{"schemaVersion":"jobsearcher.job.v1","id":"2ab392fdaeb64b2d6f4c8800","url":"https://jobsearcher.com/jobs/2ab392fdaeb64b2d6f4c8800","canonicalUrl":"https://jobsearcher.com/jobs/2ab392fdaeb64b2d6f4c8800","title":"Security Intelligence Researcher (Cloud Detection & Response)","description":"Security Intelligence Researcher (Cloud Detection & Response) 1-3 years\r\nPoland\r\nFull-Time\r\nSecurity Intelligence Researcher (Cloud Detection & Response)\r\nDepartment: Security Intelligence / Research & Development\r\nExperience: 1-3 years\r\nEmployment Type: Full-time\r\nAbout SecPod\r\nSecPod is a cybersecurity company focused on helping organizations prevent cyberattacks through continuous visibility, intelligent risk analysis, and proactive security.\r\nWe are building the next generation of Cloud Detection & Response (CDR) capabilities to help organizations identify risks, understand attacker behavior, detect anomalies, and take action before threats become incidents.\r\nThe Opportunity We are looking for a Security Intelligence Researcher to join our Cloud Detection & Response team.\r\nThis role is ideal for someone who is curious about how attackers think, enjoys investigating complex security problems, and wants to go beyond simply detecting threats.\r\nYou will research attacker techniques, cloud attack paths, security signals, vulnerabilities, and behavioral patterns to develop intelligence that can help organizations predict, prevent, detect, and respond to cyberattacks .\r\nThe role combines\r\nCybersecurity research\r\nAttack analysis\r\nSecurity data analysis\r\nAutomation and product engineering\r\nYou will work at the intersection of research and product development , converting security intelligence into capabilities that can be used by real-world security teams.\r\nWhat You Will Do Security Research & Threat Intelligence Research emerging cyber threats, attack campaigns, vulnerabilities, and attacker techniques.\r\nStudy how attackers compromise cloud environments and move across infrastructure.\r\nAnalyze TTPs using frameworks such as MITRE ATT&CK.\r\nResearch cloud attack paths across identities, workloads, containers, networks, storage, and APIs.\r\nTrack security intelligence from public sources, threat reports, vulnerability disclosures, and security research communities.\r\nIdentify patterns that can help organizations prevent attacks before exploitation occurs.\r\nResearch and develop detection use cases for cloud environments.\r\nAnalyze security telemetry and identify suspicious behavior and anomalies.\r\nDevelop detection logic for cloud infrastructure, identities, workloads, containers, and applications.\r\nInvestigate attack chains from initial access to privilege escalation, lateral movement, and impact.\r\nDesign detection capabilities that go beyond individual alerts to understand the broader context of an attack.\r\nResearch ways to reduce false positives and improve the quality of security detections.\r\nPrevention-Focused Security Intelligence Our goal is not merely to tell customers that an attack has happened.\r\nWe want to help them understand,\r\nWhat could happen, why it could happen, and what should be done to prevent it.\r\nYou will help develop intelligence that can\r\nIdentify weaknesses before attackers exploit them.\r\nPrioritize the risks that matter most.\r\nConnect vulnerabilities, misconfigurations, identities, assets, and threats.\r\nRecommend preventive actions.\r\nImprove an organization's overall cyber hygiene and resilience.\r\nResearch to Product Convert security research into product requirements and detection use cases.\r\nWork closely with software engineers and product teams to implement research findings.\r\nCreate prototypes, proof-of-concepts, scripts, and automation.\r\nDevelop and maintain security rules, indicators, detections, and intelligence models.\r\nDocument research findings and communicate complex security concepts clearly.\r\nWhat We Are Looking For Strong understanding of cybersecurity fundamentals.\r\nKnowledge of common attack techniques and attacker methodologies.\r\nUnderstanding of cloud security concepts and cloud attack surfaces.\r\nFamiliarity with MITRE ATT&CK or similar threat modeling frameworks.\r\nAbility to analyze logs, events, telemetry, and security data.\r\nStrong research and analytical skills.\r\nAbility to understand how different security signals connect to form an attack story.\r\nStrong programming or scripting skills in Python or Shell Scripts .