JOBSEARCHER

Security Intelligence Researcher (Cloud Detection & Response)

SecpodL5 SeniorAugust 6th, 2026
Security Intelligence Researcher (Cloud Detection & Response) 1-3 years Poland Full-Time Security Intelligence Researcher (Cloud Detection & Response) Department: Security Intelligence / Research & Development Experience: 1-3 years Employment Type: Full-time About SecPod SecPod is a cybersecurity company focused on helping organizations prevent cyberattacks through continuous visibility, intelligent risk analysis, and proactive security. We are building the next generation of Cloud Detection & Response (CDR) capabilities to help organizations identify risks, understand attacker behavior, detect anomalies, and take action before threats become incidents. The Opportunity We are looking for a Security Intelligence Researcher to join our Cloud Detection & Response team. This role is ideal for someone who is curious about how attackers think, enjoys investigating complex security problems, and wants to go beyond simply detecting threats. You will research attacker techniques, cloud attack paths, security signals, vulnerabilities, and behavioral patterns to develop intelligence that can help organizations predict, prevent, detect, and respond to cyberattacks . The role combines Cybersecurity research Attack analysis Security data analysis Automation and product engineering You will work at the intersection of research and product development , converting security intelligence into capabilities that can be used by real-world security teams. What You Will Do Security Research & Threat Intelligence Research emerging cyber threats, attack campaigns, vulnerabilities, and attacker techniques. Study how attackers compromise cloud environments and move across infrastructure. Analyze TTPs using frameworks such as MITRE ATT&CK. Research cloud attack paths across identities, workloads, containers, networks, storage, and APIs. Track security intelligence from public sources, threat reports, vulnerability disclosures, and security research communities. Identify patterns that can help organizations prevent attacks before exploitation occurs. Research and develop detection use cases for cloud environments. Analyze security telemetry and identify suspicious behavior and anomalies. Develop detection logic for cloud infrastructure, identities, workloads, containers, and applications. Investigate attack chains from initial access to privilege escalation, lateral movement, and impact. Design detection capabilities that go beyond individual alerts to understand the broader context of an attack. Research ways to reduce false positives and improve the quality of security detections. Prevention-Focused Security Intelligence Our goal is not merely to tell customers that an attack has happened. We want to help them understand, What could happen, why it could happen, and what should be done to prevent it. You will help develop intelligence that can Identify weaknesses before attackers exploit them. Prioritize the risks that matter most. Connect vulnerabilities, misconfigurations, identities, assets, and threats. Recommend preventive actions. Improve an organization's overall cyber hygiene and resilience. Research to Product Convert security research into product requirements and detection use cases. Work closely with software engineers and product teams to implement research findings. Create prototypes, proof-of-concepts, scripts, and automation. Develop and maintain security rules, indicators, detections, and intelligence models. Document research findings and communicate complex security concepts clearly. What We Are Looking For Strong understanding of cybersecurity fundamentals. Knowledge of common attack techniques and attacker methodologies. Understanding of cloud security concepts and cloud attack surfaces. Familiarity with MITRE ATT&CK or similar threat modeling frameworks. Ability to analyze logs, events, telemetry, and security data. Strong research and analytical skills. Ability to understand how different security signals connect to form an attack story. Strong programming or scripting skills in Python or Shell Scripts . Good to Have Experience with one or more of the following AWS, Azure, or Google Cloud security Threat Hunting Detection Engineering SIEM, XDR, or EDR technologies Kubernetes and container security Identity and Access Management Cloud APIs and audit logs Network security Vulnerability research Malware or attack analysis Security automation MITRE ATT&CK, D3FEND, or similar frameworks Security data analysis and anomaly detection The Kind of Person Who Will Succeed You will thrive in this role if you Are naturally curious about how attacks work . Enjoy asking "What happens next?" Can look at seemingly unrelated security events and connect the dots. Like going deep into technical problems. Are comfortable researching something you have never seen before. Can move between a security research paper, a cloud log, a Python script, and a product discussion. Care about the quality of security intelligence, not just the number of alerts generated. Believe that the best security outcome is to prevent the attack from happening in the first place . Why This Role Matters Cybersecurity is moving from reactive detection to proactive prevention. The future of security is not just "An attack has happened. Detect it." It is "These weaknesses and signals indicate that an attack could happen. Understand the risk. Predict the path. Prevent it." As part of this team, you will help build security intelligence that enables organizations to move from reactive security to proactive cyberattack prevention . Education & Experience Bachelor's or Master's degree in Computer Science, Cybersecurity, Information Security, or a related field. 1-3 years of experience in cybersecurity, threat intelligence, cloud security, detection engineering, or a related domain. We are also open to exceptional candidates who have demonstrated strong cybersecurity research, programming, and problem-solving skills through projects, open-source contributions, security research, CTFs, or independent work. J-18808-Ljbffr