Mid Cybersecurity Engineer - CSIRT
Offer summary

(Summary generated by AI based on the full job description)

Project concerns a cybersecurity team protecting a large, high-availability platform at massive scale. Stack includes SOAR, EDR/XDR, SIEM and tools for threat intelligence, automation and AI incident-response assistants. Responsibilities cover monitoring and triage of incidents, endpoint and network response, phishing analysis and takedowns, digital forensics and log correlation, IOC enrichment, identity risk investigations, MITRE ATT&CK reporting and coordinating remediation and detection improvements.

Mid Cybersecurity Engineer - CSIRT

Company: Allegro

from: 23 September 2026
to: 23 October 2026
salary not specifiedcontract of employment (full-time)
Offer parameters
level:mid
working mode:hybrid
Warszawa, Wola
Warszawa, WolaŻelazna 51/53View on map

Requirements

Expected technologies

Linux
Ubuntu
Debian
Windows Server
MacOS

Operating system

Windows
macOS
Linux

Our requirements

  • Have experience working in SOC, CERT or CSIRT teams
  • Have experience using SOAR, EDR/XDR and SIEM systems
  • Possess and continuously develop knowledge of current offensive and defensive security threats
  • Have hands-on experience working with modern, large-scale IT infrastructure and understand DevOps culture
  • Are familiar with the Linux systems (Ubuntu/Debian), Windows and MacOS
  • Have designed, implemented, developed, or maintained solutions that enhance security
  • Have participated in security incidents handling
  • Can communicate and collaborate effectively with people from different areas and levels of the organization
  • Understand the importance of IT security technologies, tools, and procedures, and their impact on the business
  • Demonstrate high independence and a self-driven approach – you are capable of taking full, end-to-end incident response process, from investigation, evidence and log collection to final reporting and remediation guidance
  • Are keen on leveraging automation and AI-assisted techniques to improve incident response, detection rules tuning and innovate defensive techniques
  • Are open to developing soft skills and embracing a growth mindset through active participation in team retrospectives and cross-team collaborations
  • Are excited about adopting and securing AI technologies, being ready to incorporate AI coding and security assistants into their daily work to maximize efficiency
  • Want to constantly develop and update their knowledge in a rapidly shifting threat landscape
  • Know English at at least B2 level

Your responsibilities

  • Monitor and triage security incidents generated by EDR/XDR, SIEM and other detection platforms to identify true positive incidents in real time, 24/7 on-call rotation
  • Investigate and respond to endpoint and server threats such as malicious behavior on corporate workstations and servers
  • Analyze and mitigate phishing campaigns targeting Allegro brands (Allegro, Allegro Lokalnie, AllegroPay) - identifying malicious domains impersonating the company, coordinating takedown requests, and enriching related IOCs
  • Detects and responds to network-layer attacks, including DDoS attempts, password spraying, abnormal BOT scanning
  • Perform digital forensics and log correlation across multiple data sources (Active Directory sign-ins, endpoint and server logs, proxy, DNS, VPN, DHCP logs) to reconstruct attack timelines and root cause
  • Enrich and correlate Indicators of Compromise (IPs, domains, hashes, URLs) using threat intelligence platforms and internal asset inventories to assess scope and impact
  • Investigate identity-related risks, such as suspected account takeovers, impersonation, and anomalous user behavior flagged by identity protection tools
  • Document findings and produce evidence-based incident reports, including root cause analysis, MITRE ATT&CK mapping, and remediation recommendations for stakeholders and asset owners
  • Coordinate remediation actions with IT, infrastructure, and business teams (e.g. account lockouts, endpoint isolation, credential resets, domain blocking)
  • Continuously improve detection capabilities by tuning correlation rules, updating threat intelligence, and identifying gaps based on recurring incident patterns
  • Collaborate with brand protection and external partners to detect and respond to threats against Allegro's reputation and customers

