SOC Analyst (WAAP)

G-CORE INNOVATIONS SOCIETE A RESPONSABILITE LIMITEE

Kraków

Hybrid

PLN 90,000 - 130,000

Full time

9 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Competitive compensation
Hybrid/remote options
Global remote work (up to 45 days/yr)
Private medical insurance
Extra paid vacation
Life events support
Language courses
Modern offices with snacks

Job summary

Gcore WAAP poszukuje SOC Analysta do bieżących operacji bezpieczeństwa: monitorowanie ruchu i alertów, triage fałszywych pozytywów oraz przygotowywanie raportów dla klientów. Współpraca z Threat Researchers i eskalacja istotnych incydentów.

Wymagane jest zrozumienie podstaw bezpieczeństwa, umiejętność pracy z logami i dashboardami oraz komunikatywność w języku angielskim. Praca oferuje elastyczne godziny i opcje hybrydowe/remote.

Qualifications

  • Podstawowa wiedza o bezpieczeństwie sieci i aplikacji (WAF, DDoS, OWASP Top 10).
  • Analiza ruchu poprzez logi i pulpity nawigacyjne, potrafisz wykryć anomalie.
  • Umiejętność odróżniania złośliwego ruchu od ruchu legalnego i oceny false positives.
  • Dobra znajomość angielskiego w raportowaniu dla klienta.

Responsibilities

  • Monitorowanie WAAP i aktywności DDoS w kontach klientów; przeglądaj dashboards i alerty.
  • Triage fałszywych alarmów, ogranicz szum informacyjny dla klienta.
  • Przygotowywanie raportów zagrożeń dla klientów i eskalacja do odpowiednich zespołów.
  • Wspieranie onboarding klienta w konfiguracjach bezpieczeństwa zgodnie z playbookami.
  • Przestrzeganie SLA reakcji i raportowania po incydencie.

Skills

Web security fundamentals
WAF & DDoS
Traffic analysis
Log analysis
Incident response
English reporting

Education

Brak specjalistycznych wymagań edukacyjnych

Tools

Cloudflare
Akamai
Imperva
F5
Radware
SIEM
PagerDuty

Job description

Nasze wymagania:
  • Understanding of web security fundamentals: WAF, DDoS, bots, OWASP Top 10.
  • Solid basics in HTTP, TCP/IP, TLS.
  • Comfortable analyzing logs and reading dashboards; can spot anomalies in traffic.
  • Able to distinguish malicious from legitimate traffic and reason about false positives.
  • Clear written English for customer-facing reports.
  • Reliable, detail-oriented, and calm under incident pressure.
  • Willingness to work in a shift/on-call rotation.
Mile widziane:
  • Prior SOC L1/L2 or related experience.
  • Basic query/scripting: SQL-like log queries, regex, a bit of Python.
  • Familiarity with CDN/WAF platforms (Cloudflare, Akamai, Imperva, F5, Radware).
  • Exposure to SIEM / alerting tooling and PagerDuty-style on-call.
  • Security certifications (e.g. CompTIA Security+) - a plus, not a requirement.
  • Deep threat research, exploit development, malware reverse-engineering. That work stays with our Threat Researchers - this role feeds them clean, triaged signal and takes the routine off their plate.
O projekcie:

Gcore WAAP protects customer web applications and APIs against DDoS, bots, and application-layer attacks at CDN edge scale. We are building out a proactive, managed-support offering for enterprise customers, and we need a SOC Analyst to run the day-to-day security operations: watch traffic and alerts, triage false positives, prepare customer-facing threat reports, and elevate real impact to the right team. You will work alongside our Threat Researchers, taking the operational load off them so they can focus on deep analysis. You do not need to be a threat-hunting expert.

You need to be reliable, observant, comfortable in logs and dashboards, and able to tell an attack from legitimate traffic - and know when you should elevate.

Explicitly NOT Required

Deep threat research, exploit development, malware reverse-engineering. That work stays with our Threat Researchers - this role feeds them clean, triaged signal and takes the routine off their plate.

Why This Role Matters

You become the first line of Gcore WAAP's managed security operations - the person who keeps customers informed and protected day to day, and who lets our specialists focus on the hard problems. High visibility, direct customer impact, and a clear path to grow into threat research or detection engineering.

