Digital Forensics and Incident Response Specialist (Compromise Assessment & Rapid Response)​ | f/m/d
Offer summary

(Summary generated by AI based on the full job description)

The project focuses on digital forensics, incident response, and threat hunting within ERGO Group. It involves working with tools like EDR, APT Scanner, SIEM, creating YARA and Sigma rules, and malware analysis. Responsibilities include scan management, incident analysis, cooperation with SOC, CTI, and CSIRT teams, and developing threat response strategies. Benefits include medical care, sports card, training, and remote work opportunities.

newyou can start ASAP

Digital Forensics and Incident Response Specialist (Compromise Assessment & Rapid Response)​ | f/m/d

Company: ERGO Technology & Services S.A.

from: 23 July 2026
to: 22 August 2026
salary not specifiedcontract of employment (full-time)
Offer parameters
level:junior • mid
working mode:hybrid
Gdańsk, Pomeranian
Gdańsk, PomeranianLeona Droszyńskiego 24View on map

Requirements

Expected technologies

Active Directory
Incident Response
Threat Hunting

Operating system

Windows

Our requirements

  • fluent in English
  • proven experience in the IT security area
  • hands-on experience with hardware/software tools used in incident response, computer forensics and network security assessments
  • understanding of Windows internals and Active Directory environments
  • knowledge of Linux environment and Linux forensic skills
  • general understanding of computer networking concepts and protocols
  • basic understanding of scripting languages
  • strong understanding of the Cyber Kill Chain, MITRE ATT&CK Framework, and modern threat actor TTPs
  • basic understanding of MS Defender EDR and MS Sentinel environments to use KQL queries for threat hunting purposes
  • ability to stay focused, keep calm and work under high stress
  • ability to communicate with technical and business stakeholders
  • ability to work in a multinational and multicultural environment
  • strong teamwork culture with effective collaboration, cross-group partnership
  • being an innovator, creative, passionate, independent, and motivated to make a difference and help reduce cyber risk for ERGO Group

Optional

  • Bachelor / Master in IT / Business IT / Computer Science or similar education
  • Certified: Security+, CySA+, CEH or equivalent

Your responsibilities

  • scanning management for a Compromise Assessment and Rapid Response (CA&RR) tool for various customers in the ERGO group
  • preparing analysis of findings in the CA&RR tools (e.g. detecting backdoors, attackers' tools, system misconfigurations, forensics artifacts or other malicious activity)
  • developing of rapid response playbooks
  • analyzing of malware files
  • creating of custom YARA and Sigma rules
  • performing threat hunting iterations based on feed delivered from CTI Team and researching on recent campaigns using EDR, APT Scanner, SIEM and other security tools
  • defining of threat remediation strategies for various customers in the ERGO group
  • developing and refining of hypothesis and queries to detect threats
  • providing detailed reports on threat hunting iterations against known hacker groups
  • cooperating with technical teams as the SOC, CTI and CSIRT

About the role

We are looking for a skilled and motivated Junior or Mid Digital Forensics and Incident Response and Threat Hunting Specialist. In your function, you will be a part of the Threat Hunting and CA&RR (Compromised Assessment & Rapid Response) Team, using Advanced Persistence Threat scanner and other security tools to: support ERGO Group in proactive identification of threats during threat hunting process, conducting digital investigations, analyzing security incidents, mitigate cyber risk and providing incident response recommendations.
You will be responsible for managing scans, evidence acquisition, analysis of malware files, data breaches and unauthorized access. As a part of Global Incident Response Team, you will take part in the incident investigations and cooperate with CSIRT (Computer Security Incident Response Team), CTI (Cyber Threat Intelligence) and SOC (Security Operations Center) Global Teams. In case there is a need for follow-up activities and collection of evidence, you will be responsible for coordinating the work of different cross-functional teams.
Company

What we offer

  • Let's be healthy – medical package, sports card, and numerous sports sections – these are some of the benefits that help our employees stay in good shape.
  • Let's be balanced – work-life balance is a key aspect of a healthy workplace. We offer our employees flexible working hours, a confidential employee assistant program, as well as the possibility of remote working. However, staying at home with our in-office gaming room and dog-friendly office in Warsaw won’t be easy.
  • Let's be smart – we organize numerous workshops and training courses. Thanks to hackathons and meetups, our specialists share their expertise with others. Additionally, we have a wide range of digital learning platforms and language courses.
  • Let's be responsible – each year, we participate in several CSR activities, during which, together with our colleagues, we do our best to create a better future.
  • Let's be fun – company-wide bike races and soccer matches, film marathons in our cinema room or other engaging team-building activities – we got it covered!
  • Let's be diverse – every team member is valued, regardless of gender, nationality, religious beliefs, disability, age, and sexual orientation or identity. Your qualifications, experience, and mindset are our greatest benefit!

Benefits

  • sharing the costs of sports activities
  • private medical care
  • sharing the costs of foreign language classes
  • sharing the costs of professional training & courses
  • life insurance
  • remote work opportunities
  • integration events
  • employee referral program
  • charity initiatives

ERGO Technology & Services S.A.

ERGO Technology & Services S.A. (ET&S), a member of the Munich Re and ERGO Group, is delivering integrated IT and business services to international markets. Our expertise lies in providing advanced IT services, with a focus on modern, business-driven technology solutions. On the business side, we also support the Group in various end-to-end insurance processes, including finance, operations, and underwriting. With offices in Warsaw and Gdansk, and strong global partnerships, we foster a dynamic, multicultural environment that promotes diversity and international opportunities.

This is how we work

Digital Forensics and Incident Response Specialist (Compromise Assessment & Rapid Response)​ | f/m/d
I apply to:
ERGO Technology & Services S.A.
Gdańsk, Pomeranian
Pracodawca zbiera zgłoszenia przez swój system.
Przejdziesz na zewnętrzny formularz.

By clicking "Aplikuj" you confirm that you've read and accepted our Terms and Conditions.



This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Need more information?

  • Make sure the body of the offer doesn’t already include what you’re looking for.
  • Ask a question if you need more information you’re interested in.
  • We’ll forward your question to the employer and aim to provide a response within 3 business days.

Share this offer