\r\nGood to Have Experience with one or more of the following\r\nAWS, Azure, or Google Cloud security\r\nThreat Hunting\r\nDetection Engineering\r\nSIEM, XDR, or EDR technologies\r\nKubernetes and container security\r\nIdentity and Access Management\r\nCloud APIs and audit logs\r\nNetwork security\r\nVulnerability research\r\nMalware or attack analysis\r\nSecurity automation\r\nMITRE ATT&CK, D3FEND, or similar frameworks\r\nSecurity data analysis and anomaly detection\r\nThe Kind of Person Who Will Succeed You will thrive in this role if you\r\nAre naturally curious about how attacks work .\r\nEnjoy asking \"What happens next?\"\r\nCan look at seemingly unrelated security events and connect the dots.\r\nLike going deep into technical problems.\r\nAre comfortable researching something you have never seen before.\r\nCan move between a security research paper, a cloud log, a Python script, and a product discussion.\r\nCare about the quality of security intelligence, not just the number of alerts generated.\r\nBelieve that the best security outcome is to prevent the attack from happening in the first place .\r\nWhy This Role Matters Cybersecurity is moving from reactive detection to proactive prevention.\r\nThe future of security is not just\r\n\"An attack has happened. Detect it.\"\r\nIt is\r\n\"These weaknesses and signals indicate that an attack could happen. Understand the risk. Predict the path. Prevent it.\"\r\nAs part of this team, you will help build security intelligence that enables organizations to move from reactive security to proactive cyberattack prevention .\r\nEducation & Experience Bachelor's or Master's degree in Computer Science, Cybersecurity, Information Security, or a related field.\r\n1-3 years of experience in cybersecurity, threat intelligence, cloud security, detection engineering, or a related domain.\r\nWe are also open to exceptional candidates who have demonstrated strong cybersecurity research, programming, and problem-solving skills through projects, open-source contributions, security research, CTFs, or independent work.\r\nJ-18808-Ljbffr","company":"Secpod","rawCompany":"secpod","city":"Cracow","isRemote":false,"isActive":false,"createdAt":"2026-08-06T00:45:21.382Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1299.04","title":"Penetration Testers","slug":"penetration-testers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Security Intelligence Researcher (Cloud Detection & Response)","description":"Security Intelligence Researcher (Cloud Detection & Response) 1-3 years\r\nPoland\r\nFull-Time\r\nSecurity Intelligence Researcher (Cloud Detection & Response)\r\nDepartment: Security Intelligence / Research & Development\r\nExperience: 1-3 years\r\nEmployment Type: Full-time\r\nAbout SecPod\r\nSecPod is a cybersecurity company focused on helping organizations prevent cyberattacks through continuous visibility, intelligent risk analysis, and proactive security.\r\nWe are building the next generation of Cloud Detection & Response (CDR) capabilities to help organizations identify risks, understand attacker behavior, detect anomalies, and take action before threats become incidents.\r\nThe Opportunity We are looking for a Security Intelligence Researcher to join our Cloud Detection & Response team.\r\nThis role is ideal for someone who is curious about how attackers think, enjoys investigating complex security problems, and wants to go beyond simply detecting threats.\r\nYou will research attacker techniques, cloud attack paths, security signals, vulnerabilities, and behavioral patterns to develop intelligence that can help organizations predict, prevent, detect, and respond to cyberattacks .\r\nThe role combines\r\nCybersecurity research\r\nAttack analysis\r\nSecurity data analysis\r\nAutomation and product engineering\r\nYou will work at the intersection of research and product development , converting security intelligence into capabilities that can be used by real-world security teams.\r\nWhat You Will Do Security Research & Threat Intelligence Research emerging cyber threats, attack campaigns, vulnerabilities, and attacker techniques.\r\nStudy how attackers compromise cloud environments and move across infrastructure.\r\nAnalyze TTPs using frameworks such as MITRE ATT&CK.\r\nResearch cloud attack paths across identities, workloads, containers, networks, storage, and APIs.\r\nTrack security intelligence from public sources, threat reports, vulnerability disclosures, and security research communities.\r\nIdentify patterns that can help organizations prevent attacks before exploitation occurs.