обновлено 3 дня назад
Staff Detection Engineer (Cybersecurity)
40 000 - 45 000PLN
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Staff Detection Engineer (Cybersecurity): Building and maintaining high-fidelity threat detections and a detection-as-code pipeline across cloud infrastructure, identity providers, endpoints, SaaS environments, and software supply chains with an accent on Python, SIEM telemetry, automated testing, and CI/CD. Focus on mapping coverage to MITRE ATT&CK, validating detections against attacker behavior, improving alert quality, and turning incidents into durable response automation.
Location: Warsaw, Poland innovation hub; hybrid office-centric model
Salary: 40,000–45,000 PLN gross per month, plus potential equity and benefits
Company
Asana provides a human and AI collaboration platform used by teams worldwide.
What you will do
- Design, build, and maintain high-fidelity detections across AWS, GCP, identity providers, SaaS environments, endpoints, and software supply chains.
- Own the Panther detection-as-code pipeline, including rule structure, unit and integration testing, code review standards, and CI/CD deployment.
- Map coverage gaps against MITRE ATT&CK and the company threat model, prioritizing relevant attack techniques.
- Onboard and normalize telemetry sources and ensure logs are complete, available, and queryable.
- Measure alert precision, time-to-triage, and false-positive rates while tuning or retiring low-value detections.
- Validate detections through purple-team exercises, atomic tests, adversary emulation, incident analysis, and SOAR enrichment and automation.
Requirements
- 8+ years of experience in detection engineering, security operations, or threat hunting.
- Strong Python skills and practical experience with Git workflows, pull-request reviews, automated testing, and CI/CD.
- Deep experience with detection-as-code, SIEM platforms, query languages, log schemas, and correlation.
- Strong understanding of AWS and GCP audit logs, Okta system logs, SaaS audit APIs, endpoint telemetry, and attacker TTPs.
- Experience applying MITRE ATT&CK to drive detection coverage decisions and working with EDR tools such as CrowdStrike or SentinelOne.
- Employment is offered under a Polish Contract of Employment (UoP).
Nice to have
- Experience detecting software supply-chain and CI/CD threats across build systems and developer ecosystems.
- Experience with Atomic Red Team, Caldera, purple-team exercises, or adversary emulation.
- Security data engineering experience with log pipelines, schema design, or high-volume telemetry cost optimization.
- Go, Bash, or JavaScript/TypeScript experience.
Culture & Benefits
- Hybrid, office-centric work model with office catering on working days.
- Base salary, RSUs, vacation allowance, and career growth budget.
- Health insurance with dental and travel coverage, group life insurance, and mental health support.
- Home office setup budget, gym or fitness card, and MacBook with accessories.
- Fertility healthcare and family-forming support.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
4 дня назад
Senior Security Engineer, Security Incident Response Team (SIRT) - EMEA (Cybersecurity)
7 дней назад
Security Operations Analyst (SIEM Operations and Threat Detection)
4 дня назад
DevSecOps Architect (Cybersecurity)
10 дней назад
Senior Director, Global Cyber Detection & Response (Cybersecurity)
10 дней назад
Information Security Analyst (Cloud Security)
4 дня назад
Security Operations Center (SOC) Senior Analyst
259 100 - 323 900PLN