Threat Research Analyst

Sigmasoftware2

Poland

On-site

PLN 120,000 - 180,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Sigmasoftware2 in Poland is seeking a seasoned cybersecurity threat researcher to join our security team. You will monitor threats, analyze patterns, and respond to incidents using logs, dashboards, and detection systems.

You will build threat scenarios and document methodologies while collaborating with engineering to enhance product protection. A strong background in web security, SQL, Kibana/Elasticsearch, and English (B2+) is required.

Qualifications

  • At least 3 years of commercial experience in cybersecurity, threat research, or related areas.
  • Hands-on experience in cybersecurity, threat detection, security research, threat hunting, anti-bot solutions, fraud and abuse detection, application security, or a closely related security domain.
  • Strong understanding of attacker tactics, techniques, and behaviors, including methods used to evade, bypass, or modify attacks to avoid detection.
  • Experience investigating suspicious or malicious activities, with a solid understanding of detection, alerting, and blocking mechanisms.
  • Strong understanding of web technologies and architecture, including: Client-server architecture
  • HTTP/HTTPS protocols
  • REST APIs and web services
  • Request/response lifecycle
  • Headers, cookies, sessions, and authentication mechanisms
  • Understanding of browser technologies and experience investigating: DOM structure and manipulation
  • Browser events
  • XHR and Fetch requests
  • WebSockets
  • Browser APIs
  • Browser security policies and controls
  • Ability to read and analyze JavaScript code, identify application behavior, detect suspicious or incorrect logic, and understand potential remediation approaches. Deep JavaScript development expertise is not required.
  • Working knowledge of HTML and CSS sufficient to investigate and understand web application behavior.
  • Strong practical experience with SQL for data analysis, investigations, and working with large datasets.
  • Hands-on experience using Kibana for log analysis, monitoring, and investigations.
  • Solid understanding of networking fundamentals, including: TCP/IP
  • DNS
  • VPN technologies
  • Proxies
  • Basic network troubleshooting
  • Ability to independently investigate complex technical issues and correlate multiple data points to build a complete attack or incident scenario.
  • Experience using AI-powered tools and chatbots for research and technical investigations, including the ability to write effective prompts and interpret results.
  • Upper-Intermediate (B2) or higher level of English.

Responsibilities

  • Monitor existing threats and investigate suspicious activities using logs, dashboards, and detection systems
  • Analyze attack patterns and build detailed threat scenarios based on collected data
  • Research and respond to reported threats, customer escalations, and security incidents
  • Improve detection and blocking mechanisms for automated attacks and malicious behaviors
  • Analyze intelligence from competitors, public sources, and industry trends to identify emerging threats
  • Work with monitoring and analytics tools such as Kibana and Elasticsearch
  • Collaborate with engineering and security teams to improve product protection capabilities
  • Document findings, attack methodologies, and investigation results

Skills

Threat detection
Threat hunting
Security investigations
SQL
Kibana
Elasticsearch
Python scripting
AI-assisted research
English (B2+)

