Mid Cybersecurity Engineer - CSIRT

Location: 

Warszawa, PL, 00-841 Poznań, PL, 61-569

Company:  Allegro sp. z o.o.
Team:  Technology
Contract Type:  Employee

Job Description

Join the Cybersecurity team! You will have a unique chance to safeguard one of the most visible and high-scale platforms in the region. High performance, engineering best practices, and a great atmosphere in the team guaranteed!

 

Important things for you

 

  • Flexible working hours in the hybrid model (4/1) - working hours start between 7:00 a.m. and 9:00 a.m. We also have 30 days of occasional remote work.

  • Annual bonus based on your annual performance and company results.

  • Our team is based in Warsaw, Poznań and Toruń.

 

About the job

 

  • Massive Scale & Security Challenges: Secure and optimize a world-class, cloud and on-prem environment handling thousands of requests per minute. This is high-availability, high-performance security engineering in practice.

  • Modern Tech Stack: Work within an advanced ecosystem where core technologies include specialized defensive and incident response security tools, automated SOAR playbooks, EDR/XDR systems, modern SIEM systems for logging, correlations and machine learning detection models, AI based security incident response agents.

  • True Ownership & Autonomy: We live by a "you build it, you run it" philosophy. You'll join an autonomous team with full ownership of your security services - from threat intelligence and hunting, EDR, SOAR, SIEM technologies to deploying custom incident response assistants.

  • Complex Architectural Puzzles: From securing distributed systems to tackling novel AI vulnerabilities, you'll solve complex engineering problems that directly protect a massive, real-time marketplace.

Skills required

 

  • Have experience working in SOC, CERT or CSIRT teams

  • Have experience using SOAR, EDR/XDR and SIEM systems

  • Possess and continuously develop knowledge of current offensive and defensive security threats

  • Have hands-on experience working with modern, large-scale IT infrastructure and understand DevOps culture

  • Are familiar with the Linux systems (Ubuntu/Debian), Windows and MacOS

  • Have designed, implemented, developed, or maintained solutions that enhance security

  • Have participated in security incidents handling

  • Can communicate and collaborate effectively with people from different areas and levels of the organization

  • Understand the importance of IT security technologies, tools, and procedures, and their impact on the business

  • Demonstrate high independence and a self-driven approach – you are capable of taking full, end-to-end incident response process, from investigation, evidence and log collection to final reporting and remediation guidance

  • Are keen on leveraging automation and AI-assisted techniques to improve incident response, detection rules tuning and innovate defensive techniques.

  • Are open to developing soft skills and embracing a growth mindset through active participation in team retrospectives and cross-team collaborations;

  • Are excited about adopting and securing AI technologies, being ready to incorporate AI coding and security assistants into their daily work to maximize efficiency;

  • Want to constantly develop and update their knowledge in a rapidly shifting threat landscape;

  • Know English at at least B2 level.

 

Your main responsibilities:

 

  • Monitor and triage security incidents generated by EDR/XDR, SIEM and other detection platforms to identify true positive incidents in real time, 24/7 on-call rotation.

  • Investigate and respond to endpoint and server threats such as malicious behavior on corporate workstations and servers.

  • Analyze and mitigate phishing campaigns targeting Allegro brands (Allegro, Allegro Lokalnie, AllegroPay) - identifying malicious domains impersonating the company, coordinating takedown requests, and enriching related IOCs.

  • Detects and responds to network-layer attacks, including DDoS attempts, password spraying, abnormal BOT scanning.

  • Perform digital forensics and log correlation across multiple data sources (Active Directory sign-ins, endpoint and server logs, proxy, DNS, VPN, DHCP logs) to reconstruct attack timelines and root cause.

  • Enrich and correlate Indicators of Compromise (IPs, domains, hashes, URLs) using threat intelligence platforms and internal asset inventories to assess scope and impact.

  • Investigate identity-related risks, such as suspected account takeovers, impersonation, and anomalous user behavior flagged by identity protection tools.

  • Document findings and produce evidence-based incident reports, including root cause analysis, MITRE ATT&CK mapping, and remediation recommendations for stakeholders and asset owners.

  • Coordinate remediation actions with IT, infrastructure, and business teams (e.g. account lockouts, endpoint isolation, credential resets, domain blocking).

  • Continuously improve detection capabilities by tuning correlation rules, updating threat intelligence, and identifying gaps based on recurring incident patterns.

  • Collaborate with brand protection and external partners to detect and respond to threats against Allegro's reputation and customers.

What's in it for you: 

 

  • Well-located offices (with e.g. fully equipped kitchens, bicycle parking, terraces full of greenery) and excellent work tools (e.g., raised desks, ergonomic chairs, interactive conference rooms).

  • A 16" or 14" MacBook Pro or corresponding Dell with Windows (if you don't like Macs) and all the necessary accessories.

  • A wide selection of fringe benefits in a cafeteria plan - you choose what you like (e.g., medical, sports or lunch packages, insurance, purchase vouchers).

  • English classes that we pay for related to the specific nature of your job.

  • A training budget, inter-team tourism (see more here), hackathons, and an internal learning platform where you will find multiple trainings. 

  • An additional day off for volunteering, which you can use alone, with a team, or with a larger group of people connected by a common goal. 

  • Social events for Allegro people - Spin Kilometers, Family Day, Fat Thursday, Advent of Code, and many other occasions we enjoy.


And that's just the beginning! You can read more about the benefits here.

 

#goodtobehere means that:

 

  • You will join a team you can count on - we work with top-class specialists who have knowledge- and experience-sharing in their DNA.

  • You will love our level of autonomy in team organization, the space for continuous development, and the opportunity to try new things. You get to choose which technology solves the problem and you are responsible for what you create.

  • You will be equipped with modern AI tools to automate repetitive tasks, allowing you to focus on analyzing complex threats, developing advanced security automation, and refining secure architectures.

  • You will meet the Allegro Scale, which starts with over 1000 microservices, an open-source data bus (Hermes) with 300K+ rps, a Service Mesh with 1M+ rps, tens of petabytes of data, and production-used machine learning. 

  • You will become part of Allegro Tech - We speak at industry conferences, cooperate with tech communities, run our own blog (it's been over 10 years!), record podcasts, lead guilds, and we organize our own internal conference - the Allegro Tech Meeting. We create solutions we love (and can) to talk about! 

 

Send us your CV and… see you at Allegro!

 

Don’t wait until you join us! Let's meet online!

Get to know our team, take a peek at our office life and check out what else we do at Allegro.