Incident Response Analyst II (Hybrid, Bucharest)
Core
Design and build automation, tooling, and engineering capabilities to improve CrowdStrike's internal security operations and incident response effectiveness.
Role type
Security Engineer (Incident Response & Detection Engineering)
Builds
Automation workflows, security detections, integrations, and internal tooling for the CSIRT
Domain
Cybersecurity, Cloud Security, DevOps
Deliverable
production ML models | product features | infrastructure
Required skills
Incident response investigation, Python/Go programming, API development, Cloud platforms (AWS/Azure/GCP), Linux, Networking, Enterprise security technologies
Preferred skills
CI/CD pipelines, Docker/Kubernetes/Terraform, SIEM/EDR/SOAR platforms, Security telemetry/log analytics, MITRE ATT&CK, Threat hunting, AI/ML in security
Technologies
Python, Go, AWS, Azure, Google Cloud, GitLab CI, GitHub Actions, Jenkins, Docker, Kubernetes, Terraform, SIEM, EDR, SOAR
Responsibilities
Partner with Incident Response Operations to identify challenges and engineer scalable solutions; Automate repetitive investigative and response workflows; Design solutions to improve investigative efficiency and reduce false positives; Develop and maintain detection, enrichment, and response pipelines; Build and maintain integrations between security platforms and cloud services; Engineer reliable, cloud-native capabilities using CI/CD and Infrastructure as Code
Seniority
Mid-Senior, hands-on IC
