Remote job
SOC Analyst (WAAP)
Job details
About this role
Role overview This is a full-time remote position for a Security Operations Center analyst focused on Web Application and API Protection (WAAP). The role sits within an edge network backend development organization in the engineering department, supporting infrastructure that processes traffic across distributed points of presence.
Responsibilities - Monitor, investigate, and respond to security events and alerts generated by WAAP systems protecting web applications and APIs. - Analyze attack patterns, application-layer threats, and anomalous traffic to identify genuine incidents versus false positives. - Tune detection rules, signatures, and policies to reduce noise while maintaining coverage against emerging threats. - Collaborate with backend development and engineering teams to operationalize mitigations and improve defensive posture. - Document incidents, runbooks, and analysis outcomes to support knowledge sharing across the security function.
Requirements - Practical experience in SOC operations, web application security, API security, or a related defensive security role. - Working knowledge of common application-layer attack vectors, including injection, cross-site scripting, credential abuse, and bot traffic. - Familiarity with WAAP concepts, web application firewalls, bot mitigation, or API protection tooling. - Ability to investigate alerts using logs, traffic data, and security telemetry, and to communicate findings clearly. - Eligibility to work remotely from Poland or Serbia on a full-time basis.
Benefits and work setup - Fully remote, full-time position within an engineering organization focused on edge network backend services.