15 минут назад
SOC Analyst (WAAP)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
SOC Analyst (WAAP) (Web Application and API Protection): Monitoring web application and API traffic, triaging security alerts and false positives, and preparing customer-facing threat reports with an accent on WAF, DDoS, bot, and application-layer attack analysis. Focus on distinguishing malicious from legitimate traffic, escalating customer-impacting incidents, applying standard security configurations, and maintaining repeatable response runbooks.
Location: Poland or Serbia. Hybrid or remote options may be available depending on the role; benefits include working from anywhere for up to 45 days per year.
Competitive compensation.
Company
Provides infrastructure and software solutions for AI, cloud, network, and security across global edge and cloud platforms.
What you will do
- Monitor WAAP and DDoS activity across customer accounts using dashboards, alerts, and traffic patterns.
- Review security-policy alerts, confirm or dismiss false positives, and reduce operational noise.
- Prepare weekly customer threat summaries and post-incident DDoS reports in clear written English.
- Escalate customer-impacting attacks to engineering or Support with the relevant context and follow the escalation runbook.
- Apply standard security configurations during customer onboarding based on resource type, traffic volume, and legitimate-traffic exclusions.
- Follow reaction-time SLAs and contribute to consistent, repeatable runbooks.
Requirements
- Understanding of web security fundamentals, including WAF, DDoS, bots, and OWASP Top 10.
- Solid knowledge of HTTP, TCP/IP, and TLS.
- Ability to analyze logs and dashboards, identify traffic anomalies, and distinguish malicious from legitimate traffic.
- Clear written English is required for customer-facing reports.
- Reliable, detail-oriented, and calm during security incidents.
- Willingness to work in a shift or on-call rotation.
Nice to have
- Previous SOC L1/L2 or related security operations experience.
- SQL-like log queries, regular expressions, or basic Python scripting.
- Familiarity with CDN and WAF platforms such as Cloudflare, Akamai, Imperva, F5, or Radware.
- Exposure to SIEM, alerting, or PagerDuty-style on-call tooling.
- Security certifications such as CompTIA Security+.
Culture & Benefits
- Employment is offered only under an employment or labor agreement.
- Flexible working hours and role-dependent hybrid or remote options.
- Up to 45 days per year of work from anywhere, depending on location.
- Private medical insurance, extra paid vacation and sick leave days, and support for important life events.
- Language courses, modern offices, team sports, and social activities.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →