Incident Response Lead, CSIRT

Zscaler
Poland
Workplace: RemoteFull timePLN 178,500 - 255,000 annuallyFunction: Administration & Executive AssistanceEducation: bachelorsSkills: ["Ownership","Problem-solving","Urgency","Data-driven decision-making","Cross-functional collaboration"]

Lead incident response for major security events as the CSIRT/SoC escalation point, serving as incident commander during active incidents. Drive proactive threat hunting using open-source and commercial threat intelligence, and build high-fidelity detections with SIEM/SOAR/EDR tools and YARA-L. Mentor SOC analysts and improve incident response readiness while translating findings into clear executive summaries.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Zscaler
Zscaler
2 days ago

Incident Response Lead, CSIRT

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 10 hours agoStatus: Live

Job Summary

Lead incident response for major security events as the CSIRT/SoC escalation point, serving as incident commander during active incidents. Drive proactive threat hunting using open-source and commercial threat intelligence, and build high-fidelity detections with SIEM/SOAR/EDR tools and YARA-L. Mentor SOC analysts and improve incident response readiness while translating findings into clear executive summaries.
Location: Poland
Workplace: Remote
Employment Type: Full time
Job Function: Administration & Executive Assistance
Seniority: Mid level

Key Responsibilities

  • •Serve as incident commander to lead and manage major security incidents through resolution.
  • •Drive proactive threat hunting initiatives using open-source and commercial intelligence to discover hidden threats.
  • •Develop, test, and deploy high-fidelity detection logic to enhance security monitoring.
  • •Act as the primary technical escalation point for SOC analysts during designated coverage shifts.
  • •Mentor team members to elevate SOC operational capabilities and incident response readiness.

Pay and Benefits

Salary: PLN 178,500 - 255,000 annually
Perks:Health InsuranceParental LeaveRetirementLearning Budget

Key Requirements

  • •Foundational understanding of AI/ML technologies and experience leveraging AI-driven solutions to optimize outcomes.
  • •Experience leading major incident response efforts within a large organization, preferably a SaaS provider.
  • •Experience collaborating cross-functionally to resolve complex security issues.
  • •Hands-on experience with SIEM, SOAR, and EDR tools, including authoring detection logic using YARA-L.
  • •Bachelor’s degree in Cybersecurity, Information Technology, or a related technical field.
Experience:SaaSSOCIncident responseThreat hunting
Education:Bachelor's in Cybersecurity or Information Technology (or related technical field)
Skills:OwnershipProblem-solvingUrgencyData-driven decision-makingCross-functional collaboration
Certifications:CISSPOSCPGCFAGNFA
Languages:English
Tech Stack:AIMLSIEMSOAREDRYARA-LThreat intelligenceThreat huntingOpen-source intelligence

Company Brief

Zscaler
Provides cloud-native security platform delivering secure access, threat protection, and zero trust services to organizations, enabling secure internet and private application access without traditional network appliances.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Jose, United States
Founded: 2007
WebsiteLinkedIn