\r\nResearch and develop detection use cases for cloud environments.\r\nAnalyze security telemetry and identify suspicious behavior and anomalies.\r\nDevelop detection logic for cloud infrastructure, identities, workloads, containers, and applications.\r\nInvestigate attack chains from initial access to privilege escalation, lateral movement, and impact.\r\nDesign detection capabilities that go beyond individual alerts to understand the broader context of an attack.\r\nResearch ways to reduce false positives and improve the quality of security detections.\r\nPrevention-Focused Security Intelligence Our goal is not merely to tell customers that an attack has happened.\r\nWe want to help them understand,\r\nWhat could happen, why it could happen, and what should be done to prevent it.\r\nYou will help develop intelligence that can\r\nIdentify weaknesses before attackers exploit them.\r\nPrioritize the risks that matter most.\r\nConnect vulnerabilities, misconfigurations, identities, assets, and threats.\r\nRecommend preventive actions.\r\nImprove an organization's overall cyber hygiene and resilience.\r\nResearch to Product Convert security research into product requirements and detection use cases.\r\nWork closely with software engineers and product teams to implement research findings.\r\nCreate prototypes, proof-of-concepts, scripts, and automation.\r\nDevelop and maintain security rules, indicators, detections, and intelligence models.\r\nDocument research findings and communicate complex security concepts clearly.\r\nWhat We Are Looking For Strong understanding of cybersecurity fundamentals.\r\nKnowledge of common attack techniques and attacker methodologies.\r\nUnderstanding of cloud security concepts and cloud attack surfaces.\r\nFamiliarity with MITRE ATT&CK or similar threat modeling frameworks.\r\nAbility to analyze logs, events, telemetry, and security data.\r\nStrong research and analytical skills.\r\nAbility to understand how different security signals connect to form an attack story.\r\nStrong programming or scripting skills in Python or Shell Scripts .\r\nGood to Have Experience with one or more of the following\r\nAWS, Azure, or Google Cloud security\r\nThreat Hunting\r\nDetection Engineering\r\nSIEM, XDR, or EDR technologies\r\nKubernetes and container security\r\nIdentity and Access Management\r\nCloud APIs and audit logs\r\nNetwork security\r\nVulnerability research\r\nMalware or attack analysis\r\nSecurity automation\r\nMITRE ATT&CK, D3FEND, or similar frameworks\r\nSecurity data analysis and anomaly detection\r\nThe Kind of Person Who Will Succeed You will thrive in this role if you\r\nAre naturally curious about how attacks work .\r\nEnjoy asking \"What happens next?\"\r\nCan look at seemingly unrelated security events and connect the dots.\r\nLike going deep into technical problems.\r\nAre comfortable researching something you have never seen before.\r\nCan move between a security research paper, a cloud log, a Python script, and a product discussion.\r\nCare about the quality of security intelligence, not just the number of alerts generated.\r\nBelieve that the best security outcome is to prevent the attack from happening in the first place .\r\nWhy This Role Matters Cybersecurity is moving from reactive detection to proactive prevention.\r\nThe future of security is not just\r\n\"An attack has happened. Detect it.\"\r\nIt is\r\n\"These weaknesses and signals indicate that an attack could happen. Understand the risk. Predict the path. Prevent it.\"\r\nAs part of this team, you will help build security intelligence that enables organizations to move from reactive security to proactive cyberattack prevention .\r\nEducation & Experience Bachelor's or Master's degree in Computer Science, Cybersecurity, Information Security, or a related field.\r\n1-3 years of experience in cybersecurity, threat intelligence, cloud security, detection engineering, or a related domain.\r\nWe are also open to exceptional candidates who have demonstrated strong cybersecurity research, programming, and problem-solving skills through projects, open-source contributions, security research, CTFs, or independent work.\r\nJ-18808-Ljbffr","datePosted":"2026-08-06T00:45:21.382Z","dateModified":"2026-08-06T00:45:21.382Z","hiringOrganization":{"@type":"Organization","name":"Secpod","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Cracow","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"2ab392fdaeb64b2d6f4c8800"},"url":"https://jobsearcher.com/jobs/2ab392fdaeb64b2d6f4c8800"}}