I

Cyber Incident Response Analyst

Remote
Apply
AI Summary

Join Codertal as a Cyber Incident Response Analyst to support a major international airline player. You will investigate incidents, coordinate responses, and enhance detection capabilities across critical infrastructure. Requires 8+ years cybersecurity experience with offensive security tools and SIEM/EDR expertise.

Key Highlights
8+ years cybersecurity experience with 4+ years SOC/Incident Response
Hands-on offensive security tools (Burp Suite, Nmap, Metasploit)
SIEM, EDR, SOAR, and automation proficiency
Remote contract role with competitive daily rate
Key Responsibilities
Incident triage and investigation alongside the SOC, ensuring accurate analysis, forensics, and documentation
Escalation point for SOC alerts, coordinating with outsourced vendors and internal Cyber/IT teams
Operational collaboration with SOC on daily monitoring, response processes, and playbook improvements
Process and system integration to enhance service quality and responsiveness
Maintain high-quality incident records, audit trails, lessons learned, and continuous improvement actions
Identify and validate security weaknesses using manual techniques and offensive tooling
Document findings with clear risk descriptions, reproduction steps, business/technical impact, and remediation guidance
Participate in on-call rotations for major cyber events
Work with SOC and Threat Management services on daily/weekly/monthly cadences
Improve real-time detection and response using SIEM, EDR, SOAR, and automation
Develop and maintain cyber testing playbooks, SOPs, and checklists
Support tabletop exercises and simulation tests
Stay current with emerging threats, vulnerabilities, and offensive techniques relevant to the technology stack
Technical Skills Required
SIEM EDR SOAR Python
Benefits & Perks
Competitive daily rate
B2B contract
Work fully remote
Long-term career growth opportunities
Nice to Have
MITRE ATT&CK familiarity
Experience building dashboards for service metrics
Outsourced SOC model experience
Scripting for tool integration and playbook automation

Job Description


THIS IS A B2B CONTRACT FOR CANDIDATES WHO ARE BASED IN EUROPE


Codertal is looking for an experienced Cyber Incident Response Analyst to join our team and support a major international player in the airline industry. This is a hands‑on, high‑impact role within a modern Cyber Defence environment that blends outsourced SOC services with an internal CSIRT capability.


The ideal candidate is a proactive, technically strong incident responder who thrives in fast‑moving environments, understands attacker behaviour, and can elevate detection and response processes through automation, integration and continuous improvement.


Your Role

As a Cyber Incident Response Analyst, you will work closely with the SOC, Cyber Defence and Cyber Engineering teams to ensure high‑quality incident investigations, rapid response, and continuous enhancement of monitoring coverage and playbooks. You will also simulate attacker techniques to validate and strengthen cyber controls across critical infrastructure.


Key Responsibilities

  • Incident triage & investigation alongside the SOC, ensuring accurate analysis, forensics and documentation.
  • Escalation point for SOC alerts, coordinating with outsourced vendors and internal Cyber/IT teams.
  • Operational collaboration with SOC on daily monitoring, response processes and playbook improvements.
  • Process & system integration to enhance service quality and responsiveness.
  • Maintain high‑quality incident records, audit trails, lessons learned and continuous improvement actions.
  • Identify and validate security weaknesses using manual techniques and offensive tooling.
  • Document findings with clear risk descriptions, reproduction steps, business/technical impact and remediation guidance.
  • Participate in on‑call rotations for major cyber events.
  • Work with SOC and Threat Management services on daily/weekly/monthly cadences, ensuring visibility of incidents and KPIs.
  • Improve real‑time detection and response using SIEM, EDR, SOAR and automation.
  • Develop and maintain cyber testing playbooks, SOPs, checklists.
  • Support tabletop exercises and simulation tests.
  • Stay current with emerging threats, vulnerabilities and offensive techniques relevant to the technology stack.


Initial Success Factors

  • High‑quality, complete incident investigations
  • Measurable improvements in SOC use cases and playbooks
  • Establishing a benchmark of current attack exposure across critical infrastructure


Required Qualifications & Experience

  • 8+ years in cybersecurity and/or IT
  • 4+ years in SOC, Incident Response or Offensive Security
  • Proven experience in investigation, digital forensics, triage and response
  • Hands‑on experience with offensive tools (Burp Suite, Nmap, Metasploit, custom scripts)
  • Relevant certifications: GIAC, CISSP, OSCP, CEH or similar


Essential Skills

  • Comfortable leading low‑medium severity incidents
  • Proactive, independent thinker with strong communication skills
  • Hands‑on proficiency with SIEM, Threat Intelligence, SOAR, EDR (CrowdStrike, ZeroFox, Splunk or equivalent)
  • Working knowledge of Python, Bash or PowerShell
  • Ability to improve operational processes and playbooks
  • Ability to translate threat intelligence and incident learnings into actionable requirements


Desirable Skills

  • Familiarity with MITRE ATT&CK
  • Experience building dashboards for service metrics
  • Experience with outsourced SOC models
  • Scripting for tool integration and playbook automation


What We Offer

  • Competitive daily rate
  • B2B contract
  • Work fully remote
  • Long‑term career growth opportunities
  • Exposure to a highly mature cyber environment in the aviation industry
  • Work with a passionate, collaborative team of cybersecurity professionals
  • Travel benefits with multiple international airlines



Similar Jobs

Explore other opportunities that match your interests

Application Security Engineer

Cyber Security
4h ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Entry level

BetterQA

Romania

Senior Runtime Protection Engineer

Cyber Security
6d ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

CloudLinux

Romania
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Director

ajaia | ai consultancy

Romania

Subscribe our newsletter

New Things Will Always Update Regularly