Incident Response Analyst II

American Express Global Business Travel

Województwo mazowieckie

On-site

PLN 180,000 - 280,000

Full time

9 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Health insurance
Retirement programs
Parental leave
Adoption assistance
Wellbeing resources

Job summary

Amex GBT in Poland is seeking a seasoned cybersecurity professional to join our security operations team. You will monitor alerts, triage incidents, and coordinate response actions across the organization to protect travel data and systems.

You will analyze logs, hunt threats, and work with IT and vendors to implement mitigations. The role requires 5+ years in security, relevant certifications, and strong communication under pressure.

Qualifications

  • Bachelor's degree or equivalent in computer science, information security, or a related field.
  • Minimum 5 years in cybersecurity with hands-on monitoring, incident response, and vulnerability management.
  • Relevant certifications (CompTIA Security+, CEH) are preferred.
  • Familiar with NIST/ISO 27001 standards.

Responsibilities

  • Monitor security alerts and incidents using SIEM tools and monitoring systems.
  • Analyze and triage incidents to determine severity and impact.
  • Coordinate containment, eradication, and recovery activities.
  • Review logs to detect unauthorized access, anomalies, and breaches.
  • Perform root cause analysis to improve detection and prevention.
  • Collaborate with teams to identify vulnerabilities and plan mitigations.
  • Maintain documentation of incidents and remediation efforts.

Skills

Security monitoring
Incident response
Vulnerability management
Python
PowerShell
Communication skills
Ability to work under pressure

Education

Bachelor's degree in Computer Science, Information Security, or related field

Tools

CrowdStrike
NG SIEM
Proofpoint
Abnormal
Palo Alto
Cisco

Job description

Amex GBT is a place where colleagues find inspiration in travel as a force for good and - through their work - can make an impact on our industry. We're here to help our colleagues achieve success and offer an inclusive and collaborative culture where your voice is valued.

What you'll be doing:
  • Incident Response and Management:
  • Monitor security alerts and incidents using SIEM (Security Information and Event Management) tools and other monitoring systems.
  • Analyze and triage security incidents to determine their severity and potential impact.
  • Assist in the coordination of incident response activities, including containment, eradication, and recovery.
  • Security Monitoring and Analysis:
  • Review and analyze security logs and alerts to detect unauthorized access, anomalies, and potential breaches.
  • Perform root cause analysis of security events to improve detection and prevention measures.
  • Threat Intelligence Monitoring and Threat Hunt Management:
  • In coordination with the Counter Adversary Operations team, review threat intelligence to understand emerging threats and recommend appropriate mitigation strategies.
  • Collaborate with other teams to identify and scope systems with identified vulnerabilities in a timely manner.
  • Contain and remove indicators of attack and/or compromise found pursuant to threat hunting activity.
  • Security Policy and Procedure Enforcement:
  • Ensure compliance with industry regulations and organizational security policies and procedures.
  • Assist in the development and implementation of security policies, standards, and procedures specific to the travel industry.
  • Collaboration and Communication:
  • Work closely with IT teams, vendors, and other stakeholders to address security concerns and implement effective security solutions.
  • Provide technical support and guidance to less experienced team members and other departments as needed.
  • Documentation and Reporting:
  • Maintain accurate and up-to-date documentation of security incidents, investigations, and remediation efforts.
  • Prepare detailed reports on security incidents, vulnerabilities and trends for management review.
What we're looking for:
  • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent work experience.
  • 5 years of experience in cybersecurity or a related IT role, with hands-on experience in security monitoring, incident response, and vulnerability management.
  • Relevant certifications such as CompTIA Security+, CEH (Certified Ethical Hacker), or equivalent are preferred.
  • Familiarity with industry standards and frameworks (e.g., NIST, ISO 27001).
  • Understanding of common security technologies and practices (e.g., firewalls, IDS/IPS, antivirus solutions).
  • Knowledge of security issues specific to the travel industry, such as data protection regulations and secure transaction processing.
  • Strong analytical and problem-solving skills with attention to detail.
  • Proficiency in using security tools and technologies (e.g., Crowdstrike, NG SIEM, Proofpoint, Abnormal, Palo Alto, Cisco, ).
  • Scripting language proficiency (Python, PowerShell, etc.) with the ability to filter and analyze large data sets.
  • Excellent communication skills, both written and verbal.
  • Ability to work effectively under pressure and manage multiple tasks simultaneously.
Preferred Attributes:
  • Experience in a travel or hospitality industry environment.
  • Familiarity with regulatory requirements and data protection laws relevant to the travel industry (e.g., GDPR, PCIDSS).
  • Experience with cloud security and emerging technologies.
Location

