Назад
обновлено 3 дня назад

Staff Detection Engineer (Cybersecurity)

40 000 - 45 000PLN
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Poland
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Detection Engineer (Cybersecurity): Building and maintaining high-fidelity threat detections and a detection-as-code pipeline across cloud infrastructure, identity providers, endpoints, SaaS environments, and software supply chains with an accent on Python, SIEM telemetry, automated testing, and CI/CD. Focus on mapping coverage to MITRE ATT&CK, validating detections against attacker behavior, improving alert quality, and turning incidents into durable response automation.

Location: Warsaw, Poland innovation hub; hybrid office-centric model

Salary: 40,000–45,000 PLN gross per month, plus potential equity and benefits

Company

Asana provides a human and AI collaboration platform used by teams worldwide.

What you will do

  • Design, build, and maintain high-fidelity detections across AWS, GCP, identity providers, SaaS environments, endpoints, and software supply chains.
  • Own the Panther detection-as-code pipeline, including rule structure, unit and integration testing, code review standards, and CI/CD deployment.
  • Map coverage gaps against MITRE ATT&CK and the company threat model, prioritizing relevant attack techniques.
  • Onboard and normalize telemetry sources and ensure logs are complete, available, and queryable.
  • Measure alert precision, time-to-triage, and false-positive rates while tuning or retiring low-value detections.
  • Validate detections through purple-team exercises, atomic tests, adversary emulation, incident analysis, and SOAR enrichment and automation.

Requirements

  • 8+ years of experience in detection engineering, security operations, or threat hunting.
  • Strong Python skills and practical experience with Git workflows, pull-request reviews, automated testing, and CI/CD.
  • Deep experience with detection-as-code, SIEM platforms, query languages, log schemas, and correlation.
  • Strong understanding of AWS and GCP audit logs, Okta system logs, SaaS audit APIs, endpoint telemetry, and attacker TTPs.
  • Experience applying MITRE ATT&CK to drive detection coverage decisions and working with EDR tools such as CrowdStrike or SentinelOne.
  • Employment is offered under a Polish Contract of Employment (UoP).

Nice to have

  • Experience detecting software supply-chain and CI/CD threats across build systems and developer ecosystems.
  • Experience with Atomic Red Team, Caldera, purple-team exercises, or adversary emulation.
  • Security data engineering experience with log pipelines, schema design, or high-volume telemetry cost optimization.
  • Go, Bash, or JavaScript/TypeScript experience.

Culture & Benefits

  • Hybrid, office-centric work model with office catering on working days.
  • Base salary, RSUs, vacation allowance, and career growth budget.
  • Health insurance with dental and travel coverage, group life insurance, and mental health support.
  • Home office setup budget, gym or fitness card, and MacBook with accessories.
  • Fertility healthcare and family-forming support.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →