Information Security Specialist

Where exceptional talents scale what matters.

Swicon Minds is a curated community of 450+ senior top talents working on complex enterprise challenges, while operating within a stable, structured, and supportive ecosystem.

Talent Pool

Please provide your information!


Close

LEAP WITH CONFIDENCE.

SCALE THROUGH COMPETENCE.

Information Security Specialist

2026.02.24.

Summary

Bucharest, ROU

Hybrid

Medior

Introduction

Swicon Group is one of the leading members of the IT arena for almost a decade, since 2017 present also in Romania. Our wide range of services and highly trained professionals give us the opportunity to shape our solutions to fully meet the ideas and wishes of our clients. We are proud to have leading banks, insurance and telecommunication companies, as well as large FMCG corporations and SSCs amongst our highly prestigious partners.

Description

·       Act to enforce security and information protection policies;

·     Analyze and investigate security incidents assigned directly for resolution or posted in the dedicated application. Analyze and investigate customer complaints and reports regarding information security and confidentiality;

·       Utilize threat intelligence feeds to identify emerging risks and correlate with internal telemetry

·       Collect and disseminate intelligence across the organization to detect, prevent, and mitigate cyber threats

·       Provide assistance in receiving, addressing, and reporting critical security incidents;

·       Monitor, evaluate, and report on the evolution of threats and vulnerabilities of IT systems; Continuously monitor digital channels to identify phishing, smishing, and vishing campaigns.

·       Analyze and validate alerts, block malicious sources, and coordinate response actions with the SOC.

·       Improve detection scenarios and support simulated phishing programs.

·       Monitor customer transactions and user behavior to detect anomalies or potential fraud.

·       Investigate security incidents impacting customers (account takeover, unauthorized transactions, fraudulent actions).

·       Work with Payments, Fraud, and Digital Banking teams to improve customer protection measures.

·       Detect and investigate fake profiles impersonating bank employees or the corporate brand.

·       Initiate takedown procedures with platform providers and follow up on case progress.

·       Analyze social engineering trends and recommend preventive measures.

·       Conduct end-to-end investigations of security cases reported by customers: log analysis, URL review, header inspection, digital evidence gathering.

·       Identify the root cause of each incident and recommend remediation actions.

·       Provide clear, professional communication to Customer Care and Fraud teams regarding findings.

·       Investigate alerts related to privileged or sensitive users logging in outside standard business hours.

·       Validate the legitimacy of activities, escalate when needed, and document outcomes.

·       Tune alerts and collaborate with SOC to reduce false positives.

·       Prepare onboarding documentation (log sources, use cases, integration details, detection rules).

·       Configure log collection, set up secure connections, and validate the ingestion process.

·       Test data quality, define initial alerting rules, and document the full setup.

·       Gather, analyze, and disseminate indicators of compromise (IOCs), attack techniques (TTPs), and intelligence reports.

·       Integrate CTI into SIEM rules, phishing scenarios, investigation playbooks, and detection pipelines.

·       Collaborate with Group CTI teams and contribute to coordinated threat intelligence efforts.

·       Use your ability to create automation scripts (Python, PowerShell) for: log enrichment, vulnerability scanning, phishing‑email triage workflows

·       Ensure the provision of information and the introduction of the concept of security, education, and professional training;

·       Execute work related to responding to internal and external audit missions;

·       Participate in ensuring the security and protection of classified information;

Tasks

·       Act to enforce security and information protection policies;

·     Analyze and investigate security incidents assigned directly for resolution or posted in the dedicated application. Analyze and investigate customer complaints and reports regarding information security and confidentiality;

·       Utilize threat intelligence feeds to identify emerging risks and correlate with internal telemetry

·       Collect and disseminate intelligence across the organization to detect, prevent, and mitigate cyber threats

·       Provide assistance in receiving, addressing, and reporting critical security incidents;

·       Monitor, evaluate, and report on the evolution of threats and vulnerabilities of IT systems; Continuously monitor digital channels to identify phishing, smishing, and vishing campaigns.

·       Analyze and validate alerts, block malicious sources, and coordinate response actions with the SOC.

·       Improve detection scenarios and support simulated phishing programs.

