SOC Analyst (WAAP)

G-CORE INNOVATIONS SOCIETE A RESPONSABILITE LIMITEE

Deutschland

Hybrid

EUR 55.000 - 85.000

Vollzeit

Vor 7 Tagen
Sei unter den ersten Bewerbenden
Bewerbungsgenerator

Eine zielgenaue Bewerbung für diesen Job — ein maßgeschneiderter Lebenslauf und ein Anschreiben, die genau zur Stellenanzeige passen.

Schaffe es an den ATS-Filtern vorbei

Benefits dieser Stelle

Private medical insurance
Hybrid or remote options
Flexible working hours
Additional vacation and sick leave

Zusammenfassung

Gcore WAAP protects customer web applications and APIs against DDoS and bot attacks at CDN edge scale. We’re building a proactive, managed-support SOC, and seeking an analyst to monitor traffic, triage alerts, and prepare customer-ready threat reports.

You’ll pair with Threat Researchers, handling routine signals and enabling deeper analysis. Prior experience is helpful but not required; on-call rotation is part of the role.

Qualifikationen

  • Understanding of web security fundamentals: WAF, DDoS, bots, OWASP Top 10.
  • Solid basics in HTTP, TCP/IP, TLS.
  • Comfortable analyzing logs and reading dashboards; can spot anomalies in traffic.
  • Able to distinguish malicious from legitimate traffic and reason about false positives.
  • Clear written English for customer-facing reports.
  • Reliable, detail-oriented, and calm under incident pressure.
  • Willingness to work in a shift/on-call rotation.

Aufgaben

  • Monitor WAAP and DDoS activity across customer accounts - dashboards, alerts, and traffic patterns - and recognize when something needs attention.
  • Triage false positives: review traffic flagged by security policies, confirm or dismiss, and keep noise down for customers.
  • Prepare reports: weekly threat summaries per customer and post-incident DDoS reports, in clear customer-facing English.
  • Alert and elevate: when an attack is impacting a customer, signal the engineering team or Support with the right context - e.g. a customer needs to be tagged or a policy adjusted - and follow the escalation runbook.
  • Support customer onboarding: apply standard security configuration based on the customer's profile (resource type, traffic volume, legitimate-traffic exclusions) following playbooks.
  • Follow the reaction-time SLA - our commitment to customers is speed of reaction and clear post-incident reporting, not a prevention guarantee.
  • Contribute to and maintain runbooks so responses are consistent and repeatable.

Kenntnisse

Web security fundamentals
HTTP basics
TLS basics
Log analysis
Traffic anomaly detection
Customer reporting
Reliability
On-call rotation

Tools

SIEM
PagerDuty
CDN/WAF tools
Cloudflare
Akamai
Imperva

Jobbeschreibung

This position is available only under an employment (labor) agreement.

The world’s digital experiences run on something invisible: the infrastructure and software that keep them fast, reliable, and secure. At Gcore,you’ll help design and deliver that foundation for an AI-driven world.

We’re a global provider of infrastructure and software solutions forAI, cloud, network, and security,powering everything from real-time communication and streaming to enterprise AI and secure web applications. With210+ edge locations, 50+ cloud regions, and thousands of GPUs,your work here can reach users and businesses across the globe.

You’ll collaborate with leading technology partners such asIntel, NVIDIA, Dell, and Equinix,and work on platforms that power digital products used around the world. Our vision is simple: to connect the world to AI, anywhere, anytime.

Want to work on technology that goes beyond a single product or industry? Join a global team of550+ professionalsbuilding infrastructure and software that supports the entire digital ecosystem.

Job Description

Gcore WAAP protects customer web applications and APIs against DDoS, bots, and application-layer attacks at CDN edge scale. We are building out a proactive, managed-support offering for enterprise customers, and we need a SOC Analyst to run the day-to-day security operations: watch traffic and alerts, triage false positives, prepare customer-facing threat reports, and elevate real impact to the right team. You will work alongside our Threat Researchers, taking the operational load off them so they can focus on deep analysis. You do not need to be a threat-hunting expert.

You need to be reliable, observant, comfortable in logs and dashboards, and able to tell an attack from legitimate traffic - and know when to escape.

