Incident Response Lead, CSIRT

Zscaler · Wrocław, POL · Office - Wrocław, Poland

Spotted 3h ago

What you'll need to apply

Fields this application requires

NameEmailPhoneRésuméWork authorization answerVisa sponsorship answerLocation

Company-specific questions

  • How did you learn about this job?
  • Do you currently work for, or have you previously worked for Zscaler?
  • Current Company
  • Current Title
  • Zscaler Confidential Information
  • Zscaler Privacy Policy
  • Have you been involved in procurement or contract award activities involving Zscaler as a government employee or official?
  • Home Address
Job description

About this role

Employer-provided description, formatted for easier reading.

Zscaler (NASDAQ: ZS) accelerates digital transformation so customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust Exchange™️ platform protects thousands of customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location.

Distributed across 160+ public exchanges globally and thousands of private exchanges at the edge, the SASE-based Zero Trust Exchange is the world’s largest in-line cloud security platform.

We believe the future of work is Human + AI and are building an AI-native enterprise where human potential is amplified by machine intelligence to solve the world’s hardest security challenges. Driven by deep customer obsession, we are committed to the mission, outcome, and to each other.

We bring these commitments to life through three core behaviors: ownership and collaboration, trust through outcomes and impact, and a challenge culture with ongoing feedback. Ready to make an impact at the company pioneering security transformation in the AI era? Join us at Zscaler.

Role

We are looking for an Incident Response Lead, CSIRT to join our team. This is a Remote role, reporting to the Global SOC Manager in the Enterprise Security department. As the lead escalation point for SOC analysts during your shift, you will serve as incident commander during major security events.

In this role, you will also drive our threat hunting program, leveraging open-source and commercial threat intelligence to proactively uncover threats and engineer high-fidelity detections.

What you’ll do (Role Expectations)

  • Serve as incident commander to lead and manage major security incidents through resolution
  • Drive proactive threat hunting initiatives using open-source and commercial intelligence to discover hidden threats
  • Develop, test, and deploy high-fidelity detection logic to enhance security monitoring
  • Act as the primary technical escalation point for SOC analysts during designated coverage shifts
  • Mentor team members and elevate overall SOC operational capabilities and incident response readiness

Who You Are (Success Profile)

  • You act like an owner by operating with high integrity, taking accountability for outcomes, and navigating seamlessly between strategic oversight and hands-on execution.
  • You are a dedicated problem-solver who is energized by complex security challenges and focused on delivering high-impact solutions.
  • You operate with urgency, maintaining a relentless focus on execution to deliver high-quality, high-impact results in a fast-paced environment.
  • You are data-driven, leveraging analytics and objective evidence to guide decisions, measure outcomes, and establish truth.
  • You think at scale, connecting day-to-day security operations with broader organizational goals to build sustainable processes built to support global growth.

What We’re Looking for (Minimum Qualifications)

  • Foundational understanding of AI/ML technologies and experience leveraging, securing, or positioning AI-driven solutions to optimize outcomes within your functional domain
  • Experience leading major incident response efforts within a large organization, preferably a SaaS provider
  • Experience collaborating across cross-functional departments to drive the resolution of complex security issues
  • Hands-on experience with SIEM, SOAR, and EDR tools, as well as authoring detection logic using YARA-L
  • Proven background translating technical security findings into clear executive summaries
  • Bachelor’s degree in Cybersecurity, Information Technology, or a related technical field

What Will Make You Stand Out (Preferred Qualifications)

  • Relevant industry certifications such as CISSP, OSCP, GCFA, or GNFA
  • 5+ years of dedicated incident response experience within a large enterprise organization
  • Master’s degree in Cybersecurity, Information Technology, or a related technical field

#LI-MM8

#LI-OFFICE

Zscaler’s salary ranges are benchmarked and determined by role and level. The range displayed on this job posting reflects the minimum and maximum target for new hire base salaries for this position across all Poland locations. Individual pay placement within this range is determined based on objective, gender-neutral criteria including job-related skills, relevant experience, and education or training.

The base salary range listed for this full-time position excludes commission/bonus/equity (if applicable) and benefits.

Base Pay Range

178 500 zł — 255 000 zł PLN

At Zscaler, we are committed to building a team that reflects the communities we serve and the customers we work with. We foster an inclusive environment that values all backgrounds and perspectives, emphasizing collaboration and belonging. Join us in our mission to make doing business seamless and secure.

Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including:

  • Various health plans
  • Time off plans for vacation and sick time
  • Parental leave options
  • Retirement options
  • Education reimbursement
  • In-office perks, and more!

Learn more about Zscaler's hybrid working model and benefits here .

By applying for this role, you adhere to applicable laws, regulations, and Zscaler policies, including those related to security and privacy standards and guidelines.

Zscaler is committed to providing equal employment opportunities to all individuals. We strive to create a workplace where employees are treated with respect and have the chance to succeed.

All qualified applicants will be considered for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status, or any other characteristic protected by federal, state, or local laws.

See more information by clicking on the Know Your Rights

Workplace Discrimination is Illegal link.

Pay Transparency

Zscaler complies with all applicable federal, state, and local pay transparency rules.

Zscaler is committed to providing reasonable support (called accommodations or adjustments) in our recruiting processes for candidates who are differently abled, have long term conditions, mental health conditions or sincerely held religious beliefs, or who are neurodivergent or require pregnancy-related support.

Interested in this role?Continue on Zscaler's careers page.
Apply on Zscaler