Incident Response Analyst

Posted Yesterday
Be an Early Applicant
Hiring Remotely in T'bilisi, GEO
Remote
Entry level
Blockchain • Gaming • Payments • Software
The Role
Respond to, triage, investigate, and coordinate resolution of security incidents in an on-call shift environment. Monitor alerts against SLAs, analyze indicators of compromise and logs, execute incident response tasks, maintain alert-verification playbooks, and recommend process or tooling improvements. The role requires familiarity with SIEM and SOAR/IRP platforms, cyber threats, operating systems, scripting, MITRE ATT&CK, and Cyber Kill Chain frameworks.
Summary Generated by Built In
Overview:

SOFTSWISS is looking for an Incident Response Analyst to join our on-call incident response team. In this role, you will respond to and investigate security incidents across the company, coordinate incident response with relevant teams, and help ensure timely and effective resolution of incidents.

Key responsibilities:
  • Participation in security incident response

  • Performing basic primary incident response measures/triage

  • Execution (and monitoring of execution) of tasks assigned based on planning results

  • Development and updating of playbooks for alert verification

  • Monitoring alerts in compliance with SLA

  • Submitting proposals for optimizing tools and processes used

  • The position operates on a 2-on-2-off shift pattern, encompassing a 12-hour day shift, a 12-hour night shift the next day, and 2 free days after that

Required Experience:
  • Basic indicator of compromise (IoC) analysis skills using publicly available tools (VirusTotal, AnyRun, etc.)

  • Experience working with Splunk/Clickhouse/SQL at the level of writing simple search queries and interpreting results

  • Experience working with SOAR/IRP

  • General understanding of current cyber threats and main attack methods

  • Basic programming skills in Python, PowerShell, or Bash for automating routine tasks

  • Knowledge of operating systems (Linux/Windows) at a junior system administrator level

  • Understanding of the MITRE ATT&CK framework and Cyber Kill Chain

  • Ability to analyze and process large volumes of data, including logs and triage

  • Strong communication and teamwork skills: able to clearly articulate thoughts, ask relevant questions, and effectively collaborate with colleagues across different teams, especially during incident response

  • Analytical and flexible mindset: able to approach issues from different perspectives, build logical chains, make informed decisions, and independently suggest solutions

  • Proactivity and ownership: takes responsibility for decisions and results, double-checks own work, learns from mistakes and feedback, and actively develops professional skills

Nice to have:
  • Knowledge of information security best practices (NIST, ISO) and ability to cite them when necessary

  • Basic knowledge of Docker and Kubernetes, understanding their monitoring features

  • Experience writing correlation rules in SIEM

  • Experience with NTA (Network Traffic Analysis) tools

  • Experience working with online reputation services (VT, AnyRun, IPAbuseDB, etc.)

  • Experience developing instructions for alert verification and/or writing information security incident response scenarios

  • Experience with Kafka, ELK, Graylog, etc

  • Strong Linux system administration experience

  • Expertise in network, host, and cloud-based analysis and investigation

  • A strong understanding of attack pipelines (MITRE ATT&CK Framework, Cyber Kill-Chain)

  • Familiarity with CI/CD, software development lifecycle, and Infrastructure-as-Code (Terraform/Ansible/etc)

  • Proficiency in automation (Bash/PowerShell, Python)

  • Experience with log collection, delivery, and normalization

  • Strong knowledge of open-source solutions for endpoint & infrastructure security, such as Audit.d, Sysmon, AppArmor, SELinux, etc

  • Fundamental static and dynamic malware analysis skills

  • Offensive experience (penetration testing, red teaming)

Our Benefits:
  • Private health insurance

  • Sports benefits

  • Comprehensive Mental Health Program

  • Free English lessons (online)

  • Local language courses

  • Paid time off

  • Maternity leave support

  • Referral program rewards

  • Upskilling, internal workshops, and participation in professional conferences and corporate events

Skills Required

  • Basic indicator of compromise analysis using publicly available tools such as VirusTotal and Any.Run
  • Experience writing simple search queries and interpreting results in Splunk, ClickHouse, or SQL
  • Experience working with SOAR or IRP platforms
  • General understanding of current cyber threats and common attack methods
  • Basic programming skills in Python, PowerShell, or Bash for task automation
  • Junior system administrator-level knowledge of Linux and Windows operating systems
  • Understanding of the MITRE ATT&CK framework and Cyber Kill Chain
  • Ability to analyze and process large volumes of logs and triage data
  • Strong communication, teamwork, analytical thinking, flexibility, initiative, and ownership
  • Knowledge of information security best practices including NIST and ISO
  • Basic knowledge of Docker and Kubernetes monitoring features
  • Experience writing SIEM correlation rules
  • Experience with Network Traffic Analysis tools
  • Experience with online reputation services such as VirusTotal, Any.Run, and IPAbuseDB
  • Experience developing alert-verification instructions or incident response scenarios
  • Experience with Kafka, ELK, or Graylog
  • Strong Linux system administration experience
  • Expertise in network, host, and cloud-based analysis and investigation
  • Familiarity with CI/CD, software development lifecycle, and Infrastructure-as-Code tools such as Terraform or Ansible
  • Proficiency in Bash, PowerShell, or Python automation
  • Experience with log collection, delivery, and normalization
  • Knowledge of endpoint and infrastructure security tools including Auditd, Sysmon, AppArmor, and SELinux
  • Fundamental static and dynamic malware analysis skills
  • Offensive security experience including penetration testing or red teaming
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
2,000 Employees
Year Founded: 2009

What We Do

SOFTSWISS is a global iGaming technology provider offering a comprehensive ecosystem of software solutions for online casinos and sportsbooks. The company specializes in B2B solutions, including a Casino Platform, Game Aggregator, and Sportsbook Platform, as well as the Affilka affiliate marketing tool. They provide turnkey and white-label services, enabling operators to efficiently launch and manage their gambling businesses worldwide.

Similar Jobs

Academy of Digital Industries Logo Academy of Digital Industries

Social Media Specialist

Digital Media • Edtech • Design
Remote
GEO
150 Employees

SOFTSWISS Logo SOFTSWISS

Partnership Reconciliation Manager - Junior

Blockchain • Gaming • Payments • Software
In-Office or Remote
2 Locations
2000 Employees

SOFTSWISS Logo SOFTSWISS

Email Marketing Manager

Blockchain • Gaming • Payments • Software
In-Office or Remote
6 Locations
2000 Employees

SOFTSWISS Logo SOFTSWISS

First Line Support Specialist - Junior

Blockchain • Gaming • Payments • Software
Remote
T'bilisi, GEO
2000 Employees

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account