Global Security Incident Response Lead

WE Soda

Çankaya

On-site

TRY 600,000 - 900,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

WE Soda in Türkiye seeks a hands-on Senior Security Specialist to drive incidents from detection to resolution. You will coordinate with MSSP/SOC, Group IT, Türkiye IT, and external providers to validate alerts and document outcomes.

The role requires strong expertise in LogRhythm SIEM, EDR tools, and Windows security fundamentals, with experience across international teams and email security tooling.

Qualifications

  • 5+ years in Security Operations, SOC, Incident Response, or Cybersecurity Operations.
  • 3+ years hands-on experience investigating cybersecurity incidents.
  • Direct MSSP/SOC experience.
  • Hands-on with LogRhythm SIEM.
  • Experience with EDR tools (e.g., SentinelOne, Defender for Endpoint, CrowdStrike).
  • Solid understanding of Microsoft 365 security, Entra ID, MFA and sign-in log analysis.
  • Experience with phishing and email security events (Proofpoint, Defender for Office 365, Mimecast).
  • Knowledge of Windows endpoints, AD, PowerShell basics, logs and network security fundamentals.
  • Familiarity with ITSM tools (4me/Xurrent, ServiceNow, Jira).
  • Experience working across international teams and time zones.

Responsibilities

  • Act as the main liaison for MSSP/SOC escalations.
  • Review, validate, and challenge security alerts and investigations.
  • Coordinate incident responses including phishing, malware, ransomware, and data leakage.
  • Lead containment actions (isolation, MFA review, access revocation).
  • Use LogRhythm SIEM for alarm review, evidence validation, and tuning.
  • Work with EDR, MS 365/Entra ID, email security tools.
  • Maintain audit-ready incident records in 4me/Xurrent.
  • Support SOC improvement and incident response processes.
  • Lead or participate in multi-region incident calls.

Skills

Security operations
Incident response
Stakeholder communication
Cross-region coordination
Analytical thinking

Tools

LogRhythm SIEM
SentinelOne
Microsoft Defender for Endpoint
Proofpoint
Defender for Office 365
Mimecast

Job description

WE Soda in Türkiye seeks a hands-on Senior Security Specialist to drive incidents from detection to resolution. You will coordinate with MSSP/SOC, Group IT, Türkiye IT, and external providers to validate alerts and document outcomes.

The role requires strong expertise in LogRhythm SIEM, EDR tools, and Windows security fundamentals, with experience across international teams and email security tooling.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Security Specialist
Senior Information Security Specialist

WE Soda • Çankaya

On-site
TRY 600,000 - 900,000
Senior Cyber Defense & Incident Response Engineer
Senior Cyber Defense & Incident Response Engineer

Vodafone Group Plc • Fatih

Hybrid
TRY 600,000 - 900,000
Hybrid working kit
Ergonomic kit allowance
Digital meal voucher
+2
Global Cloud Solutions Engineer: Incident Response & HA/DR
Global Cloud Solutions Engineer: Incident Response & HA/DR

Sailglobal • Fatih

On-site
TRY 300,000 - 420,000
Senior InfoSec Specialist — SIEM, IAM & Compliance
Senior InfoSec Specialist — SIEM, IAM & Compliance

Nobel İlaç • Ümraniye

On-site
TRY 350,000 - 550,000
Cyber Defense & Security Operations Lead
Cyber Defense & Security Operations Lead

BİM Birleşik Mağazalar A.Ş • Sancaktepe

On-site
TRY 400,000 - 680,000
Remote Splunk Security Engineer – SIEM & Endpoint
Remote Splunk Security Engineer – SIEM & Endpoint

SoftwareONE Deutschland GmbH • Fatih

Hybrid
TRY 300,000 - 420,000
Global company culture
Mentor support during onboarding
President’s Club recognition
+3
IT Infrastructure & Security Operations Specialist
IT Infrastructure & Security Operations Specialist

Nobel Ilac A.S • Ümraniye

On-site
TRY 240,000 - 360,000
Lead Splunk Security Architect — Hybrid (Istanbul)
Lead Splunk Security Architect — Hybrid (Istanbul)

SoftwareOne • Fatih

Hybrid
TRY 600,000 - 900,000
Enterprise-level projects
International environment
Learning opportunities
+1
Security Operations Engineer: Defenses & Incident Response
Security Operations Engineer: Defenses & Incident Response

GİZLİ • Fatih

On-site
TRY 350,000 - 550,000
Remote-First Senior Security Operations Engineer
Remote-First Senior Security Operations Engineer

Jobgether • Turkey

On-site
TRY 180,000 - 260,000
Remote-first
Learning budget USD 2,000 per year
Annual bonus
+1