Incident Response Analyst L2
SOFTSWISS is looking for an Incident Response Analyst (L2) to join its Security Operations team. In this role, the analyst will investigate complex security incidents, handle L1 escalations, and help improve the organisation's detection and incident response capabilities.
The purpose of the role is to investigate complex cybersecurity incidents, handle escalations from L1, and enhance the SOC detection and incident response capabilities. The ideal candidate will have an incident-driven mindset, capable of analysing attack chains, validating hypotheses, and making evidence-based decisions to effectively identify, investigate, and contain security threats.
- Investigate and respond to complex security incidents throughout the entire incident lifecycle.
- Perform digital forensic investigations, malware analysis, and evidence collection to determine the scope and root cause of security incidents.
- Analyze attack techniques, correlate security events, and reconstruct attack timelines.
- Develop and improve SIEM detections, correlation rules, and incident response playbooks.
- Conduct threat hunting activities and reduce false positives through detection tuning.
- Automate repetitive SOC activities using scripting where appropriate.
- Collaborate with Infrastructure, Development, IT, and Security teams during incident response.
- Mentor L1 analysts by providing technical guidance and feedback.
- 3+ years of experience in SOC, Incident Response, DFIR, or MSSP environments (required).
- Strong understanding of modern cyber threats, attack techniques, and frameworks such as MITRE ATT&CK and the Cyber Kill Chain (required).
- Hands-on experience investigating security incidents, performing digital forensics, and malware analysis (required).
- Hands-on experience with SIEM platforms (e.g. Splunk, Wazuh, ClickHouse, Redash), including writing complex search queries, correlating events, and investigating large volumes of security data (required).
- Good understanding of enterprise infrastructure, including Windows, Linux, macOS, Active Directory, email systems, Kubernetes, Docker, and databases (required).
- Experience with automation using Python, PowerShell, or Bash (required).
- Knowledge of Kubernetes and Docker security concepts (required).
- Strong analytical mindset, problem-solving skills, and effective communication in cross-functional environments (required).
- Intermediate or higher English level and strong command of Russian (required).
- Experience with Threat Hunting, Network Traffic Analysis (NTA), or cloud security (AWS) (nice-to-have).
- Familiarity with CI/CD and Infrastructure as Code (e.g. Terraform, Ansible) (nice-to-have).
- Participation in Red Team or Purple Team exercises (nice-to-have).
- Industry certifications such as GCIA, GCIH, GCED, OSCP, CEH, or Splunk certifications (nice-to-have).
- Familiarity with security frameworks such as NIST (nice-to-have).
- Private health insurance
- Sports benefits
- Comprehensive Mental Health Program
- Free English lessons (online)
- Local language courses
- Paid time off
- Maternity leave support
- Referral program rewards
- Upskilling, internal workshops, and participation in professional conferences and corporate events
SOFTSWISS is a global tech expert with over 15 years of experience in providing innovative iGaming solutions. The company offers comprehensive software for online casinos, sports betting, and affiliate management. To expand its global presence, in 2024, SOFTSWISS acquired Turfsport, a leading South African betting software provider, and a significant stake in Ously Games GmbH, the company behind the fastest-growing European social casino, SpinArena.net. Additionally, the company appointed Formula 1 legend Rubens Barrichello as Non-Executive Director in Latin America, focusing on Brazil's growing market. SOFTSWISS is committed to transforming the iGaming and entertainment industry for the better through tech innovations. The Team helps operators and providers establish enduring partnerships by building profitable and scalable businesses.
