- Company Name
- Cronos Europa
- Job Title
- Cybersecurity - Incident Responder
- Job Description
-
Job Title: Cybersecurity Incident Responder
Role Summary: Lead the design, execution, and continuous improvement of incident response processes and XSOAR automation to contain, mitigate, and resolve cyber incidents across cloud, SIEM, and EDR platforms.
Expectations: Deliver standardized, automated playbooks; maintain high‑quality documentation; report performance metrics; train analysts; collaborate with cross‑functional teams; adhere to regulatory and security frameworks.
Key Responsibilities:
- Define and refine incident handling procedures, playbook logic, and automation requirements.
- Prepare incident response workflows, enrichment steps, and technical documentation for recurring alert types.
- Manage live incident handling: triage, escalation, containment, resolution.
- Develop, test, and maintain XSOAR playbooks, integrations, and automations for Splunk, AWS, Azure Sentinel, Carbon Black Cloud, Sysdig.
- Coordinate playbook updates, incident reports, and cross‑team reviews to ensure accuracy and compliance.
- Track and report KPIs (FP/TP rate, MTTH, escalation rate, automation coverage, time saved, error reduction).
- Train analysts on playbook use and incident response methodology; update the knowledge base.
- Engage with CSIRC, CATCH analysts, infrastructure teams, and external stakeholders to validate coverage and share threat intelligence.
Required Skills:
- Strong knowledge of incident response methodologies and SOC operations.
- Proficiency in XSOAR playbook development, Python scripting, and automation logic.
- Hands‑on experience with Splunk, AWS, Azure Sentinel, Carbon Black Cloud, Sysdig, and other SIEM/SOAR platforms.
- End‑to‑end incident handling experience in large or multinational environments.
- Ability to analyze root causes, propose automation improvements, and optimize workflows.
- Excellent communication skills for technical and non‑technical audiences; ability to present findings and recommendations.
- Ability to produce clear, structured technical documentation and reports.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Information Security, or related field (preferred).
- Certifications: Palo Alto Cortex XSOAR, Splunk, Microsoft Security (SC‑200), AWS Security Specialty, Azure Security Engineer, or equivalent practical experience.