Zakres obowiązków:
  • Monitor WAAP and DDoS activity across customer accounts - dashboards, alerts, and traffic patterns - and recognize when something needs attention.
  • Triage false positives: review traffic flagged by security policies, confirm or dismiss, and keep noise down for customers (this is a large, daily part of the job).
  • Prepare reports: weekly threat summaries per customer and post-incident DDoS reports, in clear customer-facing English.
  • Alert and escalation: when an attack is impacting a customer, signal the engineering team or Support with the right context - e.g. a customer needs to be tagged or a policy adjusted - and follow the escalation runbook.
  • Support customer onboarding: apply standard security configuration based on the customer's profile (resource type, traffic volume, legitimate-traffic exclusions) following playbooks.
  • Follow the reaction-time SLA - our commitment to customers is speed of reaction and clear post-incident reporting, not a prevention guarantee.
  • Contribute to and maintain runbooks so responses are consistent and repeatable.
Oferujemy:
  • Competitive compensation
  • Flexible working hours and hybrid or remote options, depending on your role
  • Work from anywhere in the world for up to 45 days per year
  • Private medical insurance for you and your family*
  • Extra paid vacation and sick leave days*
  • Support for life’s important moments and celebrations
  • Language courses to help you connect and grow
  • Modern, welcoming offices with snacks, drinks, and entertainment*
  • Team sports and social activities*
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Analyst (WAAP)
SOC Analyst (WAAP)

Gcore • Kraków

On-site
PLN 114,000 - 136,000
Competitive compensation
Flexible hours & hybrid/remote options
Work from anywhere up to 45 days/year
+6
SOC Analyst (WAAP)
SOC Analyst (WAAP)

Gcore • Poland

On-site
PLN 114,000 - 136,000
Competitive compensation
Flexible working hours
Remote options depending on role
+2
SOC Analyst
SOC Analyst

Gcore • Kraków, Warszawa, Wrocław, Poznań

Hybrid
PLN 120,000 - 180,000
Competitive compensation
Hybrid or remote options
Work from anywhere (45 days/yr)
+6
SOC Tier 2 Analyst (Cybersecurity)
SOC Tier 2 Analyst (Cybersecurity)

Onwelo • Kielce

Hybrid
PLN 120,000 - 180,000
Elastyczne godziny pracy
Praca hybrydowa lub zdalna
Szkolenia i ścieżki rozwojowe
+1
Analityczka / Analityk ds. SOC (L1)
Analityczka / Analityk ds. SOC (L1)

Polskie Elektrownie Jądrowe sp. z o.o. • Warszawa

Hybrid
PLN 60,000 - 90,000
Praca hybrydowa
Atrakcyjne wynagrodzenie
Benefity pozapłacowe
Security Operator (SOC L1)
Security Operator (SOC L1)

DAGMA • Katowice

On-site
PLN 66,960 - 111,600
Grupowe ubezpieczenie na życie
Prywatna opieka medyczna
Karta sportowa
+2
Security Operations Analyst: WAAP & DDoS Defense
Security Operations Analyst: WAAP & DDoS Defense

Gcore • Kraków

Hybrid
PLN 114,000 - 136,000
Competitive compensation
Flexible hours & hybrid/remote options
Work from anywhere up to 45 days/year
+6
Security Operator (SOC L1)
Security Operator (SOC L1)

DAGMA Sp. z o. o. • Katowice

On-site
PLN 90,000 - 150,000
Szkolenia IT
Zatrudnienie na pełny etat
Profesjonalny zespół
+8
SOC Analyst Remote/Hybrid, Customer-Facing Incident Reports
SOC Analyst Remote/Hybrid, Customer-Facing Incident Reports

G-CORE INNOVATIONS SOCIETE A RESPONSABILITE LIMITEE • Kraków

Hybrid
PLN 90,000 - 130,000
Competitive compensation
Hybrid/remote options
Global remote work (up to 45 days/yr)
+5
Starsza Analityczka/Starszy Analityk ds. SOC (L2)
Starsza Analityczka/Starszy Analityk ds. SOC (L2)

Polskie Elektrownie Jądrowe sp. z o.o. • Warszawa

Hybrid
PLN 120,000 - 180,000
Możliwość rozwoju zawodowego
Praca w ambitnym zespole
System nagradzania i benefity pozapłac
+1