Incident Response Analyst(Bucharest, RO)

Bucharest
Security, Engineering & Service Desk

Our mission is to help people integrate technology into everyday life and to enable innovation through technology. We offer software development and infrastructure solutions, with advanced competences in Blockchain, Artificial Intelligence and Machine Learning. All our offices (in Western Europe or nearshore, in CEE) are located within the boundaries of the European Union. We believe working in close cooperation with our clients and employees is the key to success; this means we offer people the best working environment in order to achieve the best results. We love entrepreneurial spirits and encourage people around us to be proactive and make the best decisions not only for business, but for their own personal development. Our nearshore Romanian offices are in Bucharest (Victoriei Square) and Iasi (Palace) and, with over 9000 team members at group level, we make sure we are always close to our customers. About the role: We are looking for a Cybersecurity Incident Responder to join a global Cyber Detection & Response environment supporting multiple international brands. The role is part of the L2 Incident Response team and works closely with both the L1 monitoring function and the Security Engineering team. You will investigate escalated security incidents, perform in-depth technical analysis and threat hunting, and contribute to the continuous improvement of detection and response capabilities. The environment covers multiple technologies and cloud platforms, with a strong focus on hands-on security operations, collaboration and continuous improvement. #LI-DNI

  • What you will be working on:
  • Investigation and response to cybersecurity incidents escalated by the L1 monitoring team.
  • Security alerts across EDR/XDR, SIEM, SOAR, IDS/IPS, Cloud Security, Email Security and Container Security platforms.
  • Threat hunting, log analysis and root cause investigation across complex enterprise environments.
  • Security monitoring across multi-cloud environments, including Microsoft Azure and Google Cloud Platform.
  • Cloud security visibility, vulnerabilities and misconfigurations using platforms such as Wiz.
  • Investigation and response activities using Microsoft Defender.
  • SecOps automation and workflow improvements using tools such as Tines / SOAR.
  • Detection tuning, proactive debugging and onboarding of new log and data sources.
  • Collaboration with Security Engineering teams and cybersecurity teams across different business brands.
  • Continuous improvement of incident response processes, playbooks and detection capabilities.
  • What you will do:
  • Investigate security incidents escalated by the monitoring and triage teams.
  • Perform hands-on technical investigations, log analysis and threat hunting.
  • Identify root causes and determine appropriate mitigation and response actions.
  • Coordinate incident response, escalation and reporting activities.
  • Investigate alerts generated by different enterprise security tools and correlate information across multiple data sources.
  • Work closely with Security Engineering on detection improvements, automation initiatives and technical enhancements.
  • Create and maintain playbooks, runbooks, workflows and operational documentation.
  • Identify opportunities to improve and standardize existing security processes.
  • Contribute to projects focused on detection tuning, automation and security capability improvements.
  • Collaborate with internal cybersecurity teams, technical stakeholders and external vendors.
  • Support Proof of Concept activities when evaluating or introducing new security tools and technologies.

What you need to succeed:

  • Strong professional experience in SOC, Incident Response, Cybersecurity Operations or similar areas.
  • Hands-on experience investigating and responding to cybersecurity incidents.
  • Experience with security technologies such as EDR/XDR, SIEM, SOAR, IDS/IPS or Cloud Security platforms.
  • Strong log analysis and technical investigation skills.
  • Good understanding of modern attacker tactics, techniques and procedures (TTPs).
  • Good understanding of IT fundamentals across networking, operating systems, virtualization, cloud and application environments.
  • Experience working with at least one major cloud platform; exposure to multiple cloud environments is considered an advantage.
  • Ability to independently assess security incidents and coordinate an appropriate response.
  • Experience creating or maintaining incident response procedures, playbooks or operational documentation.
  • Strong communication skills and the ability to work effectively with different technical and business stakeholders.
  • Proactive, solution-oriented mindset and strong ownership of assigned topics.
  • Ability to work both independently and as part of a highly collaborative security team.
  • Nice to Have:
  • Experience with Microsoft Defender.
  • Experience with Wiz or other CNAPP / Cloud Security platforms.
  • Experience with Tines or other SOAR technologies.
  • Experience with threat hunting, digital forensics or malware analysis.
  • Experience with detection engineering or detection tuning.
  • Experience working in complex, multi-cloud enterprise environments.
  • Relevant cybersecurity certifications such as Security+, CySA+, GCIH, GCIA, GCFA, OSCP or similar.
  • Working schedule:
  • The L2 Incident Response team works Monday to Friday in alternating daytime shifts:
  • 07:00 – 16:00
  • 13:00 – 22:00
  • There are no regular night shifts. The role also includes participation in an on-call rotation outside regular working hours.

What are we offering:

  • 22 working days as Annual Vacation plus 3 additional days off.
  • Floating days
  • Medical Insurance at Signal Iduna.
  • Benefit Online platform access, with a 690 RON monthly allowance from which you can choose to invest in different wellbeing, financial or retail packages.
  • Company performance-based annual bonus prorated according to the number of worked months in a year
  • Financial support for the birth of your child or unhappy events.
  • Learning and development opportunities - allocated budget for certifications and/or trainings.
In Cegeka you see how a family-based company truly brings family principles to all its activities.

Anca Udroiu

Project Manager, Cegeka Romania

Application flow

Do you have any questions about this role?

Let's connect.