Relomote
Remote JobsRelocation Jobs
Add companySaved
Relomote

Relomote is a job board for remote, hybrid, and relocation jobs — every listing AI-classified for the countries it actually hires from, or the visa and relocation support it offers.

LinkedInCrunchbase

Remote jobs by category

  • Remote Engineering & Development jobs
  • Remote Customer Support jobs
  • Remote Design jobs
  • Remote Marketing jobs
  • Remote Sales jobs
  • Remote Product jobs
  • Remote Data & Analytics jobs
  • Remote People & Talent jobs
  • Remote Writing & Content Creation jobs
  • Remote Finance jobs
  • Remote Legal & Compliance jobs
  • Remote Operations & Admin jobs
  • Remote Data Entry jobs
  • Remote Virtual Assistant jobs
  • Remote Education/Training jobs
  • Remote Healthcare/Clinical jobs
  • Remote Other jobs

Remote jobs by location

  • Work from anywhere jobs
  • Remote jobs in Africa
  • Remote jobs in Asia
  • Remote jobs in Europe
  • Remote jobs in Latin America
  • Remote jobs in Middle East
  • Remote jobs in North America
  • Remote jobs in Oceania
  • All remote jobs →

Relocation & visa sponsorship

  • Visa sponsorship jobs
  • Relocation package jobs
  • Relocate to Europe
  • Relocate to Germany
  • Relocate to Netherlands
  • Relocate to Spain
  • Relocate to Portugal
  • Relocate to Greece
  • Relocate to United Kingdom
  • Relocate to Canada
  • Relocate to Australia
  • Relocate to Sweden
  • Relocate to Switzerland
  • Relocate to Japan
  • Relocate to United Arab Emirates
  • All relocation jobs →

© 2026 RelomoteAboutPrivacyTerms

Contact [email protected] · Built by Mahmoud

Relomote
Remote JobsRelocation Jobs
Add companySaved
Cegeka logo

Cyber Security Analyst II

Cegeka
Posted 5 hours ago
🇷🇴Romania🏠Remote📁Engineering & Development
Is this job info correct?

Our mission is to help people integrate technology into everyday life and to enable innovation through technology.

We offer software development and infrastructure solutions, with advanced competences in Blockchain, Artificial Intelligence and Machine Learning. All our offices (in Western Europe or nearshore, in CEE) are located within the boundaries of the European Union.

We believe working in close cooperation with our clients and employees is the key to success; this means we offer people the best working environment in order to achieve the best results. We love entrepreneurial spirits and encourage people around us to be proactive and make the best decisions not only for business, but for their own personal development.

Our nearshore Romanian offices are in Bucharest (Victoriei Square) and Iasi (Palace) and, with over 9000 team members at group level, we make sure we are always close to our customers.


What you will be working on:


The Cyber Security Incident Responder is a key player in providing detection, investigation and response to cyber security attacks and threats such as ransomware, spear-phishing, cloud-based attacks, and Advanced Persistent Threats (APTs). This highly specialized technical subject matter expert position focuses on investigating threats and alerts within large-scale cross-platform environments, performing threat hunting and digital forensics in order to identify intrusions and effectively respond to mitigate security threats on the business.


Key Responsibilities:


  • Responsible for investigating the incidents escalated by the 24/7 Triage & Monitoring team.
  • Assists the 24/7 Triage & Monitoring team with in-depth investigating cybersecurity alerts raised by a wide variety of security tools like: SOAR, EDR, XDR, IPS/IDS, SIEM, Sandbox, Cloud Security, Email Security, GitLab Security, Container Security.
  • Coordinates incident, response, escalation, and reporting of cybersecurity incidents.
  • Performs technical investigation on complex security incidents to achieve efficient mitigation for active threats and identification of the root cause.
  • Performs quality hands-on technical incident response, log analysis, and threat hunting.
  • Collaborates on various departmental projects that help the organization improve its cyber security posture and achieve its mission/objectives.
  • Collaborates with different CDR stakeholders and vendors to remediate any identified gaps.
  • Define and use CSIRT’s playbooks, runbooks, workflows, operational documentation, and processes. Contributes to the writing and maintenance of all such documents.
  • Looks for opportunities to improve documentation and standardization of CSIRT processes.
  • Owns and delivers on assigned projects (often around improvements to detections, processes and playbooks) while balancing execution and deliveries with operations and IR workload; Supports other team members in projects.
  • Drives continuous improvements of our detection and response capabilities quality and efficiency by identifying and owning improvement areas in the technology, methods, processes (including opportunities around detection tuning and automation).
  • Works on shifts covering 16/5 (Monday to Friday, 7 AM - 10 PM).
  • Offers on-call support during the nights, weekends and public holidays.