·       Monitor customer transactions and user behavior to detect anomalies or potential fraud.

·       Investigate security incidents impacting customers (account takeover, unauthorized transactions, fraudulent actions).

·       Work with Payments, Fraud, and Digital Banking teams to improve customer protection measures.

·       Detect and investigate fake profiles impersonating bank employees or the corporate brand.

·       Initiate takedown procedures with platform providers and follow up on case progress.

·       Analyze social engineering trends and recommend preventive measures.

·       Conduct end-to-end investigations of security cases reported by customers: log analysis, URL review, header inspection, digital evidence gathering.

·       Identify the root cause of each incident and recommend remediation actions.

·       Provide clear, professional communication to Customer Care and Fraud teams regarding findings.

·       Investigate alerts related to privileged or sensitive users logging in outside standard business hours.

·       Validate the legitimacy of activities, escalate when needed, and document outcomes.

·       Tune alerts and collaborate with SOC to reduce false positives.

·       Prepare onboarding documentation (log sources, use cases, integration details, detection rules).

·       Configure log collection, set up secure connections, and validate the ingestion process.

·       Test data quality, define initial alerting rules, and document the full setup.

·       Gather, analyze, and disseminate indicators of compromise (IOCs), attack techniques (TTPs), and intelligence reports.

·       Integrate CTI into SIEM rules, phishing scenarios, investigation playbooks, and detection pipelines.

·       Collaborate with Group CTI teams and contribute to coordinated threat intelligence efforts.

·       Use your ability to create automation scripts (Python, PowerShell) for: log enrichment, vulnerability scanning, phishing‑email triage workflows

·       Ensure the provision of information and the introduction of the concept of security, education, and professional training;

·       Execute work related to responding to internal and external audit missions;

·       Participate in ensuring the security and protection of classified information;


Expectations

·       Education: Bachelor's Degree or higher;

·       Preferred, but not mandatory, certifications: CEH, SCCP, other specific IT and IT security technology courses and certifications;

·       Minimum 3 years’ experience in the field of Information Security;

·       Experience in cybersecurity, fraud prevention, SOC operations, or threat monitoring.

·       Strong understanding of phishing, social engineering, digital fraud, and security protocols.

·       Hands-on experience with SIEM platforms

·       Excellent analytical skills and attention to detail.

·       Ability to work with sensitive information and react quickly in critical situations.

·       Clear communication skills and the ability to translate technical findings into actionable recommendations.

·       English language proficiency.

Advantages

  • Scripting knowledge (Python, PowerShell) is a strong advantage.

Employer's offer

  • Excellent learning opportunities! Variety in your work and a fantastic, informal work atmosphere. 
  • A challenging environment that will stimulate you to grow as a professional! 
  • A great foundation for your career! 
  • Grow with us! Your role will develop over time, so you can increase your experience and responsibilities. So, you can advance faster and further in your future career. 
  • A friendly and welcoming work environment with an international working atmosphere where you can practice and learn new language skills with a diverse mix of colleagues and clients. 
  • A dynamic work environment with a culture that is open, innovative, and performance orientated. 
  • Hybrid working module.

Apply for this position

Are you suitable for this positon? Click on the apply button and upload your CV!

Share this position

Share this position on your social media platform to help a friend to find his/her dreamjob!

Information Security Specialist

Please provide your information!


Close

Similar Positions

Senior Dynamics 365 F&O Consultant

Remote2026.08.27.
ROU Bucharest remote senior Swicon Group is…

DCE Lead Engineer — Microsoft Dynamics 365 CE

Remote2026.08.27.
ROU Bucharest remote senior Swicon Group is…

Data Analyst

Hybrid2026.08.27.
ROU Bucharest hybrid medior Swicon Group is…

Mid-level Java Developers

Hybrid2026.08.27.
ROU Bucharest hybrid medior Swicon Group is…

Inginer Sisteme de Securitate

Hybrid2026.08.27.
ROU Bucharest hybrid medior Swicon Group is…

Junior BMS Engineer

OnSite2026.08.27.
ROU Bucharest onSite medior Swicon Group is…

Site Coordinator

OnSite2026.08.27.
ROU Bucharest onSite senior Swicon Group is…

Business Analyst (Claims)

Hybrid2026.08.26.
HUN Budapest hybrid medior Our partner provides…

Swicon Stories

Real people. Real challenges. Real impact.

