Incident Response Analyst

21 hours ago


Bucharest, Bucureşti, Romania CrowdStrike Full time 60,000 - 80,000 per year

As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn't changed — we're here to stop breaches, and we've redefined modern security with the world's most advanced AI-native platform. Our customers span all industries, and they count on CrowdStrike to keep their businesses running, their communities safe and their lives moving forward. We're also a mission-driven company. We cultivate a culture that gives every CrowdStriker both the flexibility and autonomy to own their careers. We're always looking to add talented CrowdStrikers to the team who have limitless passion, a relentless focus on innovation and a fanatical commitment to our customers, our community and each other. Ready to join a mission that matters? The future of cybersecurity starts with you.

About The Role
The Incident Response Defensive Operations (IRDO) team is seeking a detail-oriented, proactive Analyst to help drive strategic improvements to our Cybersecurity Incident Response program. This role is designed for someone who thrives at the intersection of operations, project management, and technical problem-solving.

You'll work alongside Incident Response analysts and engineers to identify pain points in existing workflows, close capability gaps, and manage high-impact projects that enhance the efficiency, effectiveness, and overall analyst experience of the Cybersecurity IR team. You'll also serve as a key liaison with our Threat Detection and Engineering (TIDE) team, ensuring smooth collaboration on detection engineering, automation, and improvements to our IR tooling.

As part of this role, you'll also contribute to the CSIRT Attack Surface Management program - an initiative focused on evaluating and improving the organisation's ability to detect and respond to threats across critical domains including email, applications, networks, and endpoints.

What You'll Do

  • Analyse incident response workflows to identify inefficiencies and friction points; propose and implement improvements.
  • Investigate operational and technical capability gaps - such as containment or access limitations and coordinate efforts to close them.
  • Lead and support cross-functional projects aimed at improving IR tooling, processes, and analyst experience.
  • Build or coordinate the development of workflow automations that reduce manual overhead and streamline response processes.
  • Contribute to the CSIRT Attack Surface Management program by assessing detection coverage, visibility, and response readiness across key attack surfaces.
  • Serve as the intermediary between the IR team and TIDE, translating analyst needs into actionable engineering requirements and helping prioritize improvements.
  • Maintain visibility on evolving IR needs and ensure proactive delivery of scalable, reliable operational enhancements.

What You'll Need
Education & Experience:

  • Bachelor's Degree (or equivalent experience) in a computer-related field
  • 3-5 years of experience in cybersecurity operations, incident response, or a similar domain (or equivalent combination of education and experience).
  • Hands-on experience with workflow automation - such as building automation playbooks, creating scripts, or leveraging tools like TINES, AWS Lambda, or SOAR platforms.

Technical Expertise

  • Hands-on experience with workflow automation—such as building automation playbooks, creating scripts, or leveraging tools like TINES, AWS Lambda, or SOAR platforms.
  • Build or coordinate the development of workflow automations that reduce manual overhead and streamline response processes
  • Experience with ServiceNow, Jira, or similar workflow/ticketing tools
  • Strong IT background (networking fundamentals, systems) and expertise with OSX
  • Strong analytical and problem-solving skills with a passion for operational efficiency.
  • Experience with project management or process improvement in a technical environment.
  • Excellent communication and interpersonal skills; ability to interface with both technical and non-technical stakeholders.
  • Familiarity with cybersecurity technologies and concepts, particularly incident response, containment, and automation.

Analytical & Communication Skills

  • Effective communication skills in English (verbal and written)
  • Ability to maintain strict confidentiality and operate independently in high-pressure situations

Preferred Skills & Attributes

  • Scripting knowledge (e.g., Python, Perl, Bash, PowerShell)
  • Familiarity with Splunk or other advanced SIEM platforms
  • Experience with host and network forensics
  • Familiarity with agile project management and compliance frameworks
  • Technical security certifications or advanced academic credentials

Benefits Of Working At CrowdStrike

  • Remote-friendly and flexible work culture
  • Market leader in compensation and equity awards
  • Comprehensive physical and mental wellness programs
  • Competitive vacation and holidays for recharge
  • Paid parental and adoption leaves
  • Professional development opportunities for all employees regardless of level or role
  • Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections
  • Vibrant office culture with world class amenities
  • Great Place to Work Certified across the globe

CrowdStrike is proud to be an equal opportunity employer. We are committed to fostering a culture of belonging where everyone is valued for who they are and empowered to succeed. We support veterans and individuals with disabilities through our affirmative action program.

