Utwórz profil, aby pracodawcy mogli Cię znaleźć, otrzymywać lepiej dopasowane oferty pracy i szybciej aplikować.
  • Wyszukiwanie ofert pracy
  • Zapisane
  • Stwórz CV
    Nowe
  • Wynagrodzenia
  • Subskrypcje

Mid Cybersecurity Engineer - CSIRT

Allegro

Mid Cybersecurity Engineer - CSIRT

Miejsce pracy: Warszawa

Technologies we use

Expected

  • Linux
  • Ubuntu
  • Debian
  • Windows Server
  • MacOS

Operating system

  • Windows
  • macOS
  • Linux

About the project

Join the Cybersecurity team! You will have a unique chance to safeguard one of the most visible and high-scale platforms in the region. High performance, engineering best practices, and a great atmosphere in the team guaranteed!

• Massive Scale & Security Challenges: Secure and optimize a world-class, cloud and on-prem environment handling thousands of requests per minute. This is high-availability, high-performance security engineering in practice.

• Modern Tech Stack: Work within an advanced ecosystem where core technologies include specialized defensive and incident response security tools, automated SOAR playbooks, EDR/XDR systems, modern SIEM systems for logging, correlations and machine learning detection models, AI based security incident response agents.

• True Ownership & Autonomy: We live by a "you build it, you run it" philosophy. You'll join an autonomous team with full ownership of your security services - from threat intelligence and hunting, EDR, SOAR, SIEM technologies to deploying custom incident response assistants.

• Complex Architectural Puzzles: From securing distributed systems to tackling novel AI vulnerabilities, you'll solve complex engineering problems that directly protect a massive, real-time marketplace.

Your responsibilities

  • Monitor and triage security incidents generated by EDR/XDR, SIEM and other detection platforms to identify true positive incidents in real time, 24/7 on-call rotation
  • Investigate and respond to endpoint and server threats such as malicious behavior on corporate workstations and servers
  • Analyze and mitigate phishing campaigns targeting Allegro brands (Allegro, Allegro Lokalnie, AllegroPay) - identifying malicious domains impersonating the company, coordinating takedown requests, and enriching related IOCs
  • Detects and responds to network-layer attacks, including DDoS attempts, password spraying, abnormal BOT scanning
  • Perform digital forensics and log correlation across multiple data sources (Active Directory sign-ins, endpoint and server logs, proxy, DNS, VPN, DHCP logs) to reconstruct attack timelines and root cause
  • Enrich and correlate Indicators of Compromise (IPs, domains, hashes, URLs) using threat intelligence platforms and internal asset inventories to assess scope and impact
  • Investigate identity-related risks, such as suspected account takeovers, impersonation, and anomalous user behavior flagged by identity protection tools
  • Document findings and produce evidence-based incident reports, including root cause analysis, MITRE ATT&CK mapping, and remediation recommendations for stakeholders and asset owners
  • Coordinate remediation actions with IT, infrastructure, and business teams (e.g. account lockouts, endpoint isolation, credential resets, domain blocking)
  • Continuously improve detection capabilities by tuning correlation rules, updating threat intelligence, and identifying gaps based on recurring incident patterns
  • Collaborate with brand protection and external partners to detect and respond to threats against Allegro's reputation and customers

Our requirements

  • Have experience working in SOC, CERT or CSIRT teams
  • Have experience using SOAR, EDR/XDR and SIEM systems
  • Possess and continuously develop knowledge of current offensive and defensive security threats
  • Have hands-on experience working with modern, large-scale IT infrastructure and understand DevOps culture
  • Are familiar with the Linux systems (Ubuntu/Debian), Windows and MacOS
  • Have designed, implemented, developed, or maintained solutions that enhance security
  • Have participated in security incidents handling
  • Can communicate and collaborate effectively with people from different areas and levels of the organization
  • Understand the importance of IT security technologies, tools, and procedures, and their impact on the business
  • Demonstrate high independence and a self-driven approach – you are capable of taking full, end-to-end incident response process, from investigation, evidence and log collection to final reporting and remediation guidance
  • Are keen on leveraging automation and AI-assisted techniques to improve incident response, detection rules tuning and innovate defensive techniques
  • Are open to developing soft skills and embracing a growth mindset through active participation in team retrospectives and cross-team collaborations
  • Are excited about adopting and securing AI technologies, being ready to incorporate AI coding and security assistants into their daily work to maximize efficiency
  • Want to constantly develop and update their knowledge in a rapidly shifting threat landscape
  • Know English at at least B2 level

What we offer

  • Flexible working hours in the hybrid model (4/1) - working hours start between 7:00 a.m. and 9:00 a.m. We also have 30 days of occasional remote work
  • Annual bonus based on your annual performance and company results
  • Our team is based in Warsaw, Poznań and Toruń
  • Well-located offices (with e.g. fully equipped kitchens, bicycle parking, terraces full of greenery) and excellent work tools (e.g., raised desks, ergonomic chairs, interactive conference rooms)
  • A 16" or 14" MacBook Pro or corresponding Dell with Windows (if you don't like Macs) and all the necessary accessories
  • A wide selection of fringe benefits in a cafeteria plan - you choose what you like (e.g., medical, sports or lunch packages, insurance, purchase vouchers)
  • English classes that we pay for related to the specific nature of your job
  • A training budget, inter-team tourism (see more here), hackathons, and an internal learning platform where you will find multiple trainings
  • An additional day off for volunteering, which you can use alone, with a team, or with a larger group of people connected by a common goal
  • Social events for Allegro people - Spin Kilometers, Family Day, Fat Thursday, Advent of Code, and many other occasions we enjoy

Benefits

  • sharing the costs of sports activities
  • private medical care
  • sharing the costs of foreign language classes
  • sharing the costs of professional training & courses
  • life insurance
  • flexible working time
  • integration events
  • no dress code
  • leisure zone
  • extra social benefits

#goodtobehere means that:

  • You will join a team you can count on - we work with top-class specialists who have knowledge- and experience-sharing in their DNA.
  • You will love our level of autonomy in team organization, the space for continuous development, and the opportunity to try new things.
  • You get to choose which technology solves the problem and you are responsible for what you create.
  • You will value our Developer Experience and the full platform of tools and technologies that make creating software easier. We rely on an internal ecosystem based on self-service and widely used tools such as Kubernetes, Docker, Consul, GitHub, and GitHub Actions. Thanks to this, you can contribute to Allegro from your very first days on the job.
  • You will be equipped with modern AI tools to automate repetitive tasks, allowing you to focus on developing new services and refining existing ones (also leveraging AI support).
  • You will create solutions that will be used (and loved!) by your friends, family and millions of our customers.
  • You will meet the Allegro Scale, which starts with over 1000 microservices, an open-source data bus (Hermes) with 300K+ rps, a Service Mesh with 1M+ rps, tens of petabytes of data, and production-used machine learning.
  • You will become part of Allegro Tech - We speak at industry conferences, cooperate with tech communities, run our own blog (it's been over 10 years!), record podcasts, lead guilds, and we organize our own internal conference - the Allegro Tech Meeting. We create solutions we love (and can) to talk about!
Oferta pracy dodana 3 dni temu