- Location
- Bucharest, Romania
- Type
- Full-time
- Department
- Engineering
- Source
- Workday
Description
THE ROLE & THE TEAM
Zalando Bucharest is our newest site designed to consolidate and scale expert services, ensuring operational excellence as we evolve our global footprint.
Security Incidents have a high potential to cause a severe business impact on the organization. Therefore having a strong Cybersecurity Engineer on the 1st level is crucial for SOC as they form the first line of defence against cyber threats, often being the first to detect anomalies and potential attacks.
In this role, you will be working diligently on the 1st level to monitor, identify, investigate and respond to security threats. Your passion for cybersecurity, combined with your ability to collaborate with and communicate effectively, will be instrumental in the integrity of our digital assets.
INCLUSIVE BY DESIGN
At Zalando, our vision is to be the leading pan-European ecosystem for fashion and lifestyle e-commerce - one that is inclusive by design. We only assess candidates based on qualifications, merit, and business needs. We welcome applications from people of all gender identities, sexual orientations, personal expressions, racial identities, ethnicities, religious beliefs, and disability statuses. We only want to know why you’re great for this role, so please avoid including your picture, age, and marital status in your CV as well.
We want to provide you with a great candidate experience. Please feel free to inform us of any accommodations you may need, so we can best support and assist you throughout the hiring process.
do.BETTER - our diversity & inclusion strategy: https://jobs.zalando.com/en/our-culture/diversity-and-inclusion
WHAT WE’D LOVE YOU TO DO (AND LOVE DOING)
Monitor & Respond to Threats: You’ll actively identify, investigate, and respond to security threats and system anomalies, acting as a core technical anchor within the SOC.
Support Incident Response Operations: In the event of major incidents, you’ll support our CSIRT’s response activities, collaborating with dedicated task forces through the entire Security Incident Lifecycle.
Manage Stakeholder Communications: You’ll handle interactions on incoming security tickets, serving as a reliable point of contact to keep technical and intermediate stakeholders clearly updated throughout the resolution process.
Document Investigations: You’ll maintain high operational standard records by documenting security cases in tickets and authoring forensic incident investigation reports.
Drive Security Optimization: When not responding to active threats, you’ll continuously improve our monitoring coverage, engage in proactive threat hunting, curate operational playbooks, and participate in advanced security education.
WE’D LOVE TO MEET YOU IF
You Have Proven SOC Experience: You bring professional experience (ideally 1+ years) working in a SOC or a CSIRT environment, and you are fully comfortable handling structured on-call responsibilities outside of core business hours.
You Understand Detection & Analysis Tools: You possess a strong foundational knowledge of security monitoring, including practical, hands-on exposure to enterprise SIEM platforms and endpoint detection and response (EDR) tools.
You Know Cloud & Environment Security: You bring a practical understanding of protecting assets on AWS, working with Kubernetes deployments in AWS, and monitoring Google Workspace or similar corporate cloud environments.
You Leverage Frameworks & Scripting: You possess a clear operational understanding of the MITRE ATT&CK Framework and use scripting languages (such as Python, PowerShell, or Bash) to automate tasks and streamline security operations.
You Are a Reliable Communicator: You possess good verbal and written communication skills in English, with a track record of writing structured technical reports and routine handling stakeholder interactions.
OUR OFFER
As we build our new office in Bucharest, we are committed to providing a competitive benefits package tailored to local market practices. Please ask your Talent Acquisition Partner to learn more
about what we plan to offer at the start:
● 22 days of holiday a year, increasing up to 25 days depending on your tenure (every 3 years)
● Private medical coverage with options to add your family
● Daily meal allowance of 30 RON per working day
● Subsidy of public transport ticket
● Office-first working model (at least 3 days a week)