Mid Cybersecurity Engineer - CSIRT

Allegro.eu S.A.

Warszawa

Hybrid

PLN 260,000 - 380,000

Full time

21 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

MacBook Pro
Fringe benefits (cafeteria plan)
English classes
Training budget
Volunteer day off
Social events
Allegro Tech Meeting

Job summary

Allegro.eu S.A. is seeking a skilled security engineer to own and run threat intelligence, hunting, EDR, SOAR, and SIEM platforms in a high-availability global marketplace. You will deploy incident response agents and drive automated defenses across a massive cloud and on-prem environment.

Join a team with autonomy, responsible for threat detection, forensics, and remediation. The role emphasizes AI-assisted security, collaboration with IT and business teams, and continuous skill growth in a

Qualifications

  • Experience in SOC/CERT/CSIRT environments.
  • Experience using SOAR, EDR/XDR and SIEM systems.
  • Knowledge of current offensive and defensive security threats.
  • Hands-on with large-scale IT infrastructure and DevOps culture.
  • Familiarity with Linux (Ubuntu/Debian), Windows and macOS.
  • Designed, implemented or maintained security solutions.
  • Participated in security incident handling.
  • Able to communicate across organizational levels.
  • Understanding IT security technologies and their business impact.
  • Independent, end-to-end incident response capabilities.

Responsibilities

  • Monitor and triage security incidents from EDR/XDR, SIEM, and detection platforms 24/7 on-call.
  • Investigate and respond to endpoint and server threats.
  • Analyze and mitigate phishing campaigns targeting Allegro brands; coordinate takedowns and enrich IOCs.
  • Detect and respond to network-layer attacks including DDoS and password spraying.
  • Perform forensics and log correlation across multiple data sources to reconstruct timelines.
  • Enrich and correlate indicators of compromise using threat intel and asset inventories.
  • Investigate identity risks such as suspected account takeovers.
  • Document findings with evidence-based incident reports and MITRE ATT&CK mappings.
  • Coordinate remediation actions with IT, infrastructure, and business teams.
  • Continuously improve detection by tuning rules and updating threat intel.
  • Collaborate with brand protection and external partners against threats to Allegro.

Skills

SOC/CSIRT
SOAR/EDR/XDR/SIEM
Threat intel
IT infra/DevOps
Linux/Windows/macOS
Security design
Incident handling
Cross-team communication
Security tools
End-to-end IR
AI/Automation
Soft skills
AI security tools
Continuous learning
English proficiency

Job description

Important things for you

Flexible working hours in the hybrid model (4/1) - working hours start between 7:00 a.m. and 9:00 a.m. We also have 30 days of occasional remote work.


Annual bonus based on your annual performance and company results.


Our team is based in Warsaw, Poznań and Toruń.


About the job

Massive Scale & Security Challenges: Secure and optimize a world-class, cloud and on-prem environment handling thousands of requests per minute. This is high-availability, high-performance security engineering in practice.


Modern Tech Stack: Work within an advanced ecosystem where core technologies include specialized defensive and incident response security tools, automated SOAR playbooks, EDR/XDR systems, modern SIEM systems for logging, correlations and machine learning detection models, AI based security incident response agents.


True Ownership & Autonomy: We live by a \"you build it, you run it\" philosophy. You'll join an autonomous team with full ownership of your security services - from threat intelligence and hunting, EDR, SOAR, SIEM technologies to deploying custom incident response assistants.


Complex Architectural Puzzles: From securing distributed systems to tackling novel AI vulnerabilities, you'll solve complex engineering problems that directly protect a massive, real-time marketplace.


Skills required


  • Have experience working in SOC, CERT or CSIRT teams

  • Have experience using SOAR, EDR/XDR and SIEM systems

  • Possess and continuously develop knowledge of current offensive and defensive security threats

  • Have hands‑on experience working with modern, large-scale IT infrastructure and understand DevOps culture

  • Are familiar with the Linux systems (Ubuntu/Debian), Windows and MacOS

  • Have designed, implemented, developed, or maintained solutions that enhance security

  • Have participated in security incidents handling

  • Can communicate and collaborate effectively with people from different areas and levels of the organization

  • Understand the importance of IT security technologies, tools, and procedures, and their impact on the business

  • Demonstrate high independence and a self‑driven approach – you are capable of taking full, end‑to‑end incident response process, from investigation, evidence and log collection to final reporting and remediation guidance

  • Are keen on leveraging automation and AI‑assisted techniques to improve incident response, detection rules tuning and innovate defensive techniques.

  • Are open to developing soft skills and embracing a growth mindset through active participation in team retrospectives and cross‑team collaborations;

  • Are excited about adopting and securing AI technologies, being ready to incorporate AI coding and security assistants into their daily work to maximize efficiency;

  • Want to constantly develop and update their knowledge in a rapidly shifting threat landscape;

  • Know English at at least B2 level.


Your main responsibilities:


  • Monitor and triage security incidents generated by EDR/XDR, SIEM and other detection platforms to identify true positive incidents in real time, 24/7 on-call rotation.

  • Investigate and respond to endpoint and server threats such as malicious behavior on corporate workstations and servers.

  • Analyze and mitigate phishing campaigns targeting Allegro brands (Allegro, Allegro Lokalnie, AllegroPay) - identifying malicious domains impersonating the company, coordinating takedown requests, and enriching related IOCs.

  • Detects and responds to network-layer attacks, including DDoS attempts, password spraying, abnormal BOT scanning.