Requirements:


  • This role requires technology subject matter expertise in performing hands-on technical incident response, in-depth technical investigations and Threat Hunting. It is an individual who reads logs, collects technical evidence and puts together the full picture. The ideal candidate is well plugged in the world of hacking and defense and adversary techniques, all with a hands-on keyboard perspective.
  • 5+ years of operational security experience (SOC, Incident Response, Malware Analysis, etc.).
  • Bachelor's Degree OR equivalent experience and relevant certification (such as CompTIA Security+, Network+, CySA+, CCNA, CCNA CyberOps, GCIH, GCFR, GEIR, GCIA, GCFA, GCFE, GSEC, GCED, GREM, OSCP, OSCE, and similar).
  • Experience working independently to detect, handle, investigate and effectively respond to cybersecurity incidents.
  • Ability to assess security incidents quickly and communicate/coordinate a course of action to respond to the incident, while mitigating risk and limiting the impact.
  • Practical experience identifying adversary techniques, tactics, and procedures with enterprise security tools with a demonstrable understanding of modern attacker methodologies.
  • Experience developing and maintaining operations playbooks, runbooks, and operational documentation.
  • Robust understanding of IT fundamentals across networking, system, cloud, virtualization platforms application layers and advanced understanding of at least one operating system (Windows, Linux, OSX).
  • Excellent interpersonal and communication skills in order to share knowledge and to communicate effectively with different stakeholders (IT and business partners).
  • Experience with projects or issues of high complexity that require knowledge across multiple technical areas and business units.
  • Highly disciplined and motivated: a self-starter who is able to both work independently or as a member of a team.
  • Demonstrates a Can-Do, delivery-focused and solution-oriented approach (rather than problem-oriented); Flexible, practical, and positive mindset. Is quick to adapt to changing situations.
  • Constantly demonstrates ownership and proactiveness in seeking to improve and optimize in anything related to their and their team’s work.


Once on board we offer various programs and benefits:


  • 22 annual vacation days, 3 sick days that are not carried to the next year (no medical certificate required)
  • A seniority day is added every 3 years in the company
  • Floating days - free day for every public holiday that falls on the weekend, with the exception of holidays which always fall during the weekend
  • Annual Company Bonus prorated according to the number of worked months in a year
  • Private medical insurance
  • Access to an online benefit platform, with a monthly allowance of 690 RON, which you can choose to invest in different wellbeing, financial, or retail packages
  • Financial support for the birth of your child or unhappy events
  • A work culture based on cooperation and development - customized learning paths through external providers as well as special development programs.
  • We offer remote work flexibility, driven by smart working principles and aligned with team goals and values
  • Wellbeing initiatives to encourage a healthy work life balance through webinars, specialized sessions and internal programs, per our colleagues’ input


Similar jobs

Similar jobs

Nttdata logo

Cybersecurity Analyst with German

Nttdata

🇷🇴Romania2 weeks ago
Worldline logo

IT Security Analyst - Senior

Worldline

🇷🇴Romania3 weeks ago
Yopeso Romania SRL logo

Senior Cybersecurity Risk Analyst

Yopeso Romania SRL

🇷🇴Romania4 weeks ago
TechBiz Global GmbH logo

Cyber Security Analyst

TechBiz Global GmbH

🇷🇴RomaniaJul 23, 2026, 10:30 PM UTC
Synmatch AI logo

Cyber Security Analyst

Synmatch AI

🇷🇴RomaniaJul 8, 2026, 3:01 PM UTC
Autoliv Group logo

Global Information Security Governance, Risk & Compliance Analyst

Autoliv Group

🇷🇴RomaniaJul 5, 2026, 10:11 AM UTC