
1001 - 5000 employees
đź Consulting
đŁ Marketing
đŽ Gaming
Consulting ⢠Marketing ⢠Gaming
SOFTSWISS is a leading provider of iGaming software solutions, offering a wide range of products including iGaming Platform, Sportsbook Platform, Game Aggregator, Jackpot Aggregator, and more. Established in 2009, SOFTSWISS has grown to employ over 1,700 people across 4 international offices in Poland, Georgia, Malta, and several remote locations. The company is known for its innovation in the iGaming industry, being the first Crypto iGaming provider in the world. SOFTSWISS not only promotes a dynamic and flexible work culture with comprehensive employee benefits but also commits to social responsibility by supporting various campaigns and initiatives.
đĽ 18 hours ago
đŹđŞ Georgia â Remote
â° Full Time
đĄ Mid-level
đ Senior
đ¨ Incident Response Analyst
đť Ghost score 10%
Improve your chances of getting an interview by checking your resume score before you apply.

1001 - 5000 employees
đź Consulting
đŁ Marketing
đŽ Gaming
Consulting ⢠Marketing ⢠Gaming
SOFTSWISS is a leading provider of iGaming software solutions, offering a wide range of products including iGaming Platform, Sportsbook Platform, Game Aggregator, Jackpot Aggregator, and more. Established in 2009, SOFTSWISS has grown to employ over 1,700 people across 4 international offices in Poland, Georgia, Malta, and several remote locations. The company is known for its innovation in the iGaming industry, being the first Crypto iGaming provider in the world. SOFTSWISS not only promotes a dynamic and flexible work culture with comprehensive employee benefits but also commits to social responsibility by supporting various campaigns and initiatives.
⢠Participate in security incident response ⢠Perform basic primary incident response measures and triage ⢠Execute and monitor tasks assigned based on planning results ⢠Develop and update playbooks for alert verification ⢠Monitor alerts in compliance with SLA ⢠Submit proposals for optimizing security tools and processes ⢠Respond to and investigate security incidents across the company ⢠Coordinate incident response with relevant teams ⢠Help ensure timely and effective resolution of incidents ⢠Work on a 2-on-2-off shift pattern with a 12-hour day shift, a 12-hour night shift the next day, and 2 free days afterward
⢠Basic indicator of compromise (IoC) analysis skills using publicly available tools (VirusTotal, AnyRun, etc.) ⢠Experience working with Splunk/Clickhouse/SQL at the level of writing simple search queries and interpreting results ⢠Experience working with SOAR/IRP ⢠General understanding of current cyber threats and main attack methods ⢠Basic programming skills in Python, PowerShell, or Bash for automating routine tasks ⢠Knowledge of operating systems (Linux/Windows) at a junior system administrator level ⢠Understanding of the MITRE ATT&CK framework and Cyber Kill Chain ⢠Ability to analyze and process large volumes of data, including logs and triage ⢠Strong communication and teamwork skills, including collaboration across different teams during incident response ⢠Analytical and flexible mindset; ability to build logical chains, make informed decisions, and suggest solutions independently ⢠Proactivity and ownership, including responsibility for decisions and results, learning from feedback, and professional development ⢠Nice to have: Knowledge of information security best practices (NIST, ISO) ⢠Nice to have: Basic knowledge of Docker and Kubernetes and their monitoring features ⢠Nice to have: Experience writing correlation rules in SIEM ⢠Nice to have: Experience with NTA tools ⢠Nice to have: Experience with online reputation services (VT, AnyRun, IPAbuseDB, etc.) ⢠Nice to have: Experience developing alert-verification instructions or information security incident response scenarios ⢠Nice to have: Experience with Kafka, ELK, Graylog, etc. ⢠Nice to have: Strong Linux system administration experience ⢠Nice to have: Expertise in network, host, and cloud-based analysis and investigation ⢠Nice to have: Strong understanding of attack pipelines (MITRE ATT&CK Framework, Cyber Kill-Chain) ⢠Nice to have: Familiarity with CI/CD, software development lifecycle, and Infrastructure-as-Code (Terraform/Ansible/etc.) ⢠Nice to have: Proficiency in automation (Bash/PowerShell, Python) ⢠Nice to have: Experience with log collection, delivery, and normalization ⢠Nice to have: Strong knowledge of open-source endpoint and infrastructure security solutions, such as Audit.d, Sysmon, AppArmor, and SELinux ⢠Nice to have: Fundamental static and dynamic malware analysis skills ⢠Nice to have: Offensive experience (penetration testing, red teaming)
⢠Private health insurance ⢠Sports benefits ⢠Comprehensive Mental Health Program ⢠Free English lessons (online) ⢠Local language courses ⢠Paid time off ⢠Maternity leave support ⢠Referral program rewards ⢠Upskilling, internal workshops, and participation in professional conferences and corporate events
Apply Now