Security Operations Analyst

5 dni temu


Poland Attio Pełny etat
Attio is on a mission to redefine CRM for the AI era.

We're building the first AI-native CRM — designed for the most ambitious go-to-market teams. We recently announced our $52M Series B, led by GV (Google Ventures), with support from Redpoint, Balderton, Point Nine, and 01A. Our team thrives on solving complex technical challenges, delighting our users, and setting a new standard for the industry.

About the Role

The Security Operations Analyst is a mission-critical role within the Security, Infrastructure and Performance team, directly responsible for maintaining a vigilant and robust security posture for the entire organisation. This position focuses on the real-time protection of all organisational assets, infrastructure, and data.

The role requires a deep understanding of security frameworks, network protocols and adversarial tactics, techniques, and procedures (TTPs). The Analyst is the frontline defender, dedicated to ensuring business continuity and protecting the confidentiality, integrity, and availability of all critical resources.

Core Responsibilities and Duties
  • Security Monitoring, Triage & Improvement: Rapidly detect and prioritise active threats and vulnerabilities through continuous monitoring (SIEM, EDR, Cloud), ensuring that insights from root cause analysis and proactive threat hunting are directly fed back into the engineering process and used refine detection capabilities.

  • Incident Response: Serve as the initial responder to security events. Rapidly analyse, classify, and prioritise reported or detected security incidents, determining the scope, severity, and potential impact to the platform.

  • Compliance: Enforce the compliance with internal security policies and regulatory requirements maintaining meticulous records of all detected security events, analysis findings, and incident response activities.

Competencies and Skills
  • Security Information and Event Management (SIEM) Platform Expertise:

    • Must have: Hands-on experience in the operation, administration, and ongoing maintenance of a major SIEM platform

    • Desirable: Experience with Google SecOps (formerly Chronicle), including advanced knowledge of data ingestion, rule creation, dashboard development, and optimisation for performance and cost-effectiveness. The ability to leverage the platform for proactive threat hunting and complex query construction is expected.

    • Desirable: Proficiency in Google SecOps (formerly Chronicle) SOAR (security orchestration, automation, and response) tooling. This includes developing SOAR actions and workflows to automate alert triage, immediate incident mitigation, and response procedures.

  • Security Incident Response:

    • Must have: Proven experience in the end-to-end development, documentation, and execution of comprehensive security incident response playbooks and procedures.

    • Must have: Practical experience in incident triage, containment, eradication, recovery, and post-mortem analysis for a wide range of security events (e.g., malware outbreaks, unauthorised access, data exfiltration, cloud compromises).

    • Desirable: The ability to lead and coordinate incident response efforts across cross-functional teams under pressure is crucial.

  • Security Log and Network Analysis:

    • Must have: Deep expertise in the analysis of security logs from diverse sources (e.g., operating systems, firewalls, endpoint protection, cloud environments) to identify anomalies, indicators of compromise (IOCs), and root causes of incidents.

    • Must have: Expert-level knowledge of common attack vectors, attacker methodologies (e.g., MITRE ATT&CK framework), and techniques, tactics, and procedures (TTPs) used by various threat actors.

    • Desirable: Comprehensive understanding of network protocols (e.g., TCP/IP, DNS, HTTP/S) and their associated traffic patterns to effectively detect malicious activity and understand its propagation.

  • Vulnerability Management:

    • Must have: Solid familiarity with industry-standard vulnerability scanning tools (e.g., Nessus, Qualys, Rapid7, Trivy).

    • Desirable: Experience managing a vulnerability disclosure or bug bounty program. Testing disclosed vulnerabilities and working with external security researchers.

    • Desirable: Experience in establishing, running, and managing a continuous vulnerability management lifecycle, including scanning, reporting, prioritisation, and tracking of remediation efforts in coordination with engineering and system owner teams.

