Security Intelligence Researcher (Cloud Detection & Response)
Security Intelligence Researcher (Cloud Detection & Response)
Location: Warsaw Office
Department: Security Intelligence / Research & Development
Experience: 1-3 years
Employment Type: Full-time
About SecPod
SecPod is a cybersecurity company focused on helping organizations prevent cyberattacks through continuous visibility, intelligent risk analysis, and proactive security.
We are building the next generation of Cloud Detection & Response (CDR) capabilities to help organizations identify risks, understand attacker behavior, detect anomalies, and take action before threats become incidents.
The Opportunity
We are looking for a Security Intelligence Researcher to join our Cloud Detection & Response team.
This role is ideal for someone who is curious about how attackers think, enjoys investigating complex security problems, and wants to go beyond simply detecting threats.
You will research attacker techniques, cloud attack paths, security signals, vulnerabilities, and behavioral patterns to develop intelligence that can help organizations predict, prevent, detect, and respond to cyberattacks.
The role combines
- Cybersecurity research
- Cloud security
- Threat intelligence
- Detection engineering
- Attack analysis
- Security data analysis
- Automation and product engineering
You will work at the intersection of research and product development, converting security intelligence into capabilities that can be used by real-world security teams.
What You Will Do
Security Research & Threat Intelligence
- Research emerging cyber threats, attack campaigns, vulnerabilities, and attacker techniques.
- Study how attackers compromise cloud environments and move across infrastructure.
- Analyze TTPs using frameworks such as MITRE ATT&CK.
- Research cloud attack paths across identities, workloads, containers, networks, storage, and APIs.
- Track security intelligence from public sources, threat reports, vulnerability disclosures, and security research communities.
- Identify patterns that can help organizations prevent attacks before exploitation occurs.
Cloud Detection & Response
- Research and develop detection use cases for cloud environments.
- Analyze security telemetry and identify suspicious behavior and anomalies.
- Develop detection logic for cloud infrastructure, identities, workloads, containers, and applications.
- Investigate attack chains from initial access to privilege escalation, lateral movement, and impact.
- Design detection capabilities that go beyond individual alerts to understand the broader context of an attack.
- Research ways to reduce false positives and improve the quality of security detections.
Prevention-Focused Security Intelligence
Our goal is not merely to tell customers that an attack has happened.
We want to help them understand,
What could happen, why it could happen, and what should be done to prevent it.
You will help develop intelligence that can
- Identify weaknesses before attackers exploit them.
- Predict potential attack paths.
- Prioritize the risks that matter most.
- Connect vulnerabilities, misconfigurations, identities, assets, and threats.
- Recommend preventive actions.
- Improve an organization's overall cyber hygiene and resilience.
Research to Product
- Convert security research into product requirements and detection use cases.
- Work closely with software engineers and product teams to implement research findings.
- Create prototypes, proof-of-concepts, scripts, and automation.
- Develop and maintain security rules, indicators, detections, and intelligence models.
- Document research findings and communicate complex security concepts clearly.
What We Are Looking For
Essential Skills
- Strong understanding of cybersecurity fundamentals.
- Knowledge of common attack techniques and attacker methodologies.
- Understanding of cloud security concepts and cloud attack surfaces.
- Familiarity with MITRE ATT&CK or similar threat modeling frameworks.
- Ability to analyze logs, events, telemetry, and security data.
- Strong research and analytical skills.
- Ability to understand how different security signals connect to form an attack story.
- Strong programming or scripting skills in Python or Shell Scripts.
Good to Have
Experience with one or more of the following
- AWS, Azure, or Google Cloud security
- Cloud Detection & Response
- Threat Intelligence
- Threat Hunting
- Detection Engineering
- SIEM, XDR, or EDR technologies
- Kubernetes and container security
- Identity and Access Management
- Cloud APIs and audit logs
- Network security
- Vulnerability research
- Malware or attack analysis
- Security automation
- MITRE ATT&CK, D3FEND, or similar frameworks
- Security data analysis and anomaly detection
The Kind of Person Who Will Succeed
You will thrive in this role if you
- Are naturally curious about how attacks work.
- Enjoy asking "What happens next?"
- Can look at seemingly unrelated security events and connect the dots.
- Like going deep into technical problems.
- Are comfortable researching something you have never seen before.
- Can move between a security research paper, a cloud log, a Python script, and a product discussion.
- Care about the quality of security intelligence, not just the number of alerts generated.
- Believe that the best security outcome is to prevent the attack from happening in the first place.
Why This Role Matters
Cybersecurity is moving from reactive detection to proactive prevention.
The future of security is not just
"An attack has happened. Detect it."
It is
"These weaknesses and signals indicate that an attack could happen. Understand the risk. Predict the path. Prevent it."
As part of this team, you will help build security intelligence that enables organizations to move from reactive security to proactive cyberattack prevention.
Education & Experience
- Bachelor's or Master's degree in Computer Science, Cybersecurity, Information Security, or a related field.
- 1-3 years of experience in cybersecurity, threat intelligence, cloud security, detection engineering, or a related domain.
We are also open to exceptional candidates who have demonstrated strong cybersecurity research, programming, and problem-solving skills through projects, open-source contributions, security research, CTFs, or independent work.
Join Us
If you are excited by the idea of understanding how cyberattacks happen and using that understanding to stop them before they happen, we would love to hear from you.