Mid Cybersecurity Engineer - CSIRT
Allegro
Mid Cybersecurity Engineer - CSIRT
Miejsce pracy: Warszawa
Technologies we use
Expected
- Linux
- Ubuntu
- Debian
- Windows Server
- MacOS
Operating system
- Windows
- macOS
- Linux
About the project
Join the Cybersecurity team! You will have a unique chance to safeguard one of the most visible and high-scale platforms in the region. High performance, engineering best practices, and a great atmosphere in the team guaranteed!
• Massive Scale & Security Challenges: Secure and optimize a world-class, cloud and on-prem environment handling thousands of requests per minute. This is high-availability, high-performance security engineering in practice.
• Modern Tech Stack: Work within an advanced ecosystem where core technologies include specialized defensive and incident response security tools, automated SOAR playbooks, EDR/XDR systems, modern SIEM systems for logging, correlations and machine learning detection models, AI based security incident response agents.
• True Ownership & Autonomy: We live by a "you build it, you run it" philosophy. You'll join an autonomous team with full ownership of your security services - from threat intelligence and hunting, EDR, SOAR, SIEM technologies to deploying custom incident response assistants.
• Complex Architectural Puzzles: From securing distributed systems to tackling novel AI vulnerabilities, you'll solve complex engineering problems that directly protect a massive, real-time marketplace.
Your responsibilities
- Monitor and triage security incidents generated by EDR/XDR, SIEM and other detection platforms to identify true positive incidents in real time, 24/7 on-call rotation
- Investigate and respond to endpoint and server threats such as malicious behavior on corporate workstations and servers
- Analyze and mitigate phishing campaigns targeting Allegro brands (Allegro, Allegro Lokalnie, AllegroPay) - identifying malicious domains impersonating the company, coordinating takedown requests, and enriching related IOCs
- Detects and responds to network-layer attacks, including DDoS attempts, password spraying, abnormal BOT scanning
- Perform digital forensics and log correlation across multiple data sources (Active Directory sign-ins, endpoint and server logs, proxy, DNS, VPN, DHCP logs) to reconstruct attack timelines and root cause
- Enrich and correlate Indicators of Compromise (IPs, domains, hashes, URLs) using threat intelligence platforms and internal asset inventories to assess scope and impact
- Investigate identity-related risks, such as suspected account takeovers, impersonation, and anomalous user behavior flagged by identity protection tools
- Document findings and produce evidence-based incident reports, including root cause analysis, MITRE ATT&CK mapping, and remediation recommendations for stakeholders and asset owners
- Coordinate remediation actions with IT, infrastructure, and business teams (e.g. account lockouts, endpoint isolation, credential resets, domain blocking)
- Continuously improve detection capabilities by tuning correlation rules, updating threat intelligence, and identifying gaps based on recurring incident patterns
- Collaborate with brand protection and external partners to detect and respond to threats against Allegro's reputation and customers
Our requirements
- Have experience working in SOC, CERT or CSIRT teams
- Have experience using SOAR, EDR/XDR and SIEM systems
- Possess and continuously develop knowledge of current offensive and defensive security threats
- Have hands-on experience working with modern, large-scale IT infrastructure and understand DevOps culture
- Are familiar with the Linux systems (Ubuntu/Debian), Windows and MacOS
- Have designed, implemented, developed, or maintained solutions that enhance security
- Have participated in security incidents handling
- Can communicate and collaborate effectively with people from different areas and levels of the organization
- Understand the importance of IT security technologies, tools, and procedures, and their impact on the business
- Demonstrate high independence and a self-driven approach – you are capable of taking full, end-to-end incident response process, from investigation, evidence and log collection to final reporting and remediation guidance
- Are keen on leveraging automation and AI-assisted techniques to improve incident response, detection rules tuning and innovate defensive techniques
- Are open to developing soft skills and embracing a growth mindset through active participation in team retrospectives and cross-team collaborations
- Are excited about adopting and securing AI technologies, being ready to incorporate AI coding and security assistants into their daily work to maximize efficiency
- Want to constantly develop and update their knowledge in a rapidly shifting threat landscape
- Know English at at least B2 level
What we offer
- Flexible working hours in the hybrid model (4/1) - working hours start between 7:00 a.m. and 9:00 a.m. We also have 30 days of occasional remote work
- Annual bonus based on your annual performance and company results
- Our team is based in Warsaw, Poznań and Toruń
- Well-located offices (with e.g. fully equipped kitchens, bicycle parking, terraces full of greenery) and excellent work tools (e.g., raised desks, ergonomic chairs, interactive conference rooms)
- A 16" or 14" MacBook Pro or corresponding Dell with Windows (if you don't like Macs) and all the necessary accessories
- A wide selection of fringe benefits in a cafeteria plan - you choose what you like (e.g., medical, sports or lunch packages, insurance, purchase vouchers)
- English classes that we pay for related to the specific nature of your job
- A training budget, inter-team tourism (see more here), hackathons, and an internal learning platform where you will find multiple trainings
- An additional day off for volunteering, which you can use alone, with a team, or with a larger group of people connected by a common goal
- Social events for Allegro people - Spin Kilometers, Family Day, Fat Thursday, Advent of Code, and many other occasions we enjoy
Benefits
- sharing the costs of sports activities
- private medical care
- sharing the costs of foreign language classes
- sharing the costs of professional training & courses
- life insurance
- flexible working time
- integration events
- no dress code
- leisure zone
- extra social benefits
#goodtobehere means that:
- You will join a team you can count on - we work with top-class specialists who have knowledge- and experience-sharing in their DNA.
- You will love our level of autonomy in team organization, the space for continuous development, and the opportunity to try new things.
- You get to choose which technology solves the problem and you are responsible for what you create.
- You will value our Developer Experience and the full platform of tools and technologies that make creating software easier. We rely on an internal ecosystem based on self-service and widely used tools such as Kubernetes, Docker, Consul, GitHub, and GitHub Actions. Thanks to this, you can contribute to Allegro from your very first days on the job.
- You will be equipped with modern AI tools to automate repetitive tasks, allowing you to focus on developing new services and refining existing ones (also leveraging AI support).
- You will create solutions that will be used (and loved!) by your friends, family and millions of our customers.
- You will meet the Allegro Scale, which starts with over 1000 microservices, an open-source data bus (Hermes) with 300K+ rps, a Service Mesh with 1M+ rps, tens of petabytes of data, and production-used machine learning.
- You will become part of Allegro Tech - We speak at industry conferences, cooperate with tech communities, run our own blog (it's been over 10 years!), record podcasts, lead guilds, and we organize our own internal conference - the Allegro Tech Meeting. We create solutions we love (and can) to talk about!