CrowdStrike is committed to providing equal employment opportunity for all employees and applicants for employment. The Company does not discriminate in employment opportunities or practices on the basis of race, color, creed, ethnicity, religion, sex (including pregnancy or pregnancy-related medical conditions), sexual orientation, gender identity, marital or family status, veteran status, age, national origin, ancestry, physical disability (including HIV and AIDS), mental disability, medical condition, genetic information, membership or activity in a local human rights commission, status with regard to public assistance, or any other characteristic protected by law. We base all employment decisions--including recruitment, selection, training, compensation, benefits, discipline, promotions, transfers, lay-offs, return from lay-off, terminations and social/recreational programs--on valid job requirements.

If you need assistance accessing or reviewing the information on this website or need help submitting an application for employment or requesting an accommodation, please contact us at for further assistance.



  • Bucharest, Bucureşti, Romania Orange Full time 30,000 - 60,000 per year

    Locul de muncă: BucharestHow would you like to work in IT & Communication, toying with cutting edge technologies and enjoying your life? Come closer to #LifeAtOrange.What we're looking forWe are looking for a Security Incident Operations Analyst to join our Information Security department. The right candidate is analytical, responsive, and committed to...


  • Bucharest, Bucureşti, Romania Acronis Full time €15,000 - €30,000 per year

    Acronis is revolutionizing cyber protection—providing natively integrated, all-in-one solutions that monitor, control, and protect the data that businesses and lives depend on. We are looking for a MDR Analyst to join our mission to create a #CyberFit future and protect all data, applications and systems across any environment.The Junior/Mid MDR Analyst is...


  • Bucharest, Bucureşti, Romania Booking Holdings Full time 30,000 - 60,000 per year

    Booking Holdings Romania is a Center of Excellence based in Bucharest, Romania and was created to support the increasing business demands of the Booking Holdings Brands. The Center of Excellence provides access to specialized and highly skilled talent, leading industry best practices, and collaboration opportunities across all of our Brands.As part of our...

  • SOC Analyst

    6 days ago


    Bucharest, Bucureşti, Romania Prohuman Romania Full time €15,000 - €30,000 per year

    We are hiring aSOC Analystfor our client, a leading global organization in the insurance and risk management industry. Technology plays a strategic role in their mission to build more resilient societies, and their growing international tech team is central to delivering innovative and secure solutions.Job SummaryAs a SOC Analyst, you will be responsible for...

  • Cyber Threat Analyst

    2 weeks ago


    Bucharest, Bucureşti, Romania Throne Solutions Full time €30,000 - €60,000 per year

    Job Title:Cyber Threat Analyst / Soc AnalystLocation:Bucharest, Romania (Onsite)Employment Type:Full-time / W2 ContractStart Date:As early as possibleAbout the Role:Throne Solutions is seeking a skilled and analytical Cyber Threat Analyst to join our cybersecurity operations team in Bucharest. In this role, you will be responsible for monitoring, detecting,...

  • SOC Analyst

    1 week ago


    Bucharest, Bucureşti, Romania SCOR Full time 20,000 - 40,000 per year

    At our brand-new Shared Business Platform (SBP) in Bucharest, we offer a dynamic environment where career growth is actively supported through internal mobility, globally recognized certifications, and continuous professional development. We value work–life balance, offering flexible work arrangements, and wellbeing initiatives that help you thrive both...


  • Bucharest, Bucureşti, Romania Societe Generale Full time €40,000 - €60,000 per year

    ResponsibilitiesWithin the Société Générale Group, GTPS offers a complete and integrated range of services based on the expertise of Transaction Banking and Payments Services.GFL is the flow management department within GTPS.The Incident Coordination Unit (CCI) is a major cross-functional function within GFL's business lines, responsible for supporting...


  • Bucharest, Bucureşti, Romania Société Générale Full time 20,000 - 40,000 per year

    Incident Coordinator with Frenchandnbsp;andnbsp;ResponsibilitiesWithin the Sociandeacute;tandeacute; Gandeacute;nandeacute;rale Group, GTPS offers a complete and integrated range of services based on the expertise of Transaction Banking and Payments Services.GFL is the flow management department within GTPS.The Incident Coordination Unit (CCI) is a major...


  • Bucharest, Bucureşti, Romania LSEG Full time €30,000 - €60,000 per year

    About Us:LSEG (London Stock Exchange Group) is more than a diversified global financial markets infrastructure and data business. We are dedicated, open-access partners with a dedication to excellence in delivering the services our customers expect from us. With extensive experience, deep knowledge and worldwide presence across financial markets, we enable...


  • Bucharest, Bucureşti, Romania SiriusXM Full time 30,000 - 60,000 per year

    Responsibilities:Who We Are:SiriusXM and its brands (Pandora, SiriusXM Media, AdsWizz, Simplecast, and SiriusXM Connect) are leading a new era of audio entertainment and services by delivering the most compelling subscription and ad-supported audio entertainment experience for listeners - in the car, at home, and anywhere on the go with connected devices....