Unlock Full Resume Report

New offer - be the first one to apply!

September 5, 2026

SOC Analyst

Junior • Remote

Krakow, MA, Poland

Gcore WAAP protects customer web applications and APIs against DDoS, bots, and application-layer attacks at CDN edge scale. The team is building a proactive managed-support offering for enterprise customers and needs a SOC Analyst to run day-to-day security operations: monitor traffic and alerts, triage false positives, prepare customer-facing threat reports, and escalate confirmed impact to the appropriate team.

You will work alongside Threat Researchers, handling operational security work so they can focus on deep analysis. This role does not require threat-hunting expertise; it requires reliability, attention to detail, comfort with logs and dashboards, and the ability to distinguish attacks from legitimate traffic and escalate when appropriate.

Quick Facts

  • First-line role in managed WAAP security operations
  • Direct customer impact through timely monitoring, reporting, and escalation
  • Opportunity to grow into threat research or detection engineering

What You Will Do

  • Monitor WAAP and DDoS activity across customer accounts, including dashboards, alerts, and traffic patterns, and identify activity requiring attention.
  • Triage false positives by reviewing traffic flagged by security policies, confirming or dismissing findings, and reducing customer noise.
  • Prepare weekly customer threat summaries and post-incident DDoS reports in clear, customer-facing English.
  • Alert and escalate customer-impacting attacks to Engineering or Support with appropriate context, following the escalation runbook.
  • Support customer onboarding by applying standard security configurations based on resource type, traffic volume, and legitimate-traffic exclusions, following playbooks.
  • Follow the reaction-time SLA, with emphasis on rapid response and clear post-incident reporting.
  • Contribute to and maintain runbooks to ensure consistent, repeatable responses.

What We Are Looking For

  • Understanding of web-security fundamentals, including WAF, DDoS, bots, and the OWASP Top 10.
  • Solid knowledge of HTTP, TCP/IP, and TLS.
  • Ability to analyze logs and dashboards and spot traffic anomalies.
  • Ability to distinguish malicious from legitimate traffic and assess false positives.
  • Clear written English for customer-facing reports.
  • Reliable, detail-oriented approach and composure during incidents.
  • Willingness to work in a shift and on-call rotation.

Nice to Have

  • Prior SOC L1/L2 or related experience.
  • Basic query or scripting skills, including SQL-like log queries, regex, and Python.
  • Familiarity with CDN/WAF platforms such as Cloudflare, Akamai, Imperva, F5, or Radware.
  • Exposure to SIEM or alerting tools and PagerDuty-style on-call practices.
  • Security certifications such as CompTIA Security+.

Not Required

Deep threat research, exploit development, and malware reverse engineering are not required. The role provides clean, triaged operational signals to Threat Researchers and handles routine security operations.

Benefits

  • Competitive compensation.
  • Flexible working hours and hybrid or remote options, depending on the role.
  • Work from anywhere in the world for up to 45 days per year.
  • Private medical insurance for employees and families.*
  • Extra paid vacation and sick leave days.*
  • Support for important life moments and celebrations.
  • Language courses.
  • Modern offices with snacks, drinks, and entertainment.*
  • Team sports and social activities.*

*Benefits may vary depending on location.

Equal Opportunity Employer

Equal opportunity is provided to all applicants without regard to race, color, religion, sex, sexual orientation, age, gender identity, gender expression, national origin, disability, or other legally protected characteristics.

Similar jobs you might like