{"id":1472621,"url":"https://alion.io/job/gcore-soc-analyst","title":"SOC Analyst","company":{"id":1758380,"name":"Gcore","domain":"salute.gov.it","url":"https://alion.io/company/salute-gov-it","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":null,"truth_index":null},"role":"Security","role_family":"Security","seniority":null,"employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"inferred_city","remote_working_hours":null,"hiring_geo_confidence":"inferred","locations":["Kraków, Poland"],"countries":["PL"],"hiring_countries":["PL"],"hiring_countries_total":1,"salary":null,"salary_estimate":{"min_usd":53000,"max_usd":107000,"period":"year","method":"role_country_seniority_unknown","sample_n":94},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"OWASP","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"SLI/SLO/SLA","optional":false},{"name":"TCP/IP","optional":false},{"name":"Akamai","optional":true},{"name":"Cloudflare","optional":true},{"name":"PagerDuty","optional":true},{"name":"Python","optional":true},{"name":"SIEM","optional":true},{"name":"SQL","optional":true}],"status":"live","first_seen_at":"2026-09-29T16:00:11Z","employer_posted_date":null,"last_verified_at":"2026-09-29T16:00:11Z","board_verified":false,"closed_at":null,"days_open":3,"trust":{"level":"not_scored","repost_count":null,"flags":[],"days_open":3},"description":"The world's digital experiences run on something invisible: the infrastructure and software that keep them fast, reliable, and secure. At Gcore, you'll help design and deliver that foundation for an AI-driven world.\nWe're a global provider of infrastructure and software solutions for AI, cloud, network, and security, powering everything from real-time communication and streaming to enterprise AI and secure web applications. With 210+ edge locations, 50+ cloud regions, and thousands of GPUs, your work here can reach users and businesses across the globe.\nYou'll collaborate with leading technology partners such as Intel, NVIDIA, Dell, and Equinix, and work on platforms that power digital products used around the world. Our vision is simple: to connect the world to AI, anywhere, anytime.\nWant to work on technology that goes beyond a single product or industry? Join a global team of 550+ professionals building infrastructure and software that supports the entire digital ecosystem.\nGcore WAAP protects customer web applications and APIs against DDoS, bots, and application-layer attacks at CDN edge scale. We are building out a proactive, managed-support offering for enterprise customers, and we need a SOC Analyst to run the day-to-day security operations: watch traffic and alerts, triage false positives, prepare customer-facing threat reports, and escalate real impact to the right team. You will work alongside our Threat Researchers, taking the operational load off them so they can focus on deep analysis. You do not need to be a threat-hunting expert.\nYou need to be reliable, observant, comfortable in logs and dashboards, and able to tell an attack from legitimate traffic - and know when to escalate.\nWhat You Will Do\nMonitor WAAP and DDoS activity across customer accounts - dashboards, alerts, and traffic patterns - and recognize when something needs attention.\n\nTriage false positives: review traffic flagged by security policies, confirm or dismiss, and keep noise down for customers (this is a large, daily part of the job).\n\nPrepare reports: weekly threat summaries per customer and post-incident DDoS reports, in clear customer-facing English.\n\nAlert and escalate: when an attack is impacting a customer, signal the engineering team or Support with the right context - e.g. a customer needs to be tagged or a policy adjusted - and follow the escalation runbook.\n\nSupport customer onboarding: apply standard security configuration based on the customer's profile (resource type, traffic volume, legitimate-traffic exclusions) following playbooks.\n\nFollow the reaction-time SLA - our commitment to customers is speed of reaction and clear post-incident reporting, not a prevention guarantee.\n\nContribute to and maintain runbooks so responses are consistent and repeatable.\n\nWhat We are Looking For\nUnderstanding of web security fundamentals: WAF, DDoS, bots, OWASP Top 10.\n\nSolid basics in HTTP, TCP/IP, TLS.\n\nComfortable analyzing logs and reading dashboards; can spot anomalies in traffic.\n\nAble to distinguish malicious from legitimate traffic and reason about false positives.\n\nClear written English for customer-facing reports.\n\nReliable, detail-oriented, and calm under incident pressure.\n\nWillingness to work in a shift/on-call rotation.\n\nNice to Have\nPrior SOC L1/L2 or related experience.\n\nBasic query/scripting: SQL-like log queries, regex, a bit of Python.\n\nFamiliarity with CDN/WAF platforms (Cloudflare, Akamai, Imperva, F5, Radware).\n\nExposure to SIEM / alerting tooling and PagerDuty-style on-call.\n\nSecurity certifications (e.g. CompTIA Security+) - a plus, not a requirement.\n\nExplicitly NOT Required\nDeep threat research, exploit development, malware reverse-engineering. That work stays with our Threat Researchers - this role feeds them clean, triaged signal and takes the routine off their plate.\n\nWhy This Role Matters\nYou become the first line of Gcore WAAP's managed security operations - the person who keeps customers informed and protected day to day, and who lets our specialists focus on the hard problems. High visibility, direct customer impact, and a clear path to grow into threat research or detection engineering.\nBenefits\nAt Gcore, we want you to do your best work and enjoy the journey. Our benefits are designed to support your growth, well-being, and life beyond work:\nCompetitive compensation\n\nFlexible working hours and hybrid or remote options, depending on your role\n\nWork from anywhere in the world for up to 45 days per year\n\nPrivate medical insurance for you and your family*\n\nExtra paid vacation and sick leave days*\n\nSupport for life's important moments and celebrations\n\nLanguage courses to help you connect and grow\n\nModern, welcoming offices with snacks, drinks, and entertainment*\n\nTeam sports and social activities*\n\n*Benefits may vary depending on your location.\nEqual Opportunity Employer\nWe provide equal opportunity to all applicants without regard to race, color, religion, sex, sexual orientation, age, gender identity, gender expression, national origin, disability, or any other legally protected characteristics.","description_format":"text","description_chars":5102,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[{"language":"English","level":"All levels","optional":false}]},"benefits":["Flexible schedule","Health insurance"],"hiring_locations":[{"name":"Poland","iso":"PL","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Incident Response"],"lifecycle":[{"event":"open","at":"2026-09-29T17:05:32Z"}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":2,"expected_fill_days":26,"reasons":["seen:2","velocity","win:early"],"computed_at":"2026-10-02T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/gcore-soc-analyst","json_url":"https://alion.io/job/gcore-soc-analyst.json","meta":{"generated_at":"2026-10-03T03:29:58Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3303,"day_limit":5000,"remaining_today":1697,"minute_limit":60,"resets_at":"2026-10-04T00:00:00Z"}}}