Booking Holdings Romania - Cybersecurity Analyst Ii, Cdr

Booking Booking · Hospitality · Bucharest, Romania · Security & Infrastructure

Cyber Security Analyst responsible for detection, investigation, and response to cyber security attacks and threats. This role involves threat hunting, digital forensics, and incident response in large-scale environments.

What you'd actually do

  1. Responsible for investigating the incidents escalated by the 24/7 Triage & Monitoring team.
  2. Assists the 24/7 Triage & Monitoring team with in-depth investigating cybersecurity alerts raised by a wide variety of security tools like: SOAR, EDR, XDR, IPS/IDS, SIEM, Sandbox, Cloud Security, Email Security, GitLab Security, Container Security.
  3. Coordinates incident, response, escalation, and reporting of cybersecurity incidents.
  4. Performs technical investigation on complex security incidents to achieve efficient mitigation for active threats and identification of the root cause.
  5. Performs quality hands-on technical incident response, log analysis, and threat hunting.

Skills

Required

  • operational security experience (SOC, Incident Response, Malware Analysis, etc.)
  • performing hands-on technical incident response
  • in-depth technical investigations
  • Threat Hunting
  • reading logs
  • collecting technical evidence
  • understanding of modern attacker methodologies
  • developing and maintaining operations playbooks, runbooks, and operational documentation
  • IT fundamentals across networking, system, cloud, virtualization platforms , application layers
  • understanding of at least one operating system (Windows, Linux, OSX)
  • interpersonal and communication skills

Nice to have

  • CompTIA Security+
  • Network+
  • CySA+
  • CCNA
  • CCNA CyberOps
  • GCIH
  • GCFR
  • GEIR
  • GCIA
  • GCFA
  • GCFE
  • GSEC
  • GCED
  • GREM
  • OSCP
  • OSCE

What the JD emphasized

  • hands-on technical incident response
  • Threat Hunting
  • digital forensics
  • hands-on keyboard perspective
  • detect, handle, investigate and effectively respond to cybersecurity incidents
  • assessing security incidents quickly
  • identifying adversary techniques, tactics, and procedures