Skip to main content
Fever

Cyber Incident Response Analyst

RemoteArgentina only
Published
Role
Security
Experience
Mid
Employment
Full-time
Salary not disclosed
Check eligibility

Open to AR only. Set where you work from to check your eligibility.

No BS summary

Incident response/SOC analyst with 3+ years in security operations, alert triage, SIEM, EDR, SOAR automation, and cloud/SaaS/identity investigations. Must be fluent in English and based in Argentina.

Core skills

EDRSIEMSOAR

Required skills

MITRE ATT&CK

Optional skills

AWSGCPPythonBashDigital forensicsThreat intelligence platformsIOC management

Required languages

English Fluent; written and spoken required.

What you'll do

  • Triage, investigate, and resolve security alerts from EDR, SIEM, cloud security, identity, and SaaS sources.
  • Ensure accurate severity classification and timely response to security alerts.
  • Perform incident response activities including scoping, containment, evidence collection, remediation, and documentation.
  • Conduct remote forensics and live response evidence collection.
  • Build, maintain, and optimize SOAR playbooks and automation workflows.
  • Perform investigations and threat hunting across endpoint telemetry, cloud logs, and identity provider audit logs.
  • Tune existing detection rules and reduce false positives.
  • Develop new detections based on emerging threats and incident learnings.
  • Produce clear, structured incident reports.
  • Maintain investigation documentation to internal standards.
  • Collaborate with engineering and IT teams during investigations and remediation.
  • Communicate findings and required actions effectively.
  • Support continuous improvement of response procedures, playbooks, and severity/SLA criteria.
  • Participate in planning and follow-up meetings with other areas during onboarding.
  • Learn Fever's technological structure and ecosystem, including applications, cloud infrastructure, and architecture.
  • Learn Fever's detection and response processes, security tooling, and threat landscape.
  • Shadow ongoing alert triage and incident investigations during onboarding.
  • Independently triage and investigate security alerts across endpoint, identity, SaaS, and cloud sources after onboarding.
  • Perform containment and remediation actions under established procedures.
  • Document investigations following internal reporting and ticketing standards.
  • Identify false-positive patterns and propose tuning improvements to detection rules.
  • Contribute to development and refinement of SOAR playbooks for common alert types.
  • Take end-to-end ownership of incident investigations, including escalation decisions.
  • Design and implement new SOAR automation workflows to reduce manual triage effort.
  • Participate in post-incident reviews and drive improvements to response processes and playbooks.

What they require

  • Hands-on experience in a SOC or incident response role performing alert triage, investigation, and incident handling.
  • Knowledge of the incident response lifecycle.
  • Experience with EDR platforms for detection analysis, process tree investigation, and live response.
  • Experience working with a SIEM for log analysis and investigation, including writing and adapting queries.
  • Practical experience building or maintaining SOAR playbooks and security automation workflows.
  • Solid understanding of common attack techniques, malware delivery chains, phishing, and account takeover scenarios.
  • Familiarity with cloud environments and SaaS/identity log sources.
  • Strong analytical and problem-solving skills, with rigor in documenting findings.
  • 3+ years of experience in security operations, incident response, or similar hands-on cybersecurity roles.
  • Fluent in English, written and spoken.
  • Good communication skills.
  • Preferred: Bachelor's or Master's Degree in Computer Science, Information Security, or another similar relevant degree, or equivalent experience in a technical security role.
  • Preferred: Experience with cloud service providers and their security components.
  • Preferred: Scripting skills for automation and log parsing.
  • Preferred: Experience with digital forensics.
  • Preferred: Familiarity with threat intelligence platforms and IOC management.
  • Preferred: Blue team, incident response, CrowdStrike, or cloud security certifications.

Benefits

  • Relación de dependencia contract.
  • Opportunity to have a real impact in a high-growth global category leader.
  • 40% discount on all Fever events and experiences.
  • OSDE 410 as medical insurance.
  • Home office friendly anywhere in Argentina.
  • Responsibility from day one, and professional and personal growth.
  • Great work environment with a young, international team of talented people.
  • English lessons.
  • Gympass.
  • Attractive compensation package consisting of base salary and potential significant bonus for top performance.
EntertainmentStartup

Details

Apply routeGreenhouse
Salary not disclosed