Cyber Security Incident Responder
HybridBucharest, București, Romania
Job Summary
Investigate escalated security incidents and perform in-depth threat hunting, digital forensics, and log analysis across large-scale cross-platform environments using tools like SOAR, EDR, XDR, and SIEM. Coordinate incident response, escalation, and reporting while executing playbooks and runbooks to mitigate active threats and identify root causes. Collaborate with stakeholders and vendors to remediate security gaps and drive continuous improvements in detection tuning, automation, and operational processes. Own assigned projects focused on enhancing detection capabilities and standardizing CSIRT workflows while balancing complex operational workloads. Requires 5+ years of operational security experience, advanced technical skills in incident response and threat hunting, and proficiency in reading logs and technical evidence. Works on 16/5 shifts (7 AM - 10 PM) with on-call support for nights, weekends, and holidays in a hybrid setup.
Required Qualifications
- 5+ years of operational security experience (SOC, Incident Response, Malware Analysis, etc.)
- Advanced technology subject matter expertise in performing hands-on technical incident response, in-depth technical investigations and Threat Hunting
- Advanced experience in the world of hacking and defense and adversary techniques, all with a hands-on keyboard perspective
- Advanced experience working independently to detect, handle, investigate and effectively respond to cybersecurity incidents
- Advanced experience identifying adversary techniques, tactics, and procedures with enterprise security tools with a demonstrable understanding of modern attacker methodologies
- Advanced experience developing and maintaining operations playbooks, runbooks, and operational documentation
- Advanced experience with projects or issues of high complexity that require knowledge across multiple technical areas and business units
- Ability to assess security incidents quickly and communicate/coordinate a course of action to respond to the incident, while mitigating risk and limiting the impact
- Ability to read logs, collect technical evidence and put together the full picture
- Robust understanding of IT fundamentals across networking, system, cloud, virtualization platforms, application layers and advanced understanding of at least one operating system (Windows, Linux, OSX)
- Excellent English communication skills, both verbal and written, for professional communication and documentation
- Excellent interpersonal and communication skills to share knowledge and to communicate effectively with different stakeholders (IT and business partners)
- Highly disciplined and motivated: a self-starter who can both work independently or as a member of a team
- Ability to demonstrate a Can-Do, delivery-focused and solution-oriented approach (rather than problem-oriented)
- Flexible, practical, and positive mindset
- Ability to quickly adapt to changing situations
- Ability to constantly demonstrate ownership and proactiveness in seeking to improve and optimize in anything related to their and their team's work
- Works on shifts covering 16/5 (Monday to Friday, 7 AM - 10 PM)
- Offers on-call support during the nights, weekends and public holidays
Desired Qualifications
- Preferred: Bachelor's degree in computer science, Information Technology, Engineering or a related field
- Preferred education requirement: Bachelor's degree or equivalent experience and relevant certification (examples: CompTIA Security+, Network+, CySA+, CCNA, CCNA CyberOps, GCIH, GCFR, GEIR, GCIA, GCFA, GCFE, GSEC, GCED, GREM, OSCP, OSCE, and similar)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.