„The whole hiring process was a really positive experience for me. I was given the opportunity to move forward professionally and to test myself in a new, more senior role. I was trusted from the start, and I had all the support I needed to take the next step in my career with confidence. They connected me with the right technical contact, and every question I had was answered quickly and clearly, so I never felt left on my own. Communication was smooth, each step built on the one before, and the whole process moved surprisingly fast and without a hitch.”

K. R. – Solution Architect

“Looking back over more than 15 years, Swicon gets top marks from me: it has built itself into a fast-growing multinational, and all the while it has backed its people professionally across the board — it even supported my PMP certification with a proper training course.”

B. T. – Sr. Projectmanager

“I’ve been working with SWICON for almost a year and a half now, and it’s been a positive experience from start to finish. Both the hiring process and the admin side of things ran smoothly, and whenever I had a question, help came quickly. I particularly appreciate how kind and helpful my colleagues are, and the fact that the company genuinely invests in building a community — there are regular programmes and events.
I’ve grown a lot professionally in my time here, too. My tasks and my responsibilities have kept widening, I’ve been able to take on more complex challenges, and I’ve also had the chance to support and mentor others. On the IT side I’ve been given opportunities that made a real difference to where I am professionally, so on the whole I see SWICON as a supportive place that gives you genuine room to grow.”