What You Will Do

  • Monitor WAAP and DDoS activity across customer accounts - dashboards, alerts, and traffic patterns - and recognize when something needs attention.
  • Triage false positives: review traffic flagged by security policies, confirm or dismiss, and keep noise down for customers (this is a large, daily part of the job).
  • Prepare reports: weekly threat summaries per customer and post-incident DDoS reports, in clear customer-facing English.
  • Alert and elevate: when an attack is impacting a customer, signal the engineering team or Support with the right context - e.g. a customer needs to be tagged or a policy adjusted - and follow the escalation runbook.
  • Support customer onboarding: apply standard security configuration based on the customer's profile (resource type, traffic volume, legitimate-traffic exclusions) following playbooks.
  • Follow the reaction-time SLA - our commitment to customers is speed of reaction and clear post-incident reporting, not a prevention guarantee.
  • Contribute to and maintain runbooks so responses are consistent and repeatable.
Qualifications

What We are Looking For

  • Understanding of web security fundamentals: WAF, DDoS, bots, OWASP Top 10.
  • Solid basics in HTTP, TCP/IP, TLS.
  • Comfortable analyzing logs and reading dashboards; can spot anomalies in traffic.
  • Able to distinguish malicious from legitimate traffic and reason about false positives.
  • Clear written English for customer-facing reports.
  • Reliable, detail-oriented, and calm under incident pressure.
  • Willingness to work in a shift/on-call rotation.

Nice to Have

  • Prior SOC L1/L2 or related experience.
  • Basic query/scripting: SQL-like log queries, regex, a bit of Python.
  • Familiarity with CDN/WAF platforms (Cloudflare, Akamai, Imperva, F5, Radware).
  • Exposure to SIEM / alerting tooling and PagerDuty-style on-call.
  • Security certifications (e.g. CompTIA Security+) - a plus, not a requirement.

Explicitly NOT Required

  • Deep threat research, exploit development, malware reverse-engineering. That work stays with our Threat Researchers - this role feeds them clean, triaged signal and takes the routine off their plate.

Why This Role Matters

You become the first line of Gcore WAAP's managed security operations - the person who keeps customers informed and protected day to day, and who lets our specialists focus on the hard problems. High visibility, direct customer impact, and a clear path to grow into threat research or detection engineering.

Additional Information

At Gcore, we want you to do your best work and enjoy the journey. Our benefits are designed to support your growth, well-being, and life beyond work:

  • Competitive compensation
  • Flexible working hours and hybrid or remote options, depending on your role
  • Work from anywhere in the world for up to45 days per year
  • Private medical insurance for you and your family*
  • Extra paid vacation and sick leave days*
  • Support for life’s important moments and celebrations
  • Language courses to help you connect and grow
  • Modern, welcoming offices with snacks, drinks, and entertainment*
  • Team sports and social activities*

*Benefits may vary depending on your location.

Equal Opportunity Employer

We provide equal opportunity to all applicants without regard to race, color, religion, sex, sexual orientation, age, gender identity, gender expression, national origin, disability, or any other legally protected characteristics.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Engineering Manager
Engineering Manager

G-CORE INNOVATIONS SOCIETE A RESPONSABILITE LIMITEE • Deutschland

Hybrid
EUR 90.000 - 135.000
Flexible working hours
Hybrid or remote options
Work from anywhere in the world for 45
+1
System Engineer
System Engineer

Aether Biomedical • Deutschland

Vor Ort
EUR 70.000 - 110.000
Competitive compensation
Hybrid or remote options depending on役
Security and Threat Operations Engineer
Security and Threat Operations Engineer

Jobtailor • Deutschland

Remote
EUR 90.000 - 120.000
Response Engineer - CMDC
Response Engineer - CMDC

Cloudflare • Deutschland

Hybrid
EUR 104.000 - 155.000
IT Customer Support Specialist
IT Customer Support Specialist

G-CORE INNOVATIONS SOCIETE A RESPONSABILITE LIMITEE • Deutschland

Hybrid
EUR 32.000 - 52.000
Remote, hybrid, or office work options
Work from anywhere in the world for up
Private medical insurance for you and/
+5
SOC Analyst (w/m/d) - Germany based
SOC Analyst (w/m/d) - Germany based

Kraken • Berlin

Hybrid
EUR 50.000 - 70.000
Flexible working hours
Share options
Hybrid work model
+6
AI Security Research & Red Team Engineer
AI Security Research & Red Team Engineer

Socket.dev • Deutschland

Hybrid
EUR 144.000 - 180.000
Equity plan
Staff Cybersecurity Analyst [599]
Staff Cybersecurity Analyst [599]

D-Wave Quantum • Deutschland

Hybrid
EUR 103.000 - 134.000
Cybersecurity Operations Center Analyst, Senior
Cybersecurity Operations Center Analyst, Senior

Booz Allen Hamilton • Wiesbaden

Vor Ort
EUR 85.000 - 194.000
Assoc. Security Engineer, AWS Customer Incident Response Team (CIRT)
Assoc. Security Engineer, AWS Customer Incident Response Team (CIRT)

Amazon Web Services (AWS) • München

Vor Ort
EUR 90.000 - 130.000