SOC Analyst (WAAP)

Webhosting

Kraków

Hybrid

PLN 60,000 - 90,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Gcore is seeking a SOC Analyst to monitor WAAP and DDoS activity across customer accounts, review traffic patterns, and distinguish malicious events from legitimate traffic.

You will triage alerts, prepare weekly threat summaries in clear customer-facing English, escalate incidents with the proper context, and help maintain runbooks and onboarding playbooks for consistency and speed, while collaborating with Threat Researchers on enterprise-scale security operations.

Responsibilities

  • Monitor WAAP and DDoS activity across customer accounts – dashboards, alerts, and traffic patterns; recognize when something needs attention.
  • Triage false positives: review traffic flagged by security policies, confirm or dismiss, and reduce noise for customers.
  • Prepare reports: weekly threat summaries per customer and post-incident DDoS reports, in clear customer-facing English.
  • Alert and elevate: signal engineering or Support when an attack impacts a customer and follow the escalation runbook.
  • Support customer onboarding: apply standard security configuration based on the customer’s profile, following playbooks.

Job description

Not specified Full-time Not specified Operations

Job Description

Gcore WAAPprotects customer web applications and APIs against DDoS, bots, and application-layer attacks at CDN edge scale. We are building out a proactive, managed-support offering for enterprise customers, and we need a SOC Analyst to run the day-to-day security operations: watch traffic and alerts, triage false positives, prepare customer-facing threat reports, and elevate real impact to the right team. You will work alongside our Threat Researchers, taking the operational load off them so they can focus on deep analysis. You do not need to be a threat-hunting expert.

You need to be reliable, observant, comfortable in logs and dashboards, and able to tell an attack from legitimate traffic – and know when to elevate.

What You Will Do

  • Monitor WAAP and DDoS activity across customer accounts – dashboards, alerts, and traffic patterns – and recognize when something needs attention.
  • Triage false positives: review traffic flagged by security policies, confirm or dismiss, and keep noise down for customers (this is a large, daily part of the job).
  • Prepare reports: weekly threat summaries per customer and post-incident DDoS reports, in clear customer-facing English.
  • Alert and elevate: when an attack is impacting a customer, signal the engineering team or Support with the right context – e.g. a customer needs to be tagged or a policy adjusted – and follow the escalation runbook.
  • Support customer onboarding: apply standard security configuration based on the customer’s profile (resource type, traffic volume, legitimate-traffic exclusions) following playbooks.
  • Follow the reaction-time SLA – our commitment to customers is speed of reaction and clear post-incident reporting, not a prevention guarantee.
  • Contribute to and maintain runbooks so responses are consistent and repeatable.

This position is available only under an employment (labor) agreement.

The world’s digital experiences run on something invisible: the infrastructure and software that keep them fast, reliable, and secure. At Gcore,you’ll help design and deliver that foundation for an AI-driven world.

We’re a global provider of infrastructure and software solutions forAI, cloud, network, and security,powering everything from real-time communication and streaming to enterprise AI and secure web applications. With210+ edge locations, 50+ cloud regions, and thousands of GPUs,your work here can reach users and businesses across the globe.

You’ll collaborate with leading technology partners such asIntel, NVIDIA, Dell, and Equinix,and work on platforms that power digital products used around the world. Our vision is simple: to connect the world to AI, anywhere, anytime.

Want to work on technology that goes beyond a single product or industry?Join a global team of550+ professionalsbuilding infrastructure and software that supports the entire digital ecosystem.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Analyst
SOC Analyst

Gcore • Kraków, Warszawa, Wrocław, Poznań

Hybrid
PLN 120,000 - 180,000
Competitive compensation
Hybrid or remote options
Work from anywhere (45 days/yr)
+6
SOC Analyst: WAAP & DDoS Security Operations (Remote)
SOC Analyst: WAAP & DDoS Security Operations (Remote)

Gcore • Kraków, Warszawa, Wrocław, Poznań

Hybrid
PLN 120,000 - 180,000
Competitive compensation
Hybrid or remote options
Work from anywhere (45 days/yr)
+6
SOC Analyst: WAAP & DDoS Security Ops
SOC Analyst: WAAP & DDoS Security Ops

Webhosting • Kraków

Hybrid
PLN 60,000 - 90,000
SOC Analyst (WAAP)
SOC Analyst (WAAP)

Gcore • Poland

On-site
PLN 114,000 - 136,000
Competitive compensation
Flexible working hours
Remote options depending on role
+2
SOC Analyst (WAAP)
SOC Analyst (WAAP)

Gcore • Kraków

On-site
PLN 114,000 - 136,000
Competitive compensation
Flexible hours & hybrid/remote options
Work from anywhere up to 45 days/year
+6
SOC Analyst (WAAP)
SOC Analyst (WAAP)

G-CORE INNOVATIONS SOCIETE A RESPONSABILITE LIMITEE • Kraków

Hybrid
PLN 90,000 - 130,000
Competitive compensation
Hybrid/remote options
Global remote work (up to 45 days/yr)
+5
Remote SOC Analyst - Protect AI-Driven Web Apps & APIs
Remote SOC Analyst - Protect AI-Driven Web Apps & APIs

Gcore • Poland

Hybrid
PLN 114,000 - 136,000
Competitive compensation
Flexible working hours
Remote options depending on role
+2
Security Operations Analyst: WAAP & DDoS Defense
Security Operations Analyst: WAAP & DDoS Defense

Gcore • Kraków

Hybrid
PLN 114,000 - 136,000
Competitive compensation
Flexible hours & hybrid/remote options
Work from anywhere up to 45 days/year
+6
Cyber Security Analyst
Cyber Security Analyst

Sigma Software • Poland

On-site
PLN 60,000 - 80,000
SOC Analyst (L1/L2)
SOC Analyst (L1/L2)

UnderDefense LLC • Warszawa

On-site
PLN 120,000 - 180,000