# Incident Response Analyst

**Company:** [Talentgrator](http://jobs.workable.com/companies/xsrZynjHYh6UW7LTSXNEJc.md)
**Location:** Remote
**Workplace:** remote
**Employment type:** Full-time
**Department:** Saas Platform| iGaming

[Apply for this job](http://jobs.workable.com/view/5f80898e-4522-44b2-ba5b-e8f4290fba4a)

## Description

Talentgrator is a recruitment and talent partner focused on the IT entertainment and iGaming sectors, connecting businesses with specialized professionals. We work with teams that need strong technical expertise and dependable execution in fast-moving environments where security, resilience, and operational discipline matter every day.

We are looking for an **Incident Response Analyst** to join our Security team and operate on the front line of protecting the company’s infrastructure and services. In this role, you will analyze security events, investigate suspicious activity, and work with infrastructure and security data to identify and respond to potential threats.

### Purpose of the role

You will be responsible for analyzing security events and raw logs, investigating suspicious activity, and supporting incident response processes.

We're looking for someone who has a good understanding of how infrastructure works and can **read and interpret raw technical data**, connect events from different sources, identify anomalies, and determine what may have happened during a security incident.

### Responsibilities

-   Work with WAF to analyze anomalous traffic, respond to web attacks, and fine-tune rules.
-   Work with DLP and MDM to investigate data leaks, analyze policy violations, and collaborate with teams on findings.
-   Monitor and triage alerts in SIEM, analyzing events, classifying incidents, and prioritizing response.
-   Integrate raw log sources into SIEM, including normalization, parsing, and enrichment.
-   Develop and improve detection rules, correlation rules, and dashboards.
-   Reduce MTTR by identifying bottlenecks in response processes and implementing automation and runbooks.
-   Participate in incident post-mortems and provide actionable recommendations.
-   Conduct security incident investigations by collecting artifacts, reconstructing timelines, and performing root cause analysis.

## Requirements

### What We Expect

-   **3+ years of experience in Security Operations, SOC, Incident Response, Infrastructure Security, or a similar technical role.**
-   Ability to **read and interpret raw logs** and understand what different system and application events represent.
-   Good understanding of **Linux and Windows** operating systems.
-   Good understanding of **networking fundamentals** and common network protocols.
-   Hands-on experience with **SIEM platforms**, preferably Splunk or similar technologies.
-   Ability to investigate security events by correlating information from different log sources.
-   Understanding of common cybersecurity threats, attacker techniques, and **IOC/TTP concepts**.
-   Familiarity with **Active Directory** and enterprise infrastructure.
-   Understanding of **Kubernetes and Docker** environments.
-   Basic scripting experience with **Python, PowerShell, or Bash**.
-   Understanding of **Terraform and Ansible** and how they are used for infrastructure automation and configuration management.
-   Strong analytical and troubleshooting skills.

### Nice to Have

-   Experience with **WAF, DLP, MDM, EDR/XDR**, or similar security technologies.
-   Experience with Threat Hunting or Network Traffic Analysis.
-   Experience writing or tuning SIEM detection rules.
-   Experience with **SOAR** or security automation.
-   Experience with cloud infrastructure and cloud logs.
-   Experience with APIs and automation.
-   Participation in Red Team, Blue Team, Purple Team exercises, CTFs, or penetration testing.

## Benefits

-   25 vacation days and 5 family days yearly
-   Flexible start to the workday
-   Support from a professional corporate coach and psychologist
-   Regular internal and external activities, workshops, trips, and corporate events
-   Access to our internal knowledge base, meetups, and team-building activities
-   Ongoing training in new technologies and continuous professional development support