M. L. – Software developer

Powering mission – critical operations across Europe

200+

successful transformation programs

$1.5B

business value created

50M

secure transactions every month

20+

years of enterprise expertise

450+

senior experts

Trusted by enterprise leaders across the world

ROU Bucharest hybrid medior Swicon Group is one of the leading members of the IT arena for almost a decade, since 2017 present also in Romania. Our wide range of services and highly trained professionals give us the opportunity to shape our solutions to fully meet the ideas and wishes of our clients. We are proud to have leading banks, insurance and telecommunication companies, as well as large FMCG corporations and SSCs amongst our highly prestigious partners. ·       Act to enforce security and information protection policies;·     Analyze and investigate security incidents assigned directly for resolution or posted in the dedicated application. Analyze and investigate customer complaints and reports regarding information security and confidentiality;·       Utilize threat intelligence feeds to identify emerging risks and correlate with internal telemetry·       Collect and disseminate intelligence across the organization to detect, prevent, and mitigate cyber threats·       Provide assistance in receiving, addressing, and reporting critical security incidents;·       Monitor, evaluate, and report on the evolution of threats and vulnerabilities of IT systems; Continuously monitor digital channels to identify phishing, smishing, and vishing campaigns.·       Analyze and validate alerts, block malicious sources, and coordinate response actions with the SOC.·       Improve detection scenarios and support simulated phishing programs.·       Monitor customer transactions and user behavior to detect anomalies or potential fraud.·       Investigate security incidents impacting customers (account takeover, unauthorized transactions, fraudulent actions).·       Work with Payments, Fraud, and Digital Banking teams to improve customer protection measures.·       Detect and investigate fake profiles impersonating bank employees or the corporate brand.·       Initiate takedown procedures with platform providers and follow up on case progress.·       Analyze social engineering trends and recommend preventive measures.·       Conduct end-to-end investigations of security cases reported by customers: log analysis, URL review, header inspection, digital evidence gathering.·       Identify the root cause of each incident and recommend remediation actions.·       Provide clear, professional communication to Customer Care and Fraud teams regarding findings.·       Investigate alerts related to privileged or sensitive users logging in outside standard business hours.·       Validate the legitimacy of activities, escalate when needed, and document outcomes.·       Tune alerts and collaborate with SOC to reduce false positives.·       Prepare onboarding documentation (log sources, use cases, integration details, detection rules).·       Configure log collection, set up secure connections, and validate the ingestion process.·       Test data quality, define initial alerting rules, and document the full setup.·       Gather, analyze, and disseminate indicators of compromise (IOCs), attack techniques (TTPs), and intelligence reports.·       Integrate CTI into SIEM rules, phishing scenarios, investigation playbooks, and detection pipelines.·       Collaborate with Group CTI teams and contribute to coordinated threat intelligence efforts.·       Use your ability to create automation scripts (Python, PowerShell) for: log enrichment, vulnerability scanning, phishing‑email triage workflows·       Ensure the provision of information and the introduction of the concept of security, education, and professional training;·       Execute work related to responding to internal and external audit missions;·       Participate in ensuring the security and protection of classified information; ·       Act to enforce security and information protection policies;·     Analyze and investigate security incidents assigned directly for resolution or posted in the dedicated application. Analyze and investigate customer complaints and reports regarding information security and confidentiality;·       Utilize threat intelligence feeds to identify emerging risks and correlate with internal telemetry·       Collect and disseminate intelligence across the organization to detect, prevent, and mitigate cyber threats·       Provide assistance in receiving, addressing, and reporting critical security incidents;·       Monitor, evaluate, and report on the evolution of threats and vulnerabilities of IT systems; Continuously monitor digital channels to identify phishing, smishing, and vishing campaigns.·       Analyze and validate alerts, block malicious sources, and coordinate response actions with the SOC.·       Improve detection scenarios and support simulated phishing programs.·       Monitor customer transactions and user behavior to detect anomalies or potential fraud.·       Investigate security incidents impacting customers (account takeover, unauthorized transactions, fraudulent actions).·       Work with Payments, Fraud, and Digital Banking teams to improve customer protection measures.·       Detect and investigate fake profiles impersonating bank employees or the corporate brand.·       Initiate takedown procedures with platform providers and follow up on case progress.·       Analyze social engineering trends and recommend preventive measures.·       Conduct end-to-end investigations of security cases reported by customers: log analysis, URL review, header inspection, digital evidence gathering.·       Identify the root cause of each incident and recommend remediation actions.·       Provide clear, professional communication to Customer Care and Fraud teams regarding findings.·       Investigate alerts related to privileged or sensitive users logging in outside standard business hours.·       Validate the legitimacy of activities, escalate when needed, and document outcomes.·       Tune alerts and collaborate with SOC to reduce false positives.·       Prepare onboarding documentation (log sources, use cases, integration details, detection rules).·       Configure log collection, set up secure connections, and validate the ingestion process.·       Test data quality, define initial alerting rules, and document the full setup.·       Gather, analyze, and disseminate indicators of compromise (IOCs), attack techniques (TTPs), and intelligence reports.·       Integrate CTI into SIEM rules, phishing scenarios, investigation playbooks, and detection pipelines.·       Collaborate with Group CTI teams and contribute to coordinated threat intelligence efforts.·       Use your ability to create automation scripts (Python, PowerShell) for: log enrichment, vulnerability scanning, phishing‑email triage workflows·       Ensure the provision of information and the introduction of the concept of security, education, and professional training;·       Execute work related to responding to internal and external audit missions;·       Participate in ensuring the security and protection of classified information; ·       Education: Bachelor’s Degree or higher;·       Preferred, but not mandatory, certifications: CEH, SCCP, other specific IT and IT security technology courses and certifications;·       Minimum 3 years’ experience in the field of Information Security;·       Experience in cybersecurity, fraud prevention, SOC operations, or threat monitoring.·       Strong understanding of phishing, social engineering, digital fraud, and security protocols.·       Hands-on experience with SIEM platforms·       Excellent analytical skills and attention to detail.·       Ability to work with sensitive information and react quickly in critical situations.·       Clear communication skills and the ability to translate technical findings into actionable recommendations.·       English language proficiency. Scripting knowledge (Python, PowerShell) is a strong advantage. Excellent learning opportunities! Variety in your work and a fantastic, informal work atmosphere. A challenging environment that will stimulate you to grow as a professional! A great foundation for your career! Grow with us! Your role will develop over time, so you can increase your experience and responsibilities. So, you can advance faster and further in your future career. A friendly and welcoming work environment with an international working atmosphere where you can practice and learn new language skills with a diverse mix of colleagues and clients. A dynamic work environment with a culture that is open, innovative, and performance orientated. Hybrid working module.