← Back to jobs

Stefanini IT Solutions Logo
Cyber Security Services Incident Response Analyst

Stefanini IT Solutions

 

Bucharest, Romania

Posted On: Just posted
Experience: 10+ years
Availability: Remote
Openings: 1
Category: Cyber Security Specialist
Tenure: No Preference/Any
Related Jobs

No related jobs found

Description

Job responsibilities: 

  • Own assigned security alerts, incidents, and escalated tickets by conducting triage, cross-source investigations, and response activities across endpoints, identities, email, networks, cloud environments, and other relevant data sources using available security telemetry and investigation platforms.
  • Analyze endpoint activity to identify indicators of compromise and adversary behaviors, including malicious execution, persistence, privilege escalation, and lateral movement.
  • Investigate suspicious user and identity activity by analyzing Microsoft Entra ID authentication logs, sign-in activity, access patterns, anomalies, and other identity-related telemetry.
  • Use SentinelOne Singularity Data Lake and SDL PowerQuery to perform advanced searches, correlate events, analyze threats, and support security investigations.
  • Develop and validate investigation hypotheses using structured incident response, threat hunting, and forensic analysis methodologies.
  • Execute containment, eradication, and recovery activities while coordinating with relevant technology owners and stakeholders to validate findings, contain threats, and restore affected services in accordance with approved incident response procedures and playbooks.
  • Document investigative actions, evidence, analysis, decisions, communications, containment measures, and recovery activities throughout the incident lifecycle.
  • Prepare detailed P1 and P2 incident reports covering the incident timeline, root cause, impact assessment, actions taken, current status, and lessons learned.
  • Provide metrics and analysis on mean time to acknowledge, investigate, and resolve incidents by severity and lifecycle stage.
  • Provide feedback on detection logic, alert quality, false positives, telemetry gaps, and monitoring improvement, recommending rule-tuning adjustments and new detection use cases based on emerging threats, vulnerabilities, observed activity, and attack patterns.
  • Produce weekly operational reports on alert volumes and status, operational trends, investigation outcomes, false-positive rates by detection source.
  • Participate in security operations meetings and present incident findings, operational trends, detection performance, service-level results, and improvement recommendations.
  • Identify security gaps, recommend mitigation measures, and support SOAR automation workflows by providing operational feedback and identifying suitable automation opportunities to enhance operational efficiency.
  • Contribute to the development, maintenance, and refinement of standard operating procedures, incident response playbooks, investigation guides, workflows, and process documentation.
  • Support monthly security tool and log-source health checks by validating data availability, alert coverage, and investigation readiness.
  • Collaborate with security analysts, incident responders, threat hunters, technology owners, and stakeholders across multiple teams and time zones to implement security best practices.
  • Provide technical guidance, coaching, and mentoring to junior analysts, fostering a collaborative and learning-focused environment.

 

Job Requirements

 

Education:

  • Preferred: Bachelor's degree in computer science, Information Technology, Engineering, or a related field.
  • Minimum education requirement: High school studies completed with Baccalaureate diploma.

Language proficiency:

  • Excellent English communication skills, both verbal and written, for professional communication and documentation.

Experience:

  • Minimum 3 years of experience in cybersecurity operations, including hands-on experience investigating and responding to security incidents across endpoints, network, cloud, and other technology environments.
  • Demonstrated experience working in a Security Operations Center, Global Security Operations Center, Managed Security Service, or similar 24/7 operational environment.

Mandatory Technical Skills:

  • Strong understanding of cybersecurity principles, incident response methodologies, structured threat hunting and basic digital forensics.
  • Strong knowledge of industry frameworks and best practices, including NIST incident response guidance and structured threat hunting methodologies.
  • Hands-on proficiency with SentinelOne Singularity Data Lake (SDL), including PowerQuery for investigation, event correlation, and threat analysis.
  • Proficiency with Microsoft Entra ID and security technologies such as SIEM, SEG, EDR, XDR, and NDR.
  • Familiarity with SOAR platforms and security automation concepts.
  • Ability to develop and maintain standard operating procedures, incident response playbooks, workflows, and technical documentation.

Preferred / Nice-to-Have Qualifications:

  • Hands-on certifications in incident response, forensics, threat hunting, or malware analysis - for example GCIH, GCFA, GCDA, GREM, ECIH, CySA+, eCTHP, CDSA, or OSCP. Equivalent practical evidence (published research, open-source detection contributions) is weighted equally. 

Professional Skills:

  • Ability to perform effectively during crises, make sound decisions, recommend effective solutions, and manage competing priorities during security incidents.
  • Ability to work effectively in a complex global environment involving multiple entities, varying levels of IT maturity, and diverse regulatory requirements.
  • Strong communication and collaboration skills, enabling effective interaction with a diverse range of technical and non-technical stakeholders and internal teams.
  • A customer-focused mindset dedicated to delivering exceptional service.
  • A collaborative mindset with an interest in internal operations and process improvement.
  • Strong organizational, attention to detail, analytical thinking and a proactive approach to problem-solving.
  • Ability to quickly adapt to changes, new requirements, or sudden shifts in direction.
  • A commitment to continuous learning and improvement, staying abreast of industry best practices, emerging technologies, and methodologies.
  • Absolute discretion and integrity in handling sensitive customer information and critical infrastructure data.
  • Availability for on-call responsibilities, if required

Education

Any Graduate

Related Jobs

No related jobs found

← Back to jobs