Cyber Security Incident Responder
HybridBucharest, București, Romania
Job Summary
Investigate incidents escalated by the 24/7 Triage & Monitoring team and perform in-depth technical investigations on complex security alerts using tools like SOAR, EDR, XDR, SIEM, and Cloud Security. Conduct threat hunting, log analysis, and digital forensics to identify intrusions, determine root causes, and coordinate response and mitigation for active threats. Define and maintain CSIRT playbooks, runbooks, and operational documentation while collaborating with stakeholders to remediate security gaps and improve detection capabilities. Drive continuous improvements in response efficiency and own assigned projects balancing execution with daily operations. Works on a 16/5 shift schedule with on-call support for nights, weekends, and holidays in a hybrid setup.
Required Qualifications
- Bachelor's degree in computer science, Information Technology, Engineering or a related field
- Bachelor's degree or equivalent experience and relevant certification (examples: CompTIA Security+, Network+, CySA+, CCNA, CCNA CyberOps, GCIH, GCFR, GEIR, GCIA, GCFA, GCFE, GSEC, GCED, GREM, OSCP, OSCE, and similar)
- 5+ years of operational security experience (SOC, Incident Response, Malware Analysis, etc.)
- Advanced technology subject matter expertise in performing hands-on technical incident response, in-depth technical investigations and Threat Hunting
- Advanced experience in the world of hacking and defense and adversary techniques, all with a hands-on keyboard perspective
- Advanced experience working independently to detect, handle, investigate and effectively respond to cybersecurity incidents
- Advanced experience identifying adversary techniques, tactics, and procedures with enterprise security tools with a demonstrable understanding of modern attacker methodologies
- Advanced experience developing and maintaining operations playbooks, runbooks, and operational documentation
- Advanced experience with projects or issues of high complexity that require knowledge across multiple technical areas and business units
- Ability to assess security incidents quickly and communicate/coordinate a course of action to respond to the incident, while mitigating risk and limiting the impact
- Ability to read logs, collect technical evidence and put together the full picture
- Robust understanding of IT fundamentals across networking, system, cloud, virtualization platforms, application layers and advanced understanding of at least one operating system (Windows, Linux, OSX)
- Excellent English communication skills, both verbal and written, for professional communication and documentation
- Excellent interpersonal and communication skills to share knowledge and to communicate effectively with different stakeholders (IT and business partners)
- Highly disciplined and motivated: a self-starter who can both work independently or as a member of a team
- Ability to demonstrate a Can-Do, delivery-focused and solution-oriented approach (rather than problem-oriented)
- Flexible, practical, and positive mindset
- Ability to quickly adapt to changing situations
- Ability to constantly demonstrate ownership and proactiveness in seeking to improve and optimize in anything related to their and their team's work
- Works on shifts covering 16/5 (Monday to Friday, 7 AM - 10 PM)
- Offers on-call support during the nights, weekends and public holidays
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.