Stop applying to jobs that are already dead.
Every listing verified, aged honestly, expired when filled.

All listings

Talentgrator via Workable

Incident Response Analyst

Level not stated CzechiaSerbiaGeorgiaArmeniaKazakhstanPoland
still open verified 5h ago posted 148d ago checked just now
Apply at apply.workable.com

This is the employer's own posting, not a copy on a job board.

What we know

Is it still open?

Confirmed still open

Last checked 5h ago — checked against the employer's own applicant tracking system, which is the company answering directly.

We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.

Check this listing's status as JSON

How old is it?

Posted 148d ago

The date the source published, not the day we noticed it (2026-04-20). Last seen at its source just now.

Is it remote?

Marked remote on the employer's board

Their board carries a remote setting on this posting — a field they filled in, not wording we read. The location field names somewhere specific, which is usually where the team or the entity sits.

Who may apply?

Czechia, Serbia, Georgia, Armenia, Kazakhstan, Poland

The description states no restriction of its own. This is the source's own tag.

Pay not stated

Similar roles pay £74k–98.8k/yr

Middle 50% of 12 listings that do state pay — Operations · all levels · EMEA · GBP/year. This employer has published no salary; this is what comparable listings we hold disclose, never converted between currencies or periods. How this is calculated.

Skills named in the ad

Active DirectoryAnsibleBashDockerIncident ManagementKnowledge BaseKubernetesLinuxPenetration TestingPythonSIEMSplunkTerraformTroubleshootingWorkday

Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.

Carried by 1 source

The listing

Talentgrator is a recruitment and talent partner focused on the IT entertainment and iGaming sectors, connecting businesses with specialized professionals. We work with teams that need strong technical expertise and dependable execution in fast-moving environments where security, resilience, and operational discipline matter every day.

We are looking for an Incident Response Analyst to join our Security team and operate on the front line of protecting the company’s infrastructure and services. In this role, you will analyze security events, investigate suspicious activity, and work with infrastructure and security data to identify and respond to potential threats.

Purpose of the role

You will be responsible for analyzing security events and raw logs, investigating suspicious activity, and supporting incident response processes.

We're looking for someone who has a good understanding of how infrastructure works and can read and interpret raw technical data, connect events from different sources, identify anomalies, and determine what may have happened during a security incident.

Responsibilities

  • Work with WAF to analyze anomalous traffic, respond to web attacks, and fine-tune rules.
  • Work with DLP and MDM to investigate data leaks, analyze policy violations, and collaborate with teams on findings.
  • Monitor and triage alerts in SIEM, analyzing events, classifying incidents, and prioritizing response.
  • Integrate raw log sources into SIEM, including normalization, parsing, and enrichment.
  • Develop and improve detection rules, correlation rules, and dashboards.
  • Reduce MTTR by identifying bottlenecks in response processes and implementing automation and runbooks.
  • Participate in incident post-mortems and provide actionable recommendations.
  • Conduct security incident investigations by collecting artifacts, reconstructing timelines, and performing root cause analysis.

Requirements

What We Expect

  • 3+ years of experience in Security Operations, SOC, Incident Response, Infrastructure Security, or a similar technical role.
  • Ability to read and interpret raw logs and understand what different system and application events represent.
  • Good understanding of Linux and Windows operating systems.
  • Good understanding of networking fundamentals and common network protocols.
  • Hands-on experience with SIEM platforms, preferably Splunk or similar technologies.
  • Ability to investigate security events by correlating information from different log sources.
  • Understanding of common cybersecurity threats, attacker techniques, and IOC/TTP concepts.
  • Familiarity with Active Directory and enterprise infrastructure.
  • Understanding of Kubernetes and Docker environments.
  • Basic scripting experience with Python, PowerShell, or Bash.
  • Understanding of Terraform and Ansible and how they are used for infrastructure automation and configuration management.
  • Strong analytical and troubleshooting skills.

Nice to Have

  • Experience with WAF, DLP, MDM, EDR/XDR, or similar security technologies.
  • Experience with Threat Hunting or Network Traffic Analysis.
  • Experience writing or tuning SIEM detection rules.
  • Experience with SOAR or security automation.
  • Experience with cloud infrastructure and cloud logs.
  • Experience with APIs and automation.
  • Participation in Red Team, Blue Team, Purple Team exercises, CTFs, or penetration testing.

Benefits

  • 25 vacation days and 5 family days yearly
  • Flexible start to the workday
  • Support from a professional corporate coach and psychologist
  • Regular internal and external activities, workshops, trips, and corporate events
  • Access to our internal knowledge base, meetups, and team-building activities
  • Ongoing training in new technologies and continuous professional development support
Apply at apply.workable.com