Unlock Full Resume Report

New offer - be the first one to apply!

September 3, 2026

Cyber Incident & Response Team Analyst

Mid • On-site

Kraków, Poland

Division

Cyber Defense Center (CDC) is part of the Chief Information Security Officer Office. The team reduces cyber-threat risk by monitoring malicious activity targeting services, supporting assets, and people through Security Operations Centre (SOC), Cyber Incident & Response Team (CIRT), Detection & Response Engineering, and Cyber Threat Management capabilities.

The CDC covers security incident and event monitoring, cyber analytics, incident management and forensic analysis, cyber threat intelligence, vulnerability management, penetration testing, and brand and digital-footprint monitoring. It supports security capabilities across the organization and interacts with customers, oversight bodies, threat-intelligence providers, and third parties.

CIRT establishes and executes the security incident-response framework, performs incident reviews, impact assessments and root-cause analysis, manages stakeholder engagement, executes forensic investigations, and supports fraud- and personnel-related incident investigations.

Description

As a CIRT Analyst, you will support incident-response capabilities and forensic technologies, assess the impact of potential security incidents in complex corporate environments, and drive incident remediation to conclusion. You will also support reporting and stakeholder-management activities.

Responsibilities

  • Independently investigate incidents within established procedures and own resolution of complex, critical, and sensitive cases.
  • Identify incidents or requests requiring increased focus and take action to meet committed service levels.
  • Collaborate with Threat Intelligence and SOC personnel to develop automated, integrated incident-management processes.
  • Execute and manage the Cyber Security Incident Management process, ensuring timely mitigation and escalation to appropriate resolver-group leaders.
  • Perform third-tier incident handling and remediation in collaboration with IT resolver teams.
  • Coordinate and communicate incident management with the wider security organization, business, IT, and external stakeholders.
  • Validate and report deviations from incident-response playbooks involving SOC and CIRT personnel.
  • Lead major cyber-security incidents and support the organization during cyber incidents.
  • Manage incident-response and forensic technologies; assess incident impact and manage incidents to conclusion.
  • Manage reporting and internal and external stakeholder activities; use business and infrastructure knowledge to select effective responses to incidents and threats.
  • Oversee root-cause analysis for major incidents, ensure appropriate problem, issue, or risk-management processes are followed, and track issues through resolution.
  • Gather and preserve digital evidence, investigate across multiple information sources, and handle sensitive and confidential matters with integrity.
  • Execute and assist forensic investigations into potential or confirmed incidents in line with company guidelines.
  • Preserve digital evidence throughout investigations and escalate exceptions to experienced team members.
  • Act as an expert interface for legal cases, including building cyber-focused cases; potentially provide evidence in court and represent the organization in fraud forums.
  • Participate in industry-wide cyber exercises.
  • Develop and implement supporting processes and test framework and process acceptance before go-live.
  • Maintain close working relationships with device owners, business stakeholders, architecture, application, IT, and operational teams.

Technical Requirements

  • Information-security-related experience.
  • 3+ years of incident-response expertise.
  • Good knowledge of Windows or Unix/Linux operating systems.
  • Good knowledge of TCP/IP networking.
  • Good knowledge of forensic techniques and processes.
  • Good knowledge of evidence collection and chain of custody.
  • Good knowledge of cloud evidence collection and forensic capabilities.
  • Good knowledge of live and offline acquisition techniques.
  • Good knowledge of memory analysis.
  • Knowledge of Python or PowerShell scripting.
  • Excellent written and spoken English.

Preferred Qualifications

  • GIAC Certified Incident Handler (GCIH), Forensic Analyst (GCFA), Forensic Examiner (GCFE), GIAC Reverse Engineering Malware (GREM), or equivalent technical certifications.
  • Knowledge of network-traffic analysis and forensics.
  • Knowledge of firewalls, IDS, proxy, WAF, Active Directory, EDR, and antivirus technologies.
  • Experience with vulnerability management, threat management, vulnerability scanning, and Data Loss Prevention tools and processes.
  • Knowledge of IDA or other decompilation tools.
  • Knowledge of zOS and Tandem.

Benefits

  • Work with supportive, engaged colleagues in an international environment.
  • Learning and development environment focused on knowledge sharing and training.
  • Competitive salary and comprehensive benefits.
  • Hybrid working model with office attendance 8 days per month and remote-working flexibility.
  • Inclusive workplace where qualified applicants are considered regardless of personal characteristics.

About the Team

You will join the Chief Information Security Office, responsible for establishing controls to protect information assets and support security embedded in organizational management systems and processes.

Similar jobs you might like