What we offer
  • Equity in an early-stage tech company on an incredible trajectory

  • Apple hardware

  • Team off-site in fun places (We've been to Barcelona, Lisbon, Malta, and Split so far)



  • Poland Pacifica Continental Pełny etat 30 000 zł - 60 000 zł rocznie

    Our client is an European company leading the development and production of responsible packaging solutions for a wide variety of industries. The company currently has 44,000 employees supporting its operations in 220 locations in 43 countries.The company is currently looking for an IT Security Operations Analyst, who will be primarily responsible for the...


  • Poland Enterprise AI decisioning and workflow automation platform Pełny etat 40 000 zł - 80 000 zł rocznie

    Job ID: 22326  Meet Our Team: Pega is The Enterprise Transformation Company that helps organizations Build for Change with enterprise AI decisioning and workflow automation. We offer a commercial SaaS version of our industry-leading platform to our global clients. Pega was recently recognized as one of the "Top 10 Tech Winners For The AI Revolution" by...


  • Poland Euroclear Pełny etat 40 000 zł - 80 000 zł rocznie

    DescriptionDivision: Chief Information Security Office (CISO) As a global critical financial infrastructure, the protection of Euroclear information and assets is fundamental to the company's business. Information Security is at the core of our services, firmly embedded in the management systems and processes of the company. You will be joining our Chief...

  • Security Analyst

    1 tydzień temu


    Poland - Warsaw - ASEC Aviva Employment Services Pełny etat

    Hi, we're glad you're here We are hiring to our Aviva Services Excellence Centre Take a look at our job description - maybe it suits you or one of your friends?Aviva is seeking a Security Analyst who will be responsible for day-to-day security threat monitoring and analysis. You will manage security incidents and review security alerts for next steps...


  • Poland Testronic Pełny etat 40 000 zł - 80 000 zł rocznie

    We're looking for a proactive Group Cyber Security Analyst in Poland or in the Philippines to help protect Testronic's global operations and digital assets (about 2000 people spread across 3 principal locations in EU, US and Asia). You'll play a key role in detecting, analyzing, and responding to security threats while supporting the delivery of our global...


  • Poland Euroclear Pełny etat 40 000 zł - 80 000 zł rocznie

    DescriptionDivision: CISOSecurity Operations Engineer (SOAR) / CISO Platform SecurityYour main task will be to maintain the security orchestration and automation platform. This platform is used by the security operation center to manage security alerts. Our mission is to maintain and enrich this platform by integrating it with various tools. Depending on...

  • SOC Analyst

    2 dni temu


    Poland Semrush Pełny etat

    Hi thereWe are Semrush, a global Tech company developing our own product – a platform for digital marketers.Are you ready to be a part of it? This is your chance We're hiring for SOC Analyst (Security Operations Team).Tasks in the roleIncident Response. Responding to security incidents, investigating and analyzing them, coordinating with other teams, such...


  • Remote - Poland Cribl Pełny etat 40 000 zł - 80 000 zł rocznie

    Cribl does differently. What does that mean? It means we are a serious company that doesn't take itself too seriously; and we're looking for people who love to get stuff done, and laugh a bit along the way. We're growing rapidly - looking for collaborative, curious, and motivated team members who are passionate about putting customers first. As a...

  • Offensive Security

    2 tygodni temu


    Poland Euroclear Pełny etat 40 000 zł - 60 000 zł rocznie

    DescriptionDivision: CISOSecurity is at the core of Euroclear's services, embedded in every system and process across the organization. As part of the Chief Information Security Office (CISO), you will join the Offensive Security Tribe, a team dedicated to proactively identifying vulnerabilities and strengthening our cyber resilience.This role focuses on...


  • PL-Gdansk, Poland (Aleja Grunwaldzka) Arrow Electronics Pełny etat 30 000 zł - 60 000 zł rocznie

    Position:Business Operations AnalystJob Description:Arrow Electronics is a global provider of products, services, and solutions to industrial and commercial users of electronic components and enterprise computing solutions. Arrow Electronics guides innovation forward for over 220,000 leading technology manufacturers and service providers. With 2024 sales of...