- Location
- Katowice (Zabrska 19), Poland
- Type
- Full-time
- Experience
- 3+ years
- Source
- Workday
Description
ING Hubs Poland is hiring!
The expected salary for this position:
The financial ranges specified in the announcement are adjusted and may differ from the range specified in the remuneration regulations.
When a cyber incident hits ING, you identify and remove the threat.
As a Medior Incident Responder within ING's Global CSIRT (Security Defence Centre), you investigate cyber security incidents, analyse technical evidence, and support containment and remediation efforts across ING's global environment.
You work closely with senior incident responders, SOC analysts, detection engineers and technology teams to determine the scope, impact and root cause of security incidents. Beyond incident handling, you contribute to improving investigation methodologies, response tooling, automation and operational readiness.
The Global CISO organization of ING is responsible for assisting ING’s management, business and other tribes in providing customer-friendly services in a safe and secure way. Business leaders and CISO are jointly responsible for bank-wide security. CISO is mandated to drive required change in all domains, business and IT. Within CISO, the Security Defence Center (SDC) is responsible for security incident response and management as the Global CSIRT organization of ING.
How to Succeed
We are looking for you if you have:
- A university degree in Cybersecurity, Computer Science or a comparable discipline,
- 3-6 years of professional experience within Incident Response, Security Operations, Threat Detection, Threat Hunting or Digital Forensics,
- Strong understanding of security incident response methodologies and attacker techniques,
- Excellent understanding of IT platforms, networking, cloud technologies and application log data,
- Good understanding of security analytics, large-scale data analysis and technical investigations,
- Strong knowledge of current security technologies and emerging trends in detection and response,
- Hands-on experience with modern security tooling, XDRs and SOAR tooling,
- Good computer forensics skills across Windows, Linux, macOS and cloud environments,
- Experience analysing identity-related attacks, endpoint compromise and cloud-based incidents,
- Strong analytical and problem-solving skills,
- Good oral and written communication skills,
- The ability to simplify complex technical issues for a wider audience,
- The ability to continuously develop yourself and support the development of colleagues,
- Professional working proficiency in English (C1).
You'll get extra points for
- Experience in a financial or highly regulated environment,
- Knowledge of KQL, PowerShell, Python or similar automation and investigation tooling,
- Experience with threat hunting methodologies,
- Experience with cloud security incident response,
- Experience working within a CSIRT, MDR, DFIR or SOC environment.
Your responsibilities:
The Medior Incident Responder is responsible for:
- Investigating cyber security incidents using endpoint, identity, cloud, application and network telemetry,
- Working independently and collaboratively with teams to mitigate security incidents,
- Performing technical analysis using EDR, SIEM, SOAR and other security tooling,
- Determining the scope, impact and root cause of security incidents,
- Collecting, analysing and documenting technical evidence,
- Supporting containment, eradication and recovery activities during incident response,
- Performing threat hunting and proactive investigations based on emerging threats and intelligence,
- Taking up tasks to automate and improve security response activities,
- Identifying gaps in security detection and response capabilities and contributing improvement proposals,
- Contributing to response plans, investigation guides, playbooks and operational documentation,
- Supporting technical and tabletop incident response exercises,
- Working closely with global and local security teams, technology teams and other stakeholders,
- Contributing technical expertise to improve response tooling, processes and operational effectiveness,
- Supporting compliance, audit and regulatory requirements relevant to incident response services.
Information about the Team:
The Security Defence Centre (SDC) is ING's Global CSIRT and is responsible for the coordination and response of cyber security incidents across the organisation.
As part of an international team operating across multiple countries, you will contribute directly to incident investigations and response activities. Working alongside experienced responders and security specialists, you will help understand attacker behaviour, determine impact, identify affected assets and support remediation efforts.
The role naming convention in the global ING job architecture will be “Engineer IV”.