About the project

Join the Cybersecurity team! You will have a unique chance to safeguard one of the most visible and high-scale platforms in the region. High performance, engineering best practices, and a great atmosphere in the team guaranteed!
  • Massive Scale & Security Challenges: Secure and optimize a world-class, cloud and on-prem environment handling thousands of requests per minute. This is high-availability, high-performance security engineering in practice.
  • Modern Tech Stack: Work within an advanced ecosystem where core technologies include specialized defensive and incident response security tools, automated SOAR playbooks, EDR/XDR systems, modern SIEM systems for logging, correlations and machine learning detection models, AI based security incident response agents.
  • True Ownership & Autonomy: We live by a "you build it, you run it" philosophy. You'll join an autonomous team with full ownership of your security services - from threat intelligence and hunting, EDR, SOAR, SIEM technologies to deploying custom incident response assistants.
  • Complex Architectural Puzzles: From securing distributed systems to tackling novel AI vulnerabilities, you'll solve complex engineering problems that directly protect a massive, real-time marketplace.
  • #goodtobehere means that:

    • You will join a team you can count on - we work with top-class specialists who have knowledge- and experience-sharing in their DNA.
    • You will love our level of autonomy in team organization, the space for continuous development, and the opportunity to try new things.
    • You get to choose which technology solves the problem and you are responsible for what you create.
    • You will value our Developer Experience and the full platform of tools and technologies that make creating software easier. We rely on an internal ecosystem based on self-service and widely used tools such as Kubernetes, Docker, Consul, GitHub, and GitHub Actions. Thanks to this, you can contribute to Allegro from your very first days on the job.
    • You will be equipped with modern AI tools to automate repetitive tasks, allowing you to focus on developing new services and refining existing ones (also leveraging AI support).
    • You will create solutions that will be used (and loved!) by your friends, family and millions of our customers.
    • You will meet the Allegro Scale, which starts with over 1000 microservices, an open-source data bus (Hermes) with 300K+ rps, a Service Mesh with 1M+ rps, tens of petabytes of data, and production-used machine learning.
    • You will become part of Allegro Tech - We speak at industry conferences, cooperate with tech communities, run our own blog (it's been over 10 years!), record podcasts, lead guilds, and we organize our own internal conference - the Allegro Tech Meeting. We create solutions we love (and can) to talk about!
    Company

    What we offer

    • Flexible working hours in the hybrid model (4/1) - working hours start between 7:00 a.m. and 9:00 a.m. We also have 30 days of occasional remote work
    • Annual bonus based on your annual performance and company results
    • Our team is based in Warsaw, Poznań and Toruń
    • Well-located offices (with e.g. fully equipped kitchens, bicycle parking, terraces full of greenery) and excellent work tools (e.g., raised desks, ergonomic chairs, interactive conference rooms)
    • A 16" or 14" MacBook Pro or corresponding Dell with Windows (if you don't like Macs) and all the necessary accessories
    • A wide selection of fringe benefits in a cafeteria plan - you choose what you like (e.g., medical, sports or lunch packages, insurance, purchase vouchers)
    • English classes that we pay for related to the specific nature of your job
    • A training budget, inter-team tourism (see more here), hackathons, and an internal learning platform where you will find multiple trainings
    • An additional day off for volunteering, which you can use alone, with a team, or with a larger group of people connected by a common goal
    • Social events for Allegro people - Spin Kilometers, Family Day, Fat Thursday, Advent of Code, and many other occasions we enjoy

    Benefits

    • sharing the costs of sports activities
    • private medical care
    • sharing the costs of foreign language classes
    • sharing the costs of professional training & courses
    • life insurance
    • flexible working time
    • integration events
    • no dress code
    • leisure zone
    • extra social benefits
    Mid Cybersecurity Engineer - CSIRT
    I apply to:
    Allegro
    Warszawa, Wola
    Pracodawca zbiera zgłoszenia przez swój system.
    Przejdziesz na zewnętrzny formularz.

    By clicking "Aplikuj" you confirm that you've read and accepted our Terms and Conditions.


    This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

    Need more information?

    • Make sure the body of the offer doesn’t already include what you’re looking for.
    • Ask a question if you need more information you’re interested in.
    • We’ll forward your question to the employer and aim to provide a response within 3 business days.

    Share this offer