Poland

The #TeamGBT Experience
  • Flexible benefits are tailored to each country and start the day you do. These include health and welfare insurance plans, retirement programs, parental leave, adoption assistance, and wellbeing resources to support you and your immediate family.
  • Travel perks: get a choice of deals each week from major travel providers on everything from flights to hotels to cruises and car rentals.
  • Develop the skills you want when the time is right for you, with access to over 20,000 courses on our learning platform, leadership courses, and new job openings available to internal candidates first.
  • We strive to champion Inclusion in every aspect of our business at Amex GBT. You can connect with colleagues through our global INclusion Groups, centered around common identities or initiatives, to discuss challenges, obstacles, achievements, and drive company awareness and action.
  • And much more!

All applicants will receive equal consideration for employment without regard to age, sex, gender (and characteristics related to sex and gender), pregnancy (and related medical conditions), race, color, citizenship, religion, disability, or any other class or characteristic protected by law.

Furthermore, we are committed to providing reasonable accommodation to qualified individuals with disabilities. Please let your recruiter know if you need an accommodation at any point during the hiring process. For details regarding how we protect your data, please consult the Amex GBT Recruitment Privacy Statement.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Specialized Travel Counselor
Specialized Travel Counselor

American Express Global Business Travel • Poland

On-site
PLN 78,000 - 112,000
Health insurance
Parental leave
Adoption assistance
+3
Customer Relation Specialist
Customer Relation Specialist

American Express Global Business Travel • Poland

On-site
USD 16,000 - 24,000
Flexible benefits
Travel perks
Develop skills
+1
Event Planner with English and French/Spanish/German/Swedish/Norwegian
Event Planner with English and French/Spanish/German/Swedish/Norwegian

American Express Global Business Travel • Poland

Remote
PLN 40,000 - 70,000
Fully remote in Poland
IAM Governance Analyst
IAM Governance Analyst

American Express Global Business Travel (GBT) • Poland

On-site
PLN 180,000 - 240,000
Incident Response Analyst II — Threat Hunting & Monitoring
Incident Response Analyst II — Threat Hunting & Monitoring

American Express Global Business Travel • Województwo mazowieckie

On-site
PLN 180,000 - 280,000
Health insurance
Retirement programs
Parental leave
+2
Event Planner with English and French/Spanish/German/Swedish/Norwegian
Event Planner with English and French/Spanish/German/Swedish/Norwegian

American Express Global Business Travel • Warszawa

Hybrid
PLN 60,000 - 90,000
Information Security Engineer
Information Security Engineer

Equinix, Inc. • Warszawa

On-site
PLN 173,000 - 277,000
Private Medical Insurance
Pension plan
Annual leaves
+1
Sr. Security Analyst, SOC - Global Threat Operations
Sr. Security Analyst, SOC - Global Threat Operations

LevelBlue • Warszawa

On-site
PLN 180,000 - 240,000
Sport card
Life insurance
Medical insurance
+4
Principal Application Security Software Engineer
Principal Application Security Software Engineer

Sabre Corporation • Poland

Hybrid
PLN 320,000 - 420,000
Hybrid work model
Office Kraków
No dress code
+1
Senior Vulnerability & Application Security Engineer
Senior Vulnerability & Application Security Engineer

EY • Wrocław

Hybrid
PLN 180,000 - 280,000