Remote Incident Command Lead, CSIRT & Threat Hunting

Zscaler

Wrocław

On-site

PLN 180,000 - 320,000

Full time

8 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Time off plans
Parental leave options
Retirement options
In-office perks, and more!

Job summary

Zscaler in Poland is seeking an Incident Response Lead, CSIRT to join our Enterprise Security team. This remote role reports to the Senior Manager, CSIRT and serves as the incident commander during major security events, while steering our threat hunting program using open-source and commercial intelligence.

You will develop and deploy high-fidelity detections, mentor SOC analysts, and drive proactive security operations to protect customers and data across global environments.

Qualifications

  • Foundational AI/ML understanding and ability to position AI-driven solutions.
  • Experience leading major incident response efforts within a large organization, preferably a SaaS provider.
  • Experience collaborating across cross-functional departments to drive resolution of complex security issues.
  • Hands-on experience with SIEM, SOAR, and EDR tools and authoring detection logic using YARA-L.
  • Proven background translating technical security findings into clear executive summaries.
  • Bachelor's degree in Cybersecurity, Information Technology, or a related technical field.

Responsibilities

  • Serve as incident commander to lead and manage major security incidents through resolution.
  • Drive proactive threat hunting initiatives using open-source and commercial intelligence to discover hidden threats.
  • Develop, test, and deploy high-fidelity detection logic to enhance security monitoring.
  • Act as the primary technical escalation point for SOC analysts during designated coverage shifts.
  • Mentor team members and elevate overall SOC operational capabilities and incident response readiness.

Skills

AI/ML fundamentals
Incident response leadership
Cross-functional collaboration
SIEM/SOAR/EDR
YARA-L detection logic
Bachelor's degree in Cybersecurity/IT

Education

Bachelor's degree in Cybersecurity, Information Technology, or related field
Master's degree in Cybersecurity, Information Technology, or related field

Tools

SIEM
SOAR
EDR
YARA-L

Job description

Zscaler in Poland is seeking an Incident Response Lead, CSIRT to join our Enterprise Security team. This remote role reports to the Senior Manager, CSIRT and serves as the incident commander during major security events, while steering our threat hunting program using open-source and commercial intelligence.

You will develop and deploy high-fidelity detections, mentor SOC analysts, and drive proactive security operations to protect customers and data across global environments.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Incident Response Engineer – Threat Hunting
Security Incident Response Engineer – Threat Hunting

Sii Sweden AB • Warszawa

Hybrid
PLN 120,000 - 180,000
Remote Cyber Incident Response Lead: Malware & Forensics
Remote Cyber Incident Response Lead: Malware & Forensics

Atos SE • Bydgoszcz

Hybrid
PLN 169,061 - 253,592
World-class training and certifications
Flexible work environment
Opportunities for continuous growth and development
Remote Senior AI-Forward Technical Success Manager
Remote Senior AI-Forward Technical Success Manager

Zscaler • Poland

On-site
PLN 175,000 - 250,000
Health plans
Time off plans for vacation and sick
Parental leave options
+3
Senior Security Ops Lead - Incident Response & Cloud
Senior Security Ops Lead - Incident Response & Cloud

Jobtailor • Wrocław

On-site
PLN 180,000 - 240,000
Senior Incident Response Lead - Threat Hunting & Automation
Senior Incident Response Lead - Threat Hunting & Automation

Atlassian • Województwo pomorskie

Hybrid
PLN 180,000 - 260,000
Health resources
Volunteer days
Equity
Lead Cloud Security & Incident Response Engineer
Lead Cloud Security & Incident Response Engineer

Gainsight • Wrocław

Hybrid
PLN 279,000 - 318,000
Private medical care
Multisport Card
Remote work options
+3
Cyber Threat Engineer: 24/7 Incident Response (Poland)
Cyber Threat Engineer: 24/7 Incident Response (Poland)

Trustwave • Poland

On-site
PLN 130,000 - 210,000
Sport card
Vacation co-financing
Life insurance
+5
Security Engineer - Hybrid Incident Response & Forensics
Security Engineer - Hybrid Incident Response & Forensics

Sii Poland • Warszawa

Hybrid
PLN 180,000 - 240,000
Great Place to Work
Profit sharing
Medical care
+4
Security Engineer – Incident Response Team (f/m/x)
Security Engineer – Incident Response Team (f/m/x)

Sii Ukraїna TOV • Warszawa

On-site
PLN 120,000 - 180,000
Senior Incident Response Lead - 24/7 Security Operations
Senior Incident Response Lead - 24/7 Security Operations

Dun & Bradstreet • Warszawa

On-site
PLN 280,000 - 420,000