JustJoin.IT Praca zdalna Expert

Cyber Incident Response Coordinator

Link Group

⚲ Warszawa

Do uzgodnienia

Wymagania

  • IR
  • SoC
  • SANS
  • NIST
  • Data
  • Analytics

Opis stanowiska

We are looking for an Incident Response Coordinator to step into a crucial role within our global SecOps team. In this position, you will head operational efforts during overnight and weekend rotations, steering the mitigation of concurrent, multi-site threats through advanced AI analytics while keeping our response framework fully aligned with NIS2 mandates.

Key Responsibilities:
• Driving War Room initiatives to contain and resolve distributed, multi-site security events.
• Tracking incident lifecycles by maintaining precise operational logs and chronologies.
• Managing critical notification timelines to meet NIS2 compliance windows.
• Leveraging AI and LLM capabilities to cross-reference and contextualize incoming security alerts.
• Refining tactical playbooks, reinforcing DR/IR strategies, and facilitating tabletop exercises.
• Executing seamless shift transitions and auditing AI-assisted defense mechanisms.

Requirements:
• 3–5 years of experience within IR / SOC / CSIRT structures.
• Strong knowledge of IR frameworks (SANS/NIST).
• Practical understanding of NIS2 reporting requirements.
• Experience in alert correlation and data analysis using AI/LLM tools.
• Readiness to work shift rotations (nights and weekends).

🔍 Dekoder Ogłoszenia

🔴
head operational efforts during overnight and weekend rotations
Będziesz główną osobą odpowiedzialną za operacje w nocy i w weekendy, co oznacza pracę w niestandardowych godzinach.
🔴
Driving War Room initiatives
Oczekuje się, że będziesz aktywnie kierować zespołem w sytuacjach kryzysowych, co może być stresujące i wymagać szybkiego podejmowania decyzji.
🔴
Leveraging AI and LLM capabilities to cross-reference and contextualize incoming security alerts
Może to oznaczać pracę z narzędziami AI, które nie są w pełni dojrzałe lub wymagają znacznego nadzoru i walidacji ze strony człowieka.
🟡
Refining tactical playbooks, reinforcing DR/IR strategies, and facilitating tabletop exercises
Oprócz reagowania na incydenty, będziesz zaangażowany w procesy planowania i ćwiczeń, co może wymagać dodatkowego czasu i wysiłku.
🟡
3–5 years of experience within IR / SOC / CSIRT structures
Wymagane jest doświadczenie w konkretnych strukturach bezpieczeństwa, co może ograniczać kandydatów z bardziej ogólnym doświadczeniem w IT.