Cyber Incident & Response Team Analyst

Euroclear

Kraków

Hybrid

PLN 223,200 - 334,800

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive salary
Comprehensive benefits
Learning and development opportunities

Job summary

Euroclear is seeking a CIRT Analyst to support cyber incident response initiatives. This role involves managing complex security incidents, performing forensic investigations, and collaborating with various stakeholders to enhance incident management processes.

The ideal candidate will have at least 3 years of experience, knowledge in multiple operating systems, and excellent communication skills in English. This position offers a hybrid working model and a competitive salary.

Qualifications

  • 3+ years of experience in incident response is mandatory.
  • Knowledge of forensic techniques and evidence collection processes is essential.
  • Strong understanding of English is required for effective communication.

Responsibilities

  • Support the incident response capabilities and forensic technologies.
  • Independently handle complex investigations and lead incident resolution.
  • Collaborate with SOC personnel for integrated incident management.

Skills

Information Security related experience
3+ years expertise in incident response
Good knowledge of at least of these Operating Systems: Windows, Unix/Linux
Good knowledge of networking (TCP/IP)
Good knowledge of forensic technique and process
Good knowledge of evidence collection, including chain of custody
Good knowledge of cloud evidence collection and forensics capabilities
Good knowledge of both live and offline acquisition techniques
Good knowledge of memory analysis
Knowledge of Python or PowerShell Scripting
Excellent English communication skills (written and oral)

Tools

Certifications GIAC Certified Incident Handler (GCIH), Forensic Analyst (GCFA), Forensic Examiner (GCFE)
Knowledge of network traffic analysis and forensics
Knowledge of technical tools: firewalls, IDS, proxy, WAF, Active Directory, EDR, antivirus
Experience with vulnerability management & threat management

Job description

Division: CISO

Cyber Defense Center (CDC) is part of the Chief Information Security Officer Office. The main responsibility of the team is to reduce the risk of Euroclear cyber threat surface by monitoring for malicious intent targeted at Euroclear’s services, its supporting assets, and people. We do this through the Security Operations Centre (SOC), Cyber Incident & Response Team (CIRT), Detection & Response Engineering Team (D&R Eng), and Cyber Threat Management (CTM) capabilities. This includes security incident and event monitoring, cyber analytics, incident management and forensic analysis, cyber threat intelligence, vulnerability management, penetration testing, brand, and digital footprint monitoring.

Job Description

The CDC supports capabilities within the security domain and acts as a subject matter expert across all divisions in the company, interacting with external stakeholders, including customers, oversight bodies, threat intelligence providers, and third parties. CIRT establishes and executes the security incident response framework to ensure a consistent and effective approach to security incident management. Performs in-depth incident reviews, impact assessments, root‑cause analysis, and manages stakeholder engagement. Executes forensic analysis and investigations and supports fraud and personnel related incident investigations.

Role

In your role as CIRT Analyst you support the incident response capabilities and forensic technologies, understand the impact of potential security incidents on complex corporate environments, support and assess incident remediation to a conclusion, and assist with reporting and stakeholder management activities.

Your Primary Duties Will Be
  • Independently handles investigations within framework of procedures.
  • Owns the incident and leads the resolution, even the most complex, critical and sensitive cases.
  • Identify any incident/request that requires increased focus and actions necessary to meet committed service levels.
  • Collaborate and work with Threat Intelligence and the SOC personnel to develop automated and integrated incident management processes.
  • Execute the Cyber Security Incident Management process to ensure timely mitigation and escalation to appropriate incident resolver groups leaders. Execute third-tier incident handling including incident remediation in collaboration with the IT resolver team.
  • Execute and assist in the delivery of the organisation’s security incident management including coordination and communication with the wider security organisation, the business, IT and external stakeholders where required.
  • Validate and report deviation of incident response playbooks for various scenarios involving SOC and CIRT personnel.
  • Lead major cyber security incidents and provide support to the organization whenever cyber incidents occur. Independently handles investigations within framework of procedures.
  • Manage incident response and forensic technologies, understand potential security incident impact on complex corporate environments and the ability to assess and manage incidents to a conclusion.
  • Manage reporting and internal/external stakeholder management activities. Requires deep understanding of the business and infrastructure to enable choosing the most efficient and effective proposal to deal with an incident or threat.
  • Oversee root cause analysis for major cyber security incidents ensuring that the suitable problem management, issue management or risk management processes are followed as well as tracking issues through to resolution.
  • Forensics: technical expertise to gather and preserve digital evidence; investigative skills to think outside the box to build up a picture by combing through various sources of information; integrity to deal with sensitive and confidential matters.
  • Execute and assist in forensic investigations into potential or confirmed incidents in alignment with company guidelines.
  • Ensure preservation of digital evidence throughout investigations; escalation exceptions to experienced team members.
  • Expert interface for legal cases related to Euroclear - how to build case from cyber perspective.
  • Engage in industry wide cyber exercises.
  • May provide evidence in court and act as representative in fraud forum.
  • Develop and implement supporting processes, exercising and acceptance of the framework and processes before it goes live.
  • Support engagement with Threat Intelligence and the CDC personnel to develop integrated incident management processes.
  • Develop and maintain close working relationships with centrally and locally-based device owners, business stakeholders, business/application/solution architecture, application, IT & operational teams.
Technical Skills
  • Information Security related experience
  • 3+ years expertise in incident response
  • Good knowledge of at least of these Operating Systems: Windows, Unix/Linux
  • Good knowledge of networking (TCP/IP)
  • Good knowledge of forensic technique and process
  • Good knowledge of evidence collection, including chain of custody
  • Good knowledge of cloud evidence collection and forensics capabilities
  • Good knowledge of both live and offline acquisition techniques
  • Good knowledge of memory analysis
  • Knowledge of Python or PowerShell Scripting
  • Excellent English communication skills (written and oral)
Assets
  • Certifications GIAC Certified Incident Handler (GCIH), Forensic Analyst (GCFA), Forensic Examiner (GCFE), GIAC Reverse Engineering Malware (GREM) or other equivalent technical certifications.
  • Knowledge of network traffic analysis and forensics
  • Knowledge of the following technologies: firewalls, IDS, proxy, WAF, Active Directory, EDR, antivirus, ...
  • Experience with vulnerability management & threat management, vulnerability scanning, Data Loss Prevention (tools and processes)
  • Knowledge of IDA or other decompilation tools
  • Knowledge of zOS, Tandem
Soft Skills
  • Good security mindset.
  • Able to work autonomously.
  • Sense of urgency and able to apply a risk-based approach to prioritize work.
  • A problem solver: you recognize underlying issues and problems; you analyze root causes and define solutions accordingly.
  • Eager to work with challenging and technical concepts; You are ready to dive into modern technologies and extend your own expertise.
  • Reporting and continuous improvement mindset.
  • You have good influencing/persuasion skills, obtaining approval of others with good arguments, appropriate influencing methods and a certain natural authority (persuasion).
  • You examine matters from a distance and put them in a broader context and time perspective (vision).
  • A team-focused mentality with ability to work & collaborate effectively in a team environment.
  • Good leadership and communication skills, whether on the field, in the team or with management: you are a keen team player and coordinate work amongst people from different areas or divisions. A good relationship builder with strong diplomacy skills.
  • Capability to ensure confidentiality and discretion in performing sensitive tasks.
  • At ease in a fast-changing environment, with a flexible and pragmatic mindset.
  • Accurate, acting with attention to details.
  • Can express well-founded opinions and positions and understanding their consequences (judgement).
  • Project Management appetite.
  • Client focus and delivery oriented.
  • Reporting and continuous improvement mindset.
Why join us