  • Perform digital forensics and log correlation across multiple data sources (Active Directory sign‑ins, endpoint and server logs, proxy, DNS, VPN, DHCP logs) to reconstruct attack timelines and root cause.

  • Enrich and correlate Indicators of Compromise (IPs, domains, hashes, URLs) using threat intelligence platforms and internal asset inventories to assess scope and impact.

  • Investigate identity-related risks, such as suspected account takeovers, impersonation, and anomalous user behavior flagged by identity protection tools.

  • Document findings and produce evidence‑based incident reports, including root cause analysis, MITRE ATT&CK mapping, and remediation recommendations for stakeholders and asset owners.

  • Coordinate remediation actions with IT, infrastructure, and business teams (e.g. account lockouts, endpoint isolation, credential resets, domain blocking).

  • Continuously improve detection capabilities by tuning correlation rules, updating threat intelligence, and identifying gaps based on recurring incident patterns.

  • Collaborate with brand protection and external partners to detect and respond to threats against Allegro’s reputation and customers.


What's in it for you:


  • Well‑located offices (with e.g. fully equipped kitchens, bicycle parking, terraces full of greenery) and excellent work tools (e.g., raised desks, ergonomic chairs, interactive conference rooms).

  • A 16\\" or 14\\" MacBook Pro or corresponding Dell with Windows (if you don't like Macs) and all the necessary accessories.

  • A wide selection of fringe benefits in a cafeteria plan - you choose what you like (e.g., medical, sports or lunch packages, insurance, purchase vouchers).

  • English classes that we pay for related to the specific nature of your job.

  • A training budget, inter‑team tourism ( see more here ), hackathons, and an internal learning platform where you will find multiple trainings.

  • An additional day off for volunteering, which you can use alone, with a team, or with a larger group of people connected by a common goal.

  • Social events for Allegro people - Spin Kilometers, Family Day, Fat Thursday, Advent of Code, and many other occasions we enjoy.

  • And that's just the beginning! You can read more about the benefits here .


#goodtobehere means that:


  • You will join a team you can count on - we work with top‑class specialists who have knowledge- and experience-sharing in their DNA.

  • You will love our level of autonomy in team organization, the space for continuous development, and the opportunity to try new things. You get to choose which technology solves the problem and you are responsible for what you create.

  • You will be equipped with modern AI tools to automate repetitive tasks, allowing you to focus on analyzing complex threats, developing advanced security automation, and refining secure architectures.

  • You will meet the Allegro Scale, which starts with over 1000 microservices, an open‑source data bus (Hermes) with 300K+ rps, a Service Mesh with 1M+ rps, tens of petabytes of data, and production‑used machine learning.

  • You will become part of Allegro Tech - We speak at industry conferences, cooperate with tech communities, run our own blog (it's been over 10 years!), record podcasts, lead guilds, and we organize our own internal conference - the Allegro Tech Meeting. We create solutions we love (and can) to talk about!


Don’t wait until you join us! Let's meet online!

Get to know our team, take a peek at our office life and check out what else we do at Allegro.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Site Reliability Engineer
Senior Site Reliability Engineer

Allegro.eu S.A. • Warszawa

Hybrid
PLN 260,000 - 460,000
Flexible hours
RSUs
Annual bonus
+7
Junior Data Scientist
Junior Data Scientist

Allegro.eu S.A. • Warszawa

Hybrid
PLN 125,000 - 170,000
MacBook Pro
Fringe benefits plan
English classes
+3
Data Scientist
Data Scientist

Allegro.eu S.A. • Poznań

Hybrid
PLN 120,000 - 180,000
Flexible hybrid model (4/1)
30 days remote work
Annual bonus
+7
Senior Software Engineer (Java / Kotlin) - Product Page
Senior Software Engineer (Java / Kotlin) - Product Page

Allegro • Toruń

Hybrid
PLN 210,000 - 3,469,000
Annual bonus
RSUs (Allegro shares)
MacBook Pro or Dell laptop
+4
Manager, Engineering (Java / Kotlin) – Allegro Ads
Manager, Engineering (Java / Kotlin) – Allegro Ads

Allegro.eu S.A. • Poznań

Hybrid
PLN 320,000 - 520,000
Hybrid work model
Annual bonus
RSU incentives
+1
Senior Software Engineer (.NET/C#) - Logistics team
Senior Software Engineer (.NET/C#) - Logistics team

Allegro.eu S.A. • Warszawa

Hybrid
PLN 210,000 - 289,000
Dell Laptop
Fringe benefits cafeteria plan
English classes
+4
Software Engineer 2 (Java/Kotlin) – Offer Verification
Software Engineer 2 (Java/Kotlin) – Offer Verification

Allegro.eu S.A. • Warszawa

Hybrid
PLN 163,000 - 232,000
MacBook Pro or Dell laptop
Training budget
English classes
+2
Engineering Manager (Fullstack Team) - Allegro Ads
Engineering Manager (Fullstack Team) - Allegro Ads

Allegro • Warszawa

Hybrid
PLN 270,000 - 380,000
Hybrid work
MacBook Pro
Cafeteria plan
+4
Engineering Manager
Engineering Manager

Allegro • Warszawa

Hybrid
PLN 320,000 - 480,000
Annual bonus
RSUs / long-term incentive plan
Hybrid work model (4/1) with 30 days遠
+2
Manager, Engineering (Fullstack Team) - Allegro Ads
Manager, Engineering (Fullstack Team) - Allegro Ads

Allegro.eu S.A. • Warszawa

Hybrid
PLN 260,000 - 380,000
Well-located offices
MacBook Pro / Dell equipment
Fringe benefits cafeteria plan
+4