | Automation | Bash | Cause analysis | CrowdStrike | DLP | EDR | EDR XDR Threat Detection | EDR/XDR | Elasticsearch | GCP Audit Logs | GCP audit | Graylog | Incident Response | Linux | Linux forensics | Log Analysis | MDM | MTTR | MacOS | Mitre Attack | Network Protocols | OpenSearch | Playbooks | Python | Root Cause Analysis | Root cause | SIEM | SOAR | Security APIs | Security operations | SentinelOne | Splunk | Threat detection | Traffic analysis | WAF | Windows | Windows forensics | Wireshark | XDR | Zeek
Education
N/A
Related jobs
-
Threat Detection and Response Specialist CZK 612K-684KAmazon Web Services | Automation | Cloud Security | Detection engineering | English communicationAnnual bonus | Flexible working hours | Paid education and development training | Paid overtime | Paid technical certificationsSenior-level Full TimePraha - Hvezdova 1734/2c, Czechia R13d ago
-
Cloud Security Analyst CZK 915K-1400KAWS | AWS GuardDuty | Admission controls | CI/CD | Cloud ForensicsHome office stipend | Manager training | PTO | Paid parental leave | Professional development coursesSenior-level Full TimeCzech Republic R19d ago
-
Security Analyst EUR 61K-89KAccess Management | Alert Tuning | CNAPP | Cloud Native | Cloud SecurityCompany share program | Flexible hybrid working | Healthcare allowance | Home office setup budget | Parental leaveEntry-level Full TimeCzechia; Spain R1mo ago