Incident Response Analyst (L2) - SIEM & Forensics

SOFTSWISS

Georgia

On-site

USD 75,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Private health insurance
Sports benefits
Mental Health Program
Free English lessons
Local language courses
Paid time off
Maternity leave support
Referral program rewards
Upskilling and workshops
Conferences and corporate events

Job summary

SOFTSWISS is seeking an Incident Response Analyst (L2) to join our Security Operations team. You will investigate complex incidents, handle L1 escalations, and help improve detection and response capabilities.

You will analyze attack chains, validate hypotheses, and make evidence-based decisions to identify, investigate, and contain threats while coordinating with cross-functional teams.

Qualifications

  • 3+ years of experience in SOC, Incident Response, DFIR, or MSSP environments.
  • Strong understanding of modern cyber threats, attack techniques, and frameworks such as MITRE ATT&CK and the Cyber Kill Chain.
  • Hands-on experience investigating security incidents, performing digital forensics, and malware analysis.
  • Hands-on experience with SIEM platforms (e.g. Splunk, Wazuh, ClickHouse, Redash), including writing complex search queries, correlating events, and investigating large volumes of security data.
  • Good understanding of enterprise infrastructure, including Windows, Linux, macOS, Active Directory, email systems, Kubernetes, Docker, and databases.
  • Experience with automation using Python, PowerShell, or Bash.
  • Knowledge of Kubernetes and Docker security concepts.
  • Strong analytical mindset, problem-solving skills, and effective communication in cross-functional environments.
  • Intermediate or higher English level.

Responsibilities

  • Investigate and respond to complex security incidents throughout the entire incident lifecycle.
  • Perform digital forensic investigations, malware analysis, and evidence collection to determine the scope and root cause of security incidents.
  • Analyze attack techniques, correlate security events, and reconstruct attack timelines.
  • Develop and improve SIEM detections, correlation rules, and incident response playbooks.
  • Conduct threat hunting activities and reduce false positives through detection tuning.
  • Automate repetitive SOC activities using scripting where appropriate.
  • Collaborate with Infrastructure, Development, IT, and Security teams during incident response.
  • Mentor L1 analysts by providing technical guidance and feedback.

Skills

SIEM expertise
DFIR
Malware analysis
Python scripting
PowerShell
Kubernetes security
Docker security
Attack chain analysis
English communication

Tools

Splunk
Wazuh
ClickHouse
Redash
Kubernetes
Docker

Job description

SOFTSWISS is seeking an Incident Response Analyst (L2) to join our Security Operations team. You will investigate complex incidents, handle L1 escalations, and help improve detection and response capabilities.

You will analyze attack chains, validate hypotheses, and make evidence-based decisions to identify, investigate, and contain threats while coordinating with cross-functional teams.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Incident Response Analyst - L2
Incident Response Analyst - L2

SOFTSWISS • Georgia

On-site
USD 75,000 - 120,000
Private health insurance
Sports benefits
Mental Health Program
+7
SOC Analyst II: Threat Detection & Incident Response
SOC Analyst II: Threat Detection & Incident Response

LPL Financial • Tempe (AZ)

On-site
USD 100,748,000 - 167,998,000
Senior Threat Hunter & Incident Responder (SOC)
Senior Threat Hunter & Incident Responder (SOC)

Sphynx • Town of Greece (NY)

On-site
USD 110,000 - 165,000
Competitive remuneration
Excellent conditions
Professional development
+1
SOC Cyber Defense Incident Responder
SOC Cyber Defense Incident Responder

Swisslog Holding AG • Newport News (VA)

Hybrid
USD 90,000 - 130,000
SOC Analyst II - Threat Detection & Incident Response
SOC Analyst II - Threat Detection & Incident Response

LPL Financial LLC • Tempe (AZ)

Hybrid
USD 100,747,000 - 167,998,000
SOC Analyst I–II: Incident Detection & Response
SOC Analyst I–II: Incident Detection & Response

Optimalsemi • Irving (TX)

On-site
USD 95,000 - 125,000
Senior Cyber Security Analyst - Incident Response & SIEM
Senior Cyber Security Analyst - Incident Response & SIEM

InterEx Group • United States

On-site
USD 90,000 - 130,000
Remote SOC Engineer II - Threat Detection & Incident Lead
Remote SOC Engineer II - Threat Detection & Incident Lead

CTS • United States

On-site
USD 80,000 - 85,000
Health Insurance
401(k) with company match
Paid Time Off
+6
Senior L3 SOC Analyst — Remote Incident Lead
Senior L3 SOC Analyst — Remote Incident Lead

Hamilton Barnes ? • United States

Remote
AUD 127,000 - 184,000
Fully remote role
Collaborative SOC team
Opportunity to grow technical and leadership skills
Senior SOC Analyst: Threat Hunting & Incident Response
Senior SOC Analyst: Threat Hunting & Incident Response

Logicalis GmbH • Beachwood (OH)

On-site
USD 78,000 - 100,000