Incident Response Analyst - L2

SOFTSWISS

Georgia

On-site

USD 75,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Private health insurance
Sports benefits
Mental Health Program
Free English lessons
Local language courses
Paid time off
Maternity leave support
Referral program rewards
Upskilling and workshops
Conferences and corporate events

Job summary

SOFTSWISS is seeking an Incident Response Analyst (L2) to join our Security Operations team. You will investigate complex incidents, handle L1 escalations, and help improve detection and response capabilities.

You will analyze attack chains, validate hypotheses, and make evidence-based decisions to identify, investigate, and contain threats while coordinating with cross-functional teams.

Qualifications

  • 3+ years of experience in SOC, Incident Response, DFIR, or MSSP environments.
  • Strong understanding of modern cyber threats, attack techniques, and frameworks such as MITRE ATT&CK and the Cyber Kill Chain.
  • Hands-on experience investigating security incidents, performing digital forensics, and malware analysis.
  • Hands-on experience with SIEM platforms (e.g. Splunk, Wazuh, ClickHouse, Redash), including writing complex search queries, correlating events, and investigating large volumes of security data.
  • Good understanding of enterprise infrastructure, including Windows, Linux, macOS, Active Directory, email systems, Kubernetes, Docker, and databases.
  • Experience with automation using Python, PowerShell, or Bash.
  • Knowledge of Kubernetes and Docker security concepts.
  • Strong analytical mindset, problem-solving skills, and effective communication in cross-functional environments.
  • Intermediate or higher English level.

Responsibilities

  • Investigate and respond to complex security incidents throughout the entire incident lifecycle.
  • Perform digital forensic investigations, malware analysis, and evidence collection to determine the scope and root cause of security incidents.
  • Analyze attack techniques, correlate security events, and reconstruct attack timelines.
  • Develop and improve SIEM detections, correlation rules, and incident response playbooks.
  • Conduct threat hunting activities and reduce false positives through detection tuning.
  • Automate repetitive SOC activities using scripting where appropriate.
  • Collaborate with Infrastructure, Development, IT, and Security teams during incident response.
  • Mentor L1 analysts by providing technical guidance and feedback.

Skills

SIEM expertise
DFIR
Malware analysis
Python scripting
PowerShell
Kubernetes security
Docker security
Attack chain analysis
English communication

Tools

Splunk
Wazuh
ClickHouse
Redash
Kubernetes
Docker

Job description

Overview

SOFTSWISS is looking for an Incident Response Analyst (L2) to join our Security Operations team. In this role, you will investigate complex security incidents, handle L1 escalations, and help improve our detection and incident response capabilities.

Purpose of the role

You will be responsible for investigating complex cybersecurity incidents, handling escalations from L1, and enhancing our SOC detection and incident response capabilities.

We're looking for someone with an incident-driven mindset who can analyze attack chains, validate hypotheses, and make evidence-based decisions to effectively identify, investigate, and contain security threats.

Key responsibilities
  • Investigate and respond to complex security incidents throughout the entire incident lifecycle
  • Perform digital forensic investigations, malware analysis, and evidence collection to determine the scope and root cause of security incidents
  • Analyze attack techniques, correlate security events, and reconstruct attack timelines
  • Develop and improve SIEM detections, correlation rules, and incident response playbooks
  • Conduct threat hunting activities and reduce false positives through detection tuning
  • Automate repetitive SOC activities using scripting where appropriate
  • Collaborate with Infrastructure, Development, IT, and Security teams during incident response
  • Mentor L1 analysts by providing technical guidance and feedback
Required Experience
  • 3+ years of experience in SOC, Incident Response, DFIR, or MSSP environments
  • Strong understanding of modern cyber threats, attack techniques, and frameworks such as MITRE ATT&CK and the Cyber Kill Chain
  • Hands‑on experience investigating security incidents, performing digital forensics, and malware analysis
  • Hands‑on experience with SIEM platforms (e.g. Splunk, Wazuh, ClickHouse, Redash), including writing complex search queries, correlating events, and investigating large volumes of security data
  • Good understanding of enterprise infrastructure, including Windows, Linux, macOS, Active Directory, email systems, Kubernetes, Docker, and databases
  • Experience with automation using Python, PowerShell, or Bash
  • Knowledge of Kubernetes and Docker security concepts
  • Strong analytical mindset, problem‑solving skills, and effective communication in cross‑functional environments
  • Intermediate or higher English level
Nice to have
  • Experience with Threat Hunting, Network Traffic Analysis (NTA), or cloud security (AWS)
  • Familiarity with CI/CD and Infrastructure as Code (e.g. Terraform, Ansible)
  • Participation in Red Team or Purple Team exercises
  • Industry certifications such as GCIA, GCIH, GCED, OSCP, CEH, or Splunk certifications
  • Familiarity with security frameworks such as NIST
Our Benefits
  • Private health insurance
  • Sports benefits
  • Comprehensive Mental Health Program
  • Free English lessons (online)
  • Local language courses
  • Paid time off
  • Maternity leave support
  • Referral program rewards
  • Upskilling, internal workshops, and participation in professional conferences and corporate events
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Incident Response Analyst (L2) - SIEM & Forensics
Incident Response Analyst (L2) - SIEM & Forensics

SOFTSWISS • Georgia

On-site
USD 75,000 - 120,000
Private health insurance
Sports benefits
Mental Health Program
+7
L3 Security Analyst
L3 Security Analyst

Sphynx • Town of Greece (NY)

On-site
USD 110,000 - 165,000
Competitive remuneration
Excellent conditions
Professional development
+1
Senior Security Analyst
Senior Security Analyst

Tata Consultancy Services • Houston (TX)

On-site
USD 110,000 - 130,000
Discretionary Annual Incentive
Medical Coverage: Health, Dental & Vis
401K Plan
+2
Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000
Security Incident Response Engineer
Security Incident Response Engineer

United States Digital Space LLC • United States

Hybrid
USD 125,000 - 165,000
Sr. Incident Response Analyst
Sr. Incident Response Analyst

Compunnel, Inc. • Jersey City (NJ)

On-site
USD 100,000 - 130,000
Security Engineer, Incident Response
Security Engineer, Incident Response

United States Digital Space LLC • New York (NY)

On-site
USD 120,000 - 180,000
L3: Principal Security Analyst (on-sight)
L3: Principal Security Analyst (on-sight)

Lumifi Cyber, Inc. • Scottsdale (AZ)

On-site
USD 100,000 - 130,000
Self-managed time off
80% employer healthcare coverage
Comprehensive professional development benefits
+1
Security Analyst
Security Analyst

Tenarai Europe • Town of Poland (NY)

Hybrid
USD 32,000 - 51,000
Remote/Hybrid work
Office spaces
Parking
+8
Senior Security Analyst
Senior Security Analyst

Yardi Systems • Santa Barbara (CA)

Hybrid
USD 97,000 - 110,000
Flexible work arrangements
100% paid employee medical premiums
Company profit-sharing plan