Team Lead - Principal Security Detection & Response Analyst Team Lead

Alert Logic
Alert Logic

IT

Poland

Posted on Sep 8, 2026
LevelBlue reduces risk and builds lasting resilience so organizations can innovate and advance their mission with confidence. As the world’s most analyst-recognized and largest pure-play managed security services provider, LevelBlue elevates client outcomes that matter: stronger defense, faster response, and sustained business continuity. LevelBlue combines AI-powered security operations, advanced threat intelligence, and elite human expertise to provide the most comprehensive portfolio of strategic advisory, managed security, offensive security, and incident response services.ONLY POLAND BASED - Employment Contract We are looking for an experienced, hands-on cybersecurity professional to join our Global Security Operations team as a Senior or Principal Security Detection & Response Analyst and EU SOC Team Lead. This is primarily a hands-on technical role with additional Team Lead responsibilities. You will operate as a Tier 2 or Tier 3 Security Detection & Response Analyst while providing day-to-day support, coordination, coaching and technical leadership to other analysts within the EU SOC. This role requires Fluent English and either French or German languages. As an analyst, you will investigate and respond to sophisticated security threats, act as an escalation point for other analysts, participate in threat hunting and incident response, and work directly with customers to protect their environments. As Team Lead, you will help the EU SOC operate effectively on a day-to-day basis by supporting analysts, coordinating activity, monitoring workload and raising operational or resourcing concerns to SOC leadership. You will work closely with the EU SOC Director and other regional teams as part of our global follow-the-sun operating model. The Cybereason Global SOC provides 24/7 active monitoring and proactive threat hunting services, delivering fast identification, response and analysis of threats to help keep our customers safe from today's and tomorrow's adversaries. Key Responsibilities Security Analysis & Incident Response· Perform hands-on security analysis and investigation of complex endpoint and security alerts across MDR and MXDR environments.· Act as a technical escalation point for Tier 1 and Tier 2 analysts.· Piece together attack chains across complex customer environments including endpoint, cloud, identity, email and network technologies.· Participate in all stages of incident investigations, including taking decisive action in response to active breaches.· Conduct proactive threat hunting across customer environments to identify attackers, suspicious activity or remnants of compromise.· Research new and emerging attacks, threat actors, malware and attacker tactics, techniques and procedures (TTPs).· Collect, process and exploit OSINT to support investigations, improve threat-hunting queries and contribute to Threat Alerts.· Engage directly with customers during investigations and escalations, communicating effectively with stakeholders ranging from SOC analysts to C-suite executives.· Remain actively involved in the analyst workload, supporting operational investigations and escalations as required.Team Lead ResponsibilitiesAlongside your analyst responsibilities, you will provide day-to-day support and leadership to the EU SOC team.· Provide coaching, mentoring and technical guidance to EU SOC analysts.· Act as a first point of contact for analysts requiring support with technical or operational issues.· Help coordinate day-to-day activity across the team and ensure work is appropriately prioritised.· Maintain awareness of team workload and operational coverage, raising potential capacity or coverage concerns with SOC leadership.· Support analysts with complex investigations and customer escalations.· Encourage collaboration, knowledge sharing and consistent working practices across the team.· Help ensure Global SOC policies, procedures and operational processes are understood and followed.· Support the monitoring of service delivery, SLOs, SLAs and operational metrics, highlighting potential issues to SOC leadership.· Identify opportunities to improve investigation processes, methodologies and ways of working.· Support onboarding and development of new analysts.· Provide feedback to SOC leadership on team development, operational challenges and areas for improvement. What we are looking for:-We are looking for someone who combines strong technical security expertise with the ability and desire to support and develop others.· Significant experience working within a SOC, MDR, incident response or similar cybersecurity environment.· Technical capability appropriate to a Senior/Tier 2 or Principal/Tier 3 Security Analyst position.· Strong hands-on security investigation and incident-response skills.· Experience in at least two of the following areas: Endpoint security, Malware analysis, Threat hunting / threat intelligence, Incident response, Penetration testing, Reverse engineering and Digital forensics· Strong knowledge of modern operating systems, particularly Windows; knowledge of macOS and Linux is advantageous.· Solid understanding of networking protocols and network architecture. Familiarity with common security tools, technologies and frameworks.· Experience with scripting languages such as Python, Bash or PowerShell is advantageous.· Previous Team Lead or people-management experience, ability to balance Team Lead responsibilities with an active technical workload.· Ability to explain complex technical issues to both technical and non-technical audiences.· Strong customer-facing skills and confidence engaging with senior stakeholders.· Excellent English reading, writing and speaking skills.· Additional European languages, particularly French or German, are required for this role.Why it Matters:Joining our team means becoming a vital part of a market-leading force dedicated to safeguarding critical assets, solving complex security challenges, and delivering innovative services that meet the security needs of our global customer base.Why You Will Love It:Exceptional Team: Lead a highly skilled team and collaborate with experienced leaders in cybersecurity who share your passion for delivering market-leading Managed Security Services.Global Exposure: Gain insight into various aspects of the Managed Security Services business, with your leadership and actions directly impacting the security of organizations worldwide.Ownership and Impact: Assume responsibility for defining and executing processes that consistently deliver outstanding results.Desired Experience: 7 or more years of information security or networking experience.Previous operational experience as an analyst, engineer, or team lead.Excellent customer service skills.Strong analytical thinking and problem-solving skills.Strong oral and written communication skills.Self-managed and team-oriented, with the ability to coach and teach.Responsive, collaborative, and highly motivated.Leadership and management experience. Preferred: Bachelor's/Master's Degree in Information Technology or a similar area of study.At least 7 years of experience in Information Security or Networking.Certification in a security-related industry, vendor, or professional certification What We Offer: Contract of employmentSport card/ co-financing of vacationLife insuranceMedical insuranceLunch cardAnnual bonusEmployee assistance program (EAP)The employee pension scheme (PPE) This role is open to candidates legally authorized to work in Poland. At LevelBlue, we support flexible work and bring people together in person for key moments based on role, team, and business needs.LevelBlue is committed to a culture of respect, inclusion, and equal opportunity. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age, or any other status protected under applicable law.To all agencies: Please do not contact LevelBlue outside of the Talent Acquisition team. LevelBlue’s policy is to only accept resumes from agencies through its approved agency process and with a valid agreement in place. Any resume submitted outside this process will be considered the property of LevelBlue, and no fee will be paid if a candidate is hired from such a submission. #LI-SD1