Cybersecurity Incident Responder
ВакансииSummary
Andersen is hiring a Cybersecurity Incident Responder for a project protecting critical systems and managing security incidents in a complex international environment.
The customer is a large international organization that relies on modern technology and digital solutions to support its operations. Its activities involve secure IT infrastructure, data management, digital services, and the adoption of emerging technologies to improve operational efficiency and reliability.
The project is focused on providing cybersecurity and digital services for international organizations within a complex multi-tenant environment. It includes cyber defense operations, security incident management, and continuous protection of critical systems and services to ensure secure and reliable operations worldwide.
Responsibilities
- Executing the full incident lifecycle: triage, containment, eradication, recovery and lessons learned.
- Performing digital forensics on endpoints, servers and cloud workloads (disk, memory, logs).
- Investigating escalated alerts from the SOC and determine the scope and impact of incidents.
- Coordinating response activities with affected client organizations, IT teams and management.
- Developing and maintaining IR playbooks and runbooks, and run tabletop exercises.
- Writing incident reports and rooting cause analyses, and recommend remediation.
- Taking part in on-call rotation (response within 15 minutes, system access within 1 hour).
Requirements
- Experience in cybersecurity for 5+ years, including 3+ years in hands-on incident response.
- Proven end-to-end handling of real incidents (e.g. ransomware, BEC, account compromise, data exfiltration).
- Hands-on EDR/XDR experience (e.g. Microsoft Defender for Endpoint, CrowdStrike, SentinelOne).
- Forensic tools and techniques: memory and disk analysis (e.g. Volatility, KAPE, Velociraptor, FTK/EnCase), Windows and Linux artifacts.
- Investigation in Microsoft 365, Entra ID and Azure environments.
- Strong knowledge of NIST SP 800-61 or SANS incident handling frameworks.
- Readiness for on-call rotation.
- Clean record, ready for background verification.
- Level of English – from Upper-Intermediate and above.
Desired skills
- Certifications: GCIH, GCFA, GCFE, GNFA, ECIH.
- Cloud forensics in AWS or GCP.
- Malware triage and basic reverse engineering.
- Scripting in Python or PowerShell.
- Experience in a MSSP or a multi-tenant environment.
Reasons to join us
- Experience in teamwork with leaders in FinTech, Healthcare, Retail, Telecom, and others. Andersen cooperates with such businesses as Samsung, Siemens, Johnson & Johnson, BNP Paribas, Ryanair, Mercedes, TUI, Verivox, Allianz, T-Systems, etc..
- The opportunity to change the project and/or develop expertise in an interesting business domain.
- Guarantee of professional, financial, and career growth! The company has introduced systems of mentoring and adaptation for each new employee.
- The opportunity to earn up to an additional 1,000 EUR per month, depending on the level of expertise, which will be included in the annual bonus, by participating in the company's activities.
- Access to the corporate training portal, where the entire knowledge base of the company is collected and which is constantly updated.
- Bright corporate life (parties / pizza days / PlayStation / fruits / coffee / snacks / movies).
- Certification compensation (AWS, PMP, etc).
- Referral program.
- Private health insurance and sports compensation, depending on the type of employment.
Join us!
Локации
Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Hungary, Italy, Latvia, Lithuania, Luxembourg, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, The Netherlands
Будем рады видеть вас!
Мы обрабатываем персональные данные по GDPR
Думаете о новом этапе в своей карьере? Загляните в вакансии Andersen и найдите свою сегодня