Incident Response Senior Analyst

Analytics

Incident Response Senior Analyst

Analytics
Kapelanka 42A, Kraków

HSBC Service Delivery

Full-time
Permanent
Senior
Hybrid

Job description


Incident Response Senior Analyst

 


Your career opportunity


At HSBC, we are investing heavily across our Technology and Digital domains. Our global technology teams work closely with HSBC’s global businesses to help design and build digital services that allow our millions of customers around the world, to bank quickly, simply, and securely.


Operating within the Cybersecurity function and under the management of the Global Head of Cybersecurity Operations, the Global Cybersecurity Operations (GCO) team provides a coordinated suite of “Network Defence" related services and are responsible for the detection and response to information and cybersecurity threats across the global HSBC assets and estate


What you’ll do


  • Performing the technical and forensic investigations into cyber security events across the globe, taking responsibility for the timely identification of cyber-threats and where possible, minimising further risk to HSBC’s information assets and services.

  • Carrying out post-incident reviews, assessing the effectiveness of controls, detection and response capability and supporting the required improvements with the responsible owners.

  • Performing the forensic services for the collection, processing, preservation, analysis, and presentation of evidence in support of vulnerability mitigation and information security incident investigations.

  • Maintaining a strong awareness of technology trends and industry best practice, to enable the provision of informed advice and guidance to HSBC Business functions and HSBC IT.

  • Collaboration with the wider GCO teams (and wider business/function teams where applicable) in the production and maintenance of efficient and effective incident response playbooks.

  • Supporting the Identification, development and implementation of new detections (Use cases).

  • Developing and defining detailed processes and procedures to manage the response to cyber security events.

  • Directly contributing to the continued technical enhancement of the security platforms


What you need to have to succeed in this role


  • Excellent knowledge and demonstrated experience of common cybersecurity technologies such as; IDS / IPS / HIPS, Advanced Anti-malware prevention and analysis, Firewalls, Proxies, MSS, etc.

  • Excellent knowledge of common network protocols such as TCP, UDP, DNS, DHCP, IPSEC, HTTP, etc. and network protocol analysis suits.

  • Excellent knowledge of common enterprise technology infrastructure, platforms and tooling, including; Windows, Linux, infrastructure management and networking hardware.

  • Excellent knowledge and demonstrated experience in common cybersecurity incident response and forensic investigation tools such as: EnCase, FTK, Sleuthkit, Kali Linux, IDA Pro, DEFT, SANS SIFT, etc.

  • Very good knowledge and demonstrated experience in analysis and dissection of advanced attacker tactics, techniques and procedures in order to inform adjustments to the control plane.

  • Very good knowledge and demonstrated experience of common log management suites, Security Information and Event Management (SIEM) tools, use of “Big Data" and Cloud-based solution for the collection and real-time analysis of security information.

  • Good knowledge of common mobile platforms, such as Blackberry, iOS, Android and Windows.

  • Good knowledge of scripting, programming and/or development of bespoke tooling or solutions to solve unique problems.


What we offer


  • Competitive salary

  • Annual performance-based bonus

  • Additional bonuses for recognition awards

  • Multisport card

  • Private medical care

  • Life insurance

  • One-time reimbursement of home office set-up (up to 800 PLN).

  • Corporate parties & events

  • CSR initiatives

  • Nursery and kindergarten discounts

  • Financial support with trainings and education

  • Social fund

  • Flexible working hours 

  • Free parking


If your CV meets our criteria, you should expect the following steps in the recruitment process:


  • Online behavioural test 

  • Telephone screen 

  • Zoom interview with the hiring manager


We are looking to hire as soon as possible so don’t wait and apply now!

You'll achieve more when you join HSBC.


We thank all interested candidates for their applications. We reserve the right to contact only selected candidates.

Applications sent to us will be taken into consideration only if they include the following statement:

I hereby declare that I have familiarized myself with the Privacy Statement for Applicants published at http://www.about.hsbc.pl/careers and I hereby give consent for personal data included in my application to be processed for the purposes of recruitment in HSBC Service Delivery (Polska) Sp. z o. o. according to rules described in the Privacy Statement for Applicants, as per the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (GDPR).”

In case you would like to resign from participation in recruitment process or withdraw previously sent to us application, please email us at: krakow.recruitment@hsbc.com 


Tech stack

    English

    C1

    Analytics

    advanced

    Analytical Thinking

    advanced

    Cybersecurity

    advanced

    TCP

    advanced

    SIEM

    advanced

Office location

Published: 19.12.2025

Incident Response Senior Analyst

Summary of the offer

Incident Response Senior Analyst

Kapelanka 42A, Kraków
HSBC Service Delivery
By applying, I consent to the processing of my personal data for the purpose of conducting the recruitment process. Informujemy, że administratorem danych jest HSBC_ z siedzibą w Krakowie, ul. Kapelanka 42a (dalej jako "administrator"). Masz prawo do... MoreThis site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.