×
Hier anmelden um sich kostenlos auf Stellen zu bewerben oder Stellenanzeigen aufzugeben. X

SOC Analyst; WAAP

in 28195, Bremen, Bremen, Deutschland
Unternehmen: G-CORE INNOVATIONS SOCIETE A RESPONSABILITE LIMITEE
Vollzeit position
Verfasst am 2026-10-05
Berufliche Spezialisierung:
  • IT/Informationstechnik
    Cyber-Sicherheit, Netzwerksicherheit
Gehalts-/Lohnspanne oder Branchenbenchmark: 55000 - 85000 EUR pro Jahr EUR 55000.00 85000.00 YEAR
Stellenbeschreibung
Stellenbezeichnung: SOC Analyst (WAAP)

This position is available only under an employment (labor) agreement.

The world’s digital experiences run on something invisible: the infrastructure and software that keep them fast, reliable, and secure. At Gcore,
you’ll help design and deliver that foundation for an AI-driven world.

We’re a global provider of infrastructure and software solutions for
AI, cloud, network, and security,powering everything from real-time communication and streaming to enterprise AI and secure web applications. With
210+ edge locations, 50+ cloud regions, and thousands of GPUs,your work here can reach users and businesses across the globe.

You’ll collaborate with leading technology partners such as
Intel, NVIDIA, Dell, and Equinix,and work on platforms that power digital products used around the world. Our vision is simple: to connect the world to AI, anywhere, anytime.

Want to work on technology that goes beyond a single product or industry? Join a global team of
550+ professionals
building infrastructure and software that supports the entire digital ecosystem.

Job Description

Gcore WAAP protects customer web applications and APIs against DDoS, bots, and application-layer attacks at CDN edge scale. We are building out a proactive, managed-support offering for enterprise customers, and we need a SOC Analyst to run the day-to-day security operations: watch traffic and alerts, triage false positives, prepare customer-facing threat reports, and elevate real impact to the right team. You will work alongside our Threat Researchers, taking the operational load off them so they can focus on deep analysis.

You do not need to be a threat-hunting expert.

You need to be reliable, observant, comfortable in logs and dashboards, and able to tell an attack from legitimate traffic - and know when to escape.

What You Will Do

  • Monitor WAAP and DDoS activity across customer accounts - dashboards, alerts, and traffic patterns - and recognize when something needs attention.
  • Triage false positives: review traffic flagged by security policies, confirm or dismiss, and keep noise down for customers (this is a large, daily part of the job).
  • Prepare reports: weekly threat summaries per customer and post-incident DDoS reports, in clear customer-facing English.
  • Alert and elevate: when an attack is impacting a customer, signal the engineering team or Support with the right context - e.g. a customer needs to be tagged or a policy adjusted - and follow the escalation runbook.
  • Support customer onboarding: apply standard security configuration based on the customer's profile (resource type, traffic volume, legitimate-traffic exclusions) following playbooks.
  • Follow the reaction-time SLA - our commitment to customers is speed of reaction and clear post-incident reporting, not a prevention guarantee.
  • Contribute to and maintain runbooks so responses are consistent and repeatable.
Qualifications

What We are Looking For

  • Understanding of web security fundamentals: WAF, DDoS, bots, OWASP Top 10.
  • Solid basics in HTTP, TCP/IP, TLS.
  • Comfortable analyzing logs and reading dashboards; can spot anomalies in traffic.
  • Able to distinguish malicious from legitimate traffic and reason about false positives.
  • Clear written English for customer-facing reports.
  • Reliable, detail-oriented, and calm under incident pressure.
  • Willingness to work in a shift/on-call rotation.

Nice to Have

  • Prior SOC L1/L2 or related experience.
  • Basic query/scripting: SQL-like log queries, regex, a bit of Python.
  • Familiarity with CDN/WAF platforms (Cloudflare, Akamai, Imperva, F5, Radware).
  • Exposure to SIEM / alerting tooling and Pager Duty-style on-call.
  • Security certifications (e.g. CompTIA Security+) - a plus, not a requirement.

Explicitly NOT Required

  • Deep threat research, exploit development, malware…
Um Jobs auf dieser Seite anzusehen und sich zu bewerben, die Bewerbungen aus Ihrem Standort oder Land akzeptieren, klicken Sie unten auf den Button, um eine Suche zu starten.
(Wenn dieser Job tatsächlich in Ihrem Zuständigkeitsbereich liegt, verwenden Sie möglicherweise einen Proxy oder VPN, um auf diese Seite zuzugreifen. Um weiterzukommen, sollten Sie Ihre Verbindung zu einem anderen Mobilgerät oder PC wechseln).
 
 
 
Suchen Sie hier nach weiteren Stellen:
(nach Beruf, Fähigkeit)
Standort
Suchradius erweitern (Meilen)
0
200
Filter
Mindest-Bildungsgrad für die Stelle
Mindest-Berufserfahrung für die Stelle
Veröffentlicht in den letzten:
Gehalt