Embark on your new adventure at Euroclear, and work at the heart of the global capital markets. We connect over 2,000 financial institutions across the globe. As an open and resilient infrastructure, we contribute to the stability of the financial markets. We help clients cut through complexity, lower costs, and mitigate risks of financial transactions. At Euroclear, we have the clear ambition to use our key role to facilitate and accelerate a sustainable global financial system.

What We Offer
  • Work closely with inspiring, supportive and engaged colleagues from more than 80 different countries.
  • Practice your talents in a highly professional international environment.
  • Join a learning and development environment with an emphasis on knowledge sharing and training.
  • Competitive salary and comprehensive benefits.
Ways of working

Find your own optimal balance within our hybrid working model, where you can connect at the office 8 days a month and also benefit from remote working.

Great Place to Work for All

We are committed to creating an inclusive culture that celebrates diversity and strives to be a Great Place to Work for All. All qualified applicants will be considered for employment, regardless of any aspect that makes them unique (including race, religion, national origin, gender, sexual orientation, age, marital status, pregnancy, disability, ...). If you need any specific accommodation due to disability or any other reason, you can let the recruiter know during your application process. Our values guide how we work together and shape our future: Our mission and values - Euroclear.

About The Team

As a global critical financial infrastructure, the protection of Euroclear information and assets is fundamental to the company’s business. Security is at the core of our services, firmly embedded in the management systems and processes of the company. You will be joining our Chief Information Security Office (CISO) in charge of putting in place the required controls to adequately and effectively protect our information assets.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

CyberArk 2nd Line Service Support Engineer
CyberArk 2nd Line Service Support Engineer

Euroclear • Kraków

Hybrid
PLN 180,000 - 280,000
Hybrid working model
Competitive salary
Comprehensive benefits
+1
PAM IDAM 2nd Line Service Support Engineer
PAM IDAM 2nd Line Service Support Engineer

Euroclear • Kraków

Hybrid
PLN 90,000 - 130,000
Cloudflare – Expert Security Engineer
Cloudflare – Expert Security Engineer

Euroclear • Kraków

Hybrid
PLN 180,000 - 260,000
Competitive salary
Comprehensive benefits
Cloudflare - Expert Security Engineer
Cloudflare - Expert Security Engineer

Euroclear • Poland

Hybrid
PLN 120,000 - 190,000
Hybrid working model
Competitive salary
Comprehensive benefits
Senior CIAM IT Business Analyst
Senior CIAM IT Business Analyst

Euroclear • Poland

Hybrid
PLN 60,000 - 80,000
Competitive salary
Comprehensive benefits
Learning and development opportunities
1st line PAM Security Operator
1st line PAM Security Operator

Euroclear • Kraków

Hybrid
PLN 120,000 - 180,000
Hybrid work model
Competitive salary
International, diverse environment
Senior CIAM IT Business Analyst
Senior CIAM IT Business Analyst

Euroclear • Kraków

Hybrid
PLN 120,000 - 180,000
Competitive salary
Comprehensive benefits
International environment
+1
IT Windows Senior Engineer
IT Windows Senior Engineer

Euroclear • Kraków

Hybrid
PLN 180,000 - 240,000
Friendly team
Continuous learning
Modern technologies
+2
CyberArk Senior Engineer
CyberArk Senior Engineer

Euroclear • Kraków

Hybrid
PLN 190,000 - 290,000
Competitive salary
Hybrid working model
Learning & development opportunities
Cyber Security Risk Analyst
Cyber Security Risk Analyst

Euroclear • Kraków

On-site
PLN 254,000 - 383,000