Cyber Security Services Incident Response Engineer @Stefanini EMEA
All Others
Salary unspecified
Remote Location
Employment Type contract
Posted 1mth ago

[Hiring] Cyber Security Services Incident Response Engineer @Stefanini EMEA

1mth ago - Stefanini EMEA is hiring a remote Cyber Security Services Incident Response Engineer. πŸ’Έ Salary: unspecified πŸ“Location: EET (UTC+2)

Role Description

Stefanini Group is seeking a skilled Cyber Security Services (CSS) Incident Response (IR) Engineer to join our Security Operations Center (SOC), which operates as a Managed Security Service Provider (MSSP). As a CSS IR Engineer, you will manage security incidents, develop incident response processes, and enhance security configurations tailored to client needs. Your expertise will be crucial in reducing false positives and identifying security gaps within the client's IT infrastructure.

Work Schedule: Two rotating 8.5-hour shifts within the 8:00 a.m.-8:00 p.m. EET coverage window.

Job Responsibilities:

  • Own assigned security alerts, incidents, and escalated security tickets by providing advisory feedback and mitigating encountered technical issues.
  • Lead the investigation and response to security incidents across endpoint, identity, email, network, cloud, and other available telemetry sources.
  • Analyze endpoint activity to identify indicators of compromise and adversary behaviors, including malicious execution, persistence, privilege escalation, and lateral movement.
  • Investigate suspicious user and identity activity by analyzing Microsoft Entra ID authentication logs, sign-in activity, access patterns, anomalies, and other identity-related telemetry.
  • Use SentinelOne Singularity Data Lake (SDL) and SDL PowerQuery to perform advanced searches, correlate events, analyze threats, and support security investigations.
  • Document investigative actions, evidence, analysis, decisions, communications, containment measures, and recovery activities throughout the incident lifecycle.
  • Prepare detailed P1 and P2 incident reports covering the incident timeline, root cause, impact assessment, actions taken, current status, and lessons learned.
  • Provide feedback to client security team on detection logic, alert quality, false positives, telemetry gaps, and monitoring improvement, recommending rule-tuning adjustments and new detection use cases based on emerging threats, vulnerabilities, observed activity, and attack patterns.
  • Produce weekly operational reports on alert volumes and status, operational trends, investigation outcomes, false-positive rates by detection source.
  • Execute containment, eradication, and recovery activities in accordance with approved procedures and incident response playbooks.
  • Conduct forensic analysis and develop investigation hypotheses using structured incident response and threat hunting methodologies.
  • Support threat hunting and proactive detection initiatives based on emerging tactics, techniques, and procedures (TTPs).
  • Participate in security operations meetings and present incident findings, operational trends, detection performance, service-level results, and improvement recommendations.
  • Identify and track security gaps, recommend mitigation measures, and support SOAR automation workflows by providing operational feedback and identifying suitable automation opportunities to enhance operational efficiency.
  • Contribute to the development, maintenance, and refinement of standard operating procedures, incident response playbooks, investigation guides, workflows, and process documentation.
  • Support monthly security tool and log-source health checks and provide mean time to resolution (MTTR) metrics by incident severity and lifecycle stage.
  • Collaborate with security analysts, incident responders, threat hunters, technology owners, and stakeholders across multiple teams and time zones to implement security best practices.
  • Provide technical guidance, coaching, and mentoring to junior analysts, fostering a collaborative and learning-focused environment.

Qualifications

  • Preferred: Bachelor's degree in computer science, Information Technology, Engineering, or a related field.
  • Minimum education requirement: High school studies completed with Baccalaureate diploma.
  • Excellent English communication skills, both verbal and written, for professional communication and documentation.

Requirements

  • Minimum 5 years of experience in cybersecurity operations, including hands-on experience investigating and responding to security incidents across endpoints, network, cloud, and other technology environments.
  • Demonstrated experience working in a Security Operations Center, Global Security Operations Center, Managed Security Service, or similar 24/7 operational environment.

Benefits

  • Hands-on certifications in incident response, forensics, threat hunting, or malware analysis - for example GCIH, GCFA, GCDA, GREM, ECIH, CySA+, eCTHP, CDSA, or OSCP. Equivalent practical evidence (published research, open-source detection contributions) is weighted equally.

Company Description

We are the Stefanini group, a global tech consulting company of Brazilian origin that believes in the power of people to transform businesses through technology. We are present in over 40 countries and operate with the purpose of co-creating solutions TOGETHER WITH OUR CLIENTS that accelerate results and improve the experience of people and organizations.

Here, we like to say that technology is not the end, but the means: what really matters are the people who drive it all.

Our mindset is AI First, meaning we invest in cutting-edge technology in everything we do, focusing on results for our clients.

We are a company, A GROUP, that breathes collaboration and offers a dynamic environment where you will learn by doing, grow alongside the team, and have space to contribute with ideas and projects.

More than just talking about digital transformation, we believe in real transformation that starts with people and impacts real businesses.

Before You Apply
️
remote Be aware of the location restriction for this remote position: EET (UTC+2)
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Cyber Security Services Incident Response Engineer @Stefanini EMEA
All Others
Salary unspecified
Remote Location
Employment Type contract
Posted 1mth ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: EET (UTC+2)
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 126,869+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later