3,012 Open roles
109 Companies
81 Posted today
Jobs / SoftSwiss / Incident Response Analyst
Posted 2026-09-16

Incident Response Analyst

Description

SOFTSWISS is looking for an Incident Response Analyst to join its on-call incident response team. In this role, the analyst will respond to and investigate security incidents across the company, coordinate incident response with relevant teams, and help ensure timely and effective resolution of incidents.

The position operates on a 2-on-2-off shift pattern, encompassing a 12-hour day shift, a 12-hour night shift the next day, and 2 free days after that.

Responsibilities
  • Participation in security incident response
  • Performing basic primary incident response measures/triage
  • Execution (and monitoring of execution) of tasks assigned based on planning results
  • Development and updating of playbooks for alert verification
  • Monitoring alerts in compliance with SLA
  • Submitting proposals for optimizing tools and processes used
Requirements
  • Basic indicator of compromise (IoC) analysis skills using publicly available tools (VirusTotal, AnyRun, etc.) (required)
  • Experience working with Splunk/Clickhouse/SQL at the level of writing simple search queries and interpreting results (required)
  • Experience working with SOAR/IRP (required)
  • General understanding of current cyber threats and main attack methods (required)
  • Basic programming skills in Python, PowerShell, or Bash for automating routine tasks (required)
  • Knowledge of operating systems (Linux/Windows) at a junior system administrator level (required)
  • Understanding of the MITRE ATT&CK framework and Cyber Kill Chain (required)
  • Ability to analyze and process large volumes of data, including logs and triage (required)
  • Strong communication and teamwork skills: able to clearly articulate thoughts, ask relevant questions, and effectively collaborate with colleagues across different teams, especially during incident response (required)
  • Analytical and flexible mindset: able to approach issues from different perspectives, build logical chains, make informed decisions, and independently suggest solutions (required)
  • Proactivity and ownership: takes responsibility for decisions and results, double-checks own work, learns from mistakes and feedback, and actively develops professional skills (required)
  • Knowledge of information security best practices (NIST, ISO) and ability to cite them when necessary (nice-to-have)
  • Basic knowledge of Docker and Kubernetes, understanding their monitoring features (nice-to-have)
  • Experience writing correlation rules in SIEM (nice-to-have)
  • Experience with NTA (Network Traffic Analysis) tools (nice-to-have)
  • Experience working with online reputation services (VT, AnyRun, IPAbuseDB, etc.) (nice-to-have)
  • Experience developing instructions for alert verification and/or writing information security incident response scenarios (nice-to-have)
  • Experience with Kafka, ELK, Graylog, etc (nice-to-have)
  • Strong Linux system administration experience (nice-to-have)
  • Expertise in network, host, and cloud-based analysis and investigation (nice-to-have)
  • A strong understanding of attack pipelines (MITRE ATT&CK Framework, Cyber Kill-Chain) (nice-to-have)
  • Familiarity with CI/CD, software development lifecycle, and Infrastructure-as-Code (Terraform/Ansible/etc) (nice-to-have)
  • Proficiency in automation (Bash/PowerShell, Python) (nice-to-have)
  • Experience with log collection, delivery, and normalization (nice-to-have)
  • Strong knowledge of open-source solutions for endpoint & infrastructure security, such as Audit.d, Sysmon, AppArmor, SELinux, etc (nice-to-have)
  • Fundamental static and dynamic malware analysis skills (nice-to-have)
  • Offensive experience (penetration testing, red teaming) (nice-to-have)
Benefits
  • Private health insurance
  • Sports benefits
  • Comprehensive Mental Health Program
  • Free English lessons (online)
  • Local language courses
  • Paid time off
  • Maternity leave support
  • Referral program rewards
  • Upskilling, internal workshops, and participation in professional conferences and corporate events
About SoftSwiss

SOFTSWISS is a global tech expert with over 15 years of experience in providing innovative iGaming solutions. The company offers comprehensive software for online casinos, sports betting, and affiliate management. To expand its global presence, in 2024, SOFTSWISS acquired Turfsport, a leading South African betting software provider, and a significant stake in Ously Games GmbH, the company behind the fastest-growing European social casino, SpinArena.net. Additionally, the company appointed Formula 1 legend Rubens Barrichello as Non-Executive Director in Latin America, focusing on Brazil's growing market. SOFTSWISS is committed to transforming the iGaming and entertainment industry for the better through tech innovations. The Team helps operators and providers establish enduring partnerships by building profitable and scalable businesses.

Read more about SoftSwiss →

Apply on SoftSwiss →