Lead Cyber Security Analyst
Endava Vezi toate joburile
- Cluj-Napoca, Cluj
- Permanent
- Full-time
- Lead triage, investigation, and containment of complex security incidents escalated from L1.
- Lead Security Incidents and coordinate Incident Response
- Coordinate with stakeholders to contain, eradicate, and recover from security incidents.
- Conduct root cause analysis, malware analysis, and advanced forensics (network, endpoint, and cloud).
- Develop and refine incident response playbooks.
- Proactively hunt for threats using SIEM, EDR, and threat intelligence feeds.
- Support the creation and optimization of detection rules, correlation logic, and automation scripts.
- Perform gap analysis to improve detection capabilities.
- Monitor and analyze security alerts from SIEM, IDS/IPS, EDR, DLP, and other security platforms.
- Correlate events across multiple data sources for accurate threat assessment.
- Support audits, compliance checks, and risk assessments.
- Mentor and train SOC L1 analysts on investigation techniques and tools.
- 3+ years in cybersecurity, with at least 2 years in SOC/Incident Response.
- Advanced knowledge of SIEM, EDR, IDS/IPS, DLP, IAM, and cloud security tools.
- Hands-on experience in malware analysis, memory forensics, and log analysis.
- Strong understanding of network protocols, secure configurations, and common attack techniques (MITRE ATT&CK).
- One or more of the following certifications: OSCP, GCIA, GCIH, CEH, CompTIA Security+, CompTIA Cysa, CISSP, Security Blue Team L1/L2
- Familiarity with cloud environments (AWS, Azure, GCP) and container security
- Strong problem-solving and analytical skills.
- Ability to remain calm and decisive during high-pressure incidents.
- Excellent communication skills, both technical and non-technical.
- Continuous learning mindset and willingness to explore new tools and methods.
- Finance: Competitive salary package, share plan, company performance bonuses, value-based recognition awards, referral bonus;
- Career Development: Career coaching, global career opportunities, non-linear career paths, internal development programmes for management and technical leadership;
- Learning Opportunities: Complex projects, rotations, internal tech communities, training, certifications, coaching, online learning platforms subscriptions, pass-it-on sessions, workshops, conferences;
- Work-Life Balance: Hybrid work and flexible working hours, employee assistance programme;
- Health: Global internal wellbeing programme, access to wellbeing apps;
- Community: Global internal tech communities, hobby clubs and interest groups, inclusion and diversity programmes, events and celebrations.