WorkaemКарьерная платформа
  • Вакансии
  • Компании
  • Зарплаты
  • Офферы
  • Сервисы
  • Блог
  • Работодателям
Workaem

Карьерная платформа для IT-специалистов: вакансии напрямую с карьерных страниц 300+ компаний, из телеграм-каналов, с международных площадок и от работодателей напрямую. Разбор условий, детектор мёртвых вакансий, AI-инструменты для резюме. Базовые функции бесплатны.

Подпишись, присылаем лучшие вакансии недели
Или читай канал в телеграме
Соискателям
Все вакансииЗа границейУдалёнка в долларахКомпании с РУ основателямиЗарплатыОфферыВозможностиСоветыСоздать резюмеТренировка интервью
По технологиям
Вакансии PythonВакансии JavaScriptВакансии ReactВакансии JavaВакансии GoВакансии Docker
По профессиям
РазработкаДизайнQA / ТестированиеАналитикаProduct / Project ManagerМаркетинг
Работодателям
Разместить вакансиюТарифыБаза кандидатовСвязаться с нами
Кабинет
РегистрацияВойтиЛичный кабинетМои откликиСохранённыеУведомления
Компания
О проектеПредложенияКонтактыБлогКонфиденциальностьУсловия использования
© 2026 Workaem. Все права защищены.КонфиденциальностьУсловияОферта
Made by IT, for IT 💛
Incident Response Analyst (L2)
ВердиктОписаниеИнструментыКомпанияПохожие
  1. Главная
  2. /
  3. Вакансии
  4. /
  5. Incident Response Analyst (L2)

Название скрыто (Сфера развлечений) ·Весь мир·19 авг.

Incident Response Analyst (L2)

3 000 – 5 500 €
≈ 301,9 тыс.–553,4 тыс. ₽
🌍 УдалённоMiddleПолная занятостьАнглийский B1
3 000 – 5 500 €≈ 301,9 тыс.–553,4 тыс. ₽
86
Сильная вакансия
Платят на 40% выше медианы грейда, навык востребован (Python).
Нажмите на сигнал, чтобы увидеть, на чём он основан

Описание вакансии

Work format: remote from anywhere in the world or from one of our European offices. The company hires specialists who have already relocated from Russia/Belarus.

An Incident Response Analyst (L2) is required to join our Security Operations team. In this role, you will investigate complex security incidents, handle L1 escalations, and help improve our detection and incident response capabilities.

Purpose of the role

You will be responsible for investigating complex cybersecurity incidents, handling escalations from L1, and enhancing our SOC detection and incident response capabilities.

We're looking for someone with an incident-driven mindset who can analyze attack chains, validate hypotheses, and make evidence-based decisions to effectively identify, investigate, and contain security threats.

Key responsibilities

Investigate and respond to complex security incidents throughout the entire incident lifecycle.
Perform digital forensic investigations, malware analysis, and evidence collection to determine the scope and root cause of security incidents.
Analyze attack techniques, correlate security events, and reconstruct attack timelines.
Develop and improve SIEM detections, correlation rules, and incident response playbooks.
Conduct threat hunting activities and reduce false positives through detection tuning.
Automate repetitive SOC activities using scripting where appropriate.
Collaborate with Infrastructure, Development, IT, and Security teams during incident response.
Mentor L1 analysts by providing technical guidance and feedback.

Required Experience

3+ years of experience in SOC, Incident Response, DFIR, or MSSP environments.
Strong understanding of modern cyber threats, attack techniques, and frameworks such as MITRE ATT&CK and the Cyber Kill Chain.
Hands-on experience investigating security incidents, performing digital forensics, and malware analysis.
Hands-on experience with SIEM platforms (e.g., Splunk, Wazuh, ClickHouse, Redash), including writing complex search queries, correlating events, and investigating large volumes of security data.
Good understanding of enterprise infrastructure, including Windows, Linux, macOS, Active Directory, email systems, Kubernetes, Docker, and databases.
Experience with automation using Python, PowerShell, or Bash.
Knowledge of Kubernetes and Docker security concepts.
Strong analytical mindset, problem-solving skills, and effective communication in cross-functional environments.
Intermediate or higher English level.
Nice to have
Experience with Threat Hunting, Network Traffic Analysis (NTA), or cloud security (AWS).
Familiarity with CI/CD and Infrastructure as Code (e.g., Terraform, Ansible).
Participation in Red Team or Purple Team exercises.
Industry certifications such as GCIA, GCIH, GCED, OSCP, CEH, or Splunk certifications.
Familiarity with security frameworks such as NIST.

Технологии и навыки

Windows
Linux
Kubernetes
Docker
Python
PowerShell
Bash
SIEM
Splunk
ClickHouse
Redash
macOS
Active Directory
Название скрыто (Сфера развлечений)
Название скрыто (Сфера развлечений)
Весь мир

ГрейдMiddle
ЗанятостьПолная занятость
РегионРоссия
ФорматУдалённо
ИсточникСкрыто
Опубликовано19 авг.
Все вакансии компании

AI-помощник

под эту вакансию
Войди, чтобы AI оценил твоё соответствие вакансии и написал сопроводительное письмо

Похожие вакансии

Разработчик в команду геосервисов автономного транспортаЯндексQA Lead в команду AI-агентов (Python)2ГИСPenetration Tester (Middle)KPMGНачальник отдела администрирования автоматизированной системы взаимодействияБелорусский межбанковский расчетный центр
Мы против мошенников на площадке: если тебя просят заплатить, продиктовать код или установить непонятное приложение, прекращай общение и сразу пиши нам (чат с основателем или форма обратной связи).