Incident Response Analyst
Job Overview
Overview:
SOFTSWISS is looking for an Incident Response Analyst to join our on-call incident response team. In this role, you will respond to and investigate security incidents across the company, coordinate incident response with relevant teams, and help ensure timely and effective resolution of incidents.
Key responsibilities:
Participation in security incident response
Performing basic primary incident response measures/triage
Execution (and monitoring of execution) of tasks assigned based on planning results
Development and updating of playbooks for alert verification
Monitoring alerts in compliance with SLA
Submitting proposals for optimizing tools and processes used
The position operates on a 2-on-2-off shift pattern, encompassing a 12-hour day shift, a 12-hour night shift the next day, and 2 free days after that
Required Experience:
Basic indicator of compromise (IoC) analysis skills using publicly available tools (VirusTotal, AnyRun, etc.)
Experience working with Splunk/Clickhouse/SQL at the level of writing simple search queries and interpreting results
Experience working with SOAR/IRP
General understanding of current cyber threats and main attack methods
Basic programming skills in Python, PowerShell, or Bash for automating routine tasks
Knowledge of operating systems (Linux/Windows) at a junior system administrator level
Understanding of the MITRE ATT&CK framework and Cyber Kill Chain
Ability to analyze and process large volumes of data, including logs and triage
Strong communication and teamwork skills: able to clearly articulate thoughts, ask relevant questions, and effectively collaborate with colleagues across different teams, especially during incident response
Analytical and flexible mindset: able to approach issues from different perspectives, build logical chains, make informed decisions, and independently suggest solutions
Proactivity and ownership: takes responsibility for decisions and results, double-checks own work, learns from mistakes and feedback, and actively develops professional skills
Nice to have:
Knowledge of information security best practices (NIST, ISO) and ability to cite them when necessary
Basic knowledge of Docker and Kubernetes, understanding their monitoring features
Experience writing correlation rules in SIEM
Experience with NTA (Network Traffic Analysis) tools
Experience working with online reputation services (VT, AnyRun, IPAbuseDB, etc.)
Experience developing instructions for alert verification and/or writing information security incident response scenarios
Experience with Kafka, ELK, Graylog, etc
Strong Linux system administration experience
Expertise in network, host, and cloud-based analysis and investigation
A strong understanding of attack pipelines (MITRE ATT&CK Framework, Cyber Kill-Chain)
Familiarity with CI/CD, software development lifecycle, and Infrastructure-as-Code (Terraform/Ansible/etc)
Proficiency in automation (Bash/PowerShell, Python)
Experience with log collection, delivery, and normalization
Strong knowledge of open-source solutions for endpoint & infrastructure security, such as Audit.d, Sysmon, AppArmor, SELinux, etc
Fundamental static and dynamic malware analysis skills
Offensive experience (penetration testing, red teaming)
Our Benefits:
Private health insurance
Sports benefits
Comprehensive Mental Health Program
Free English lessons (online)
Local language courses
Paid time off
Maternity leave support
Referral program rewards
Upskilling, internal workshops, and participation in professional conferences and corporate events
Make Your Resume Now