Tools

Kibana
Elasticsearch
SQL
Python scripting

Job description

Responsibilities
  • Monitor existing threats and investigate suspicious activities using logs, dashboards, and detection systems
  • Analyze attack patterns and build detailed threat scenarios based on collected data
  • Research and respond to reported threats, Customer escalations, and security incidents
  • Improve detection and blocking mechanisms for automated attacks and malicious behaviors
  • Analyze intelligence from competitors, public sources, and industry trends to identify emerging threats
  • Work with monitoring and analytics tools such as Kibana and Elasticsearch
  • Collaborate with engineering and security teams to improve product protection capabilities
  • Document findings, attack methodologies, and investigation results
Qualifications
  • At least 3 years of commercial experience in cybersecurity, threat research, or related areas
  • Hands-on experience in cybersecurity, threat detection, security research, threat hunting, anti-bot solutions, fraud and abuse detection, application security, or a closely related security domain.
  • Strong understanding of attacker tactics, techniques, and behaviors, including methods used to evade, bypass, or modify attacks to avoid detection.
  • Experience investigating suspicious or malicious activities, with a solid understanding of detection, alerting, and blocking mechanisms.
  • Strong understanding of web technologies and architecture, including: Client-server architecture
  • HTTP/HTTPS protocols
  • REST APIs and web services
  • Request/response lifecycle
  • Headers, cookies, sessions, and authentication mechanisms
  • Understanding of browser technologies and experience investigating: DOM structure and manipulation
  • Browser events
  • XHR and Fetch requests
  • WebSockets
  • Browser APIs
  • Browser security policies and controls
  • Ability to read and analyze JavaScript code, identify application behavior, detect suspicious or incorrect logic, and understand potential remediation approaches. Deep JavaScript development expertise is not required.
  • Working knowledge of HTML and CSS sufficient to investigate and understand web application behavior.
  • Strong practical experience with SQL for data analysis, investigations, and working with large datasets.
  • Hands-on experience using Kibana for log analysis, monitoring, and investigations.
  • Solid understanding of networking fundamentals, including: TCP/IP
  • DNS
  • VPN technologies
  • Proxies
  • Basic network troubleshooting
  • Ability to independently investigate complex technical issues and correlate multiple data points to build a complete attack or incident scenario.
  • Experience using AI-powered tools and chatbots for research and technical investigations, including the ability to write effective prompts and interpret results.
  • Upper-Intermediate (B2) or higher level of English.
WILL BE A PLUS
  • Understanding of Elasticsearch and its ecosystem.
  • Python scripting and automation skills.
  • Experience developing, analyzing, or investigating crawlers, scrapers, or browser automation tools.
  • Experience with deobfuscation and/or reverse engineering techniques.
  • Experience investigating bot traffic, automated attacks, scraping activity, credential stuffing, account takeover attempts, abuse, fraud, or similar threats.
  • Experience with monitoring, analytics, and observability platforms such as Datadog, Imply, Splunk, Microsoft Sentinel, OpenSearch, or similar tools.
PERSONAL PROFILE
  • Strong analytical and investigative mindset
  • Attention to detail and ability to identify unusual behavioral patterns
  • Curiosity about cybersecurity threats and attacker techniques
  • Ability to work independently in a fast-paced environment
  • Strong communication and collaboration skills
  • Proactive approach to problem-solving and continuous learning
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Analyst
Cyber Security Analyst

Sigma Software • Poland

On-site
PLN 60,000 - 80,000
Lead Security Operations Engineer
Lead Security Operations Engineer

Jobtailor • Wrocław

On-site
PLN 180,000 - 240,000
Security Detection Engineer
Security Detection Engineer

SoftServe • Poland

On-site
PLN 180,000 - 280,000
Senior Cyber Security Analyst - EMEA
Senior Cyber Security Analyst - EMEA

Internetwork Expert • Warszawa

On-site
PLN 218,978 - 364,964
Flexible Working Hours
Remote Work
Modern Development Workflows
+2
Cyber Security Engineer
Cyber Security Engineer

Interact Software • Poland

On-site
PLN 120,000 - 180,000
Threat Research Architect
Threat Research Architect

Sigmasoftware2 • Poland

On-site
PLN 120,000 - 180,000
Cyber Threat Intelligence Analyst
Cyber Threat Intelligence Analyst

aspenview • Poland

Hybrid
PLN 70,000 - 110,000
Competitive base salary
Flexible work model: hybrid, remote,or
Growth opportunities and leadership
+1
CyberSecurity Specialist
CyberSecurity Specialist

SEIDOR • Warszawa

On-site
PLN 180,000 - 260,000
Cybersecurity Researcher
Cybersecurity Researcher

MWDN • Warszawa

Hybrid
PLN 120,000 - 160,000
People-first management
Free English classes
Flexible working hours
+1
Senior Security Research Engineer, SONAR (Security Operations and Novel Adversary Research)
Senior Security Research Engineer, SONAR (Security Operations and Novel Adversary Research)

Elastic • Poland

On-site
PLN 346,000 - 547,000
Health coverage
Flexible locations & schedules
Generous vacation
+3