Security Researcher III

F5 F5 · Enterprise · Warsaw, Poland Homebase

Experienced Security Researcher to conduct threat hunting and penetration testing for internet-facing traffic management and security platforms. Role involves analyzing intrusions, developing detection logic, and mentoring junior analysts within the Office of the CISO.

What you'd actually do

  1. Conduct proactive, intelligence‑driven threat hunts across endpoint, network, SaaS, and cloud data to identify activity that evades traditional security controls.
  2. Develop and test hunt hypotheses based on MITRE ATT&CK, adversary TTPs, emerging and stale vulnerabilities .
  3. Perform deep technical analysis of intrusions, malware, and tools; reconstruct attack chains and identify root cause and detection gaps.
  4. Contribute to detection logic, advanced queries, and automation (e.g., Falcon queries, Netskope policies, SIEM/SOAR content) to operationalize hunt findings at scale.
  5. Produce high‑quality written and verbal reporting, clearly explaining complex intrusions and risks to both technical and executive stakeholders.

Skills

Required

  • Cybersecurity
  • Threat hunting
  • Penetration testing
  • Incident Response
  • Threat Intelligence
  • EDR/XDR platforms (CrowdStrike Falcon, Netskope)
  • Windows and Linux internals
  • Network protocols
  • Attacker tradecraft
  • SIEM/log platforms (Splunk, LogScale, Elastic, Sentinel)
  • MITRE ATT&CK framework
  • Scripting (Python, PowerShell, KQL, SQL)

Nice to have

  • Published security research
  • Conference talks
  • Public write-ups on threats, detections, or hunt methodologies
  • Investigating attacker activity in Azure, AWS, or major SaaS platforms
  • Relevant certifications (GCTI, GCIA, GCFA, GNFA, GREM, OSCP, CRTO)

What the JD emphasized

  • 5–8+ years of hands‑on experience in cybersecurity (Pentestng, IR, threat hunting, or threat intel), including direct ownership of complex investigations.
  • Strong proficiency with at least one EDR/XDR platform, preferably CrowdStrike Falcon (queries, detections, RTR, dashboards) and/or Netskope (DLP, CASB, SWG, inline policies).
  • Deep understanding of Windows and Linux internals, network protocols, and common attacker tradecraft (persistence, lateral movement, credential access, C2).
  • Experience building and running hunts using SIEM/log platforms (e.g., Splunk, LogScale, Elastic, Sentinel) and writing complex queries for anomaly detection.
  • Solid working knowledge of MITRE ATT&CK and its use in structuring hunts and mapping detections.
  • Strong scripting/query skills (e.g., Python, PowerShell, KQL, SQL or similar) to automate analysis and hunting workflows.