Zalando Bucharest is our newest site designed to consolidate and scale expert services, ensuring operational excellence as we evolve our global footprint.
Security Incidents have a high potential to cause a severe business impact on the organization. Therefore having a strong Cybersecurity Engineer on the 1st level is crucial for SOC as they form the first line of defence against cyber threats, often being the first to detect anomalies and potential attacks.
In this role, you will be working diligently on the 1st level to monitor, identify, investigate and respond to security threats. Your passion for cybersecurity, combined with your ability to collaborate with and communicate effectively, will be instrumental in the integrity of our digital assets.
INCLUSIVE BY DESIGNAt Zalando, our vision is to be the leading pan-European ecosystem for fashion and lifestyle e-commerce - one that is inclusive by design. We only assess candidates based on qualifications, merit, and business needs. We welcome applications from people of all gender identities, sexual orientations, personal expressions, racial identities, ethnicities, religious beliefs, and disability statuses. We only want to know why you’re great for this role, so please avoid including your picture, age, and marital status in your CV as well.
We want to provide you with a great candidate experience. Please feel free to inform us of any accommodations you may need, so we can best support and assist you throughout the hiring process.
do.BETTER - our diversity & inclusion strategy: https://jobs.zalando.com/en/our-culture/diversity-and-inclusion
WHAT WE’D LOVE YOU TO DO (AND LOVE DOING)Monitor & Respond to Threats: You’ll actively identify, investigate, and respond to security threats and system anomalies, acting as a core technical anchor within the SOC.
Support Incident Response Operations: In the event of major incidents, you’ll support our CSIRT’s response activities, collaborating with dedicated task forces through the entire Security Incident Lifecycle.
Manage Stakeholder Communications: You’ll handle interactions on incoming security tickets, serving as a reliable point of contact to keep technical and intermediate stakeholders clearly updated throughout the resolution process.
Document Investigations: You’ll maintain high operational standard records by documenting security cases in tickets and authoring forensic incident investigation reports.
Drive Security Optimization: When not responding to active threats, you’ll continuously improve our monitoring coverage, engage in proactive threat hunting, curate operational playbooks, and participate in advanced security education.
You Have Proven SOC Experience: You bring professional experience (ideally 1+ years) working in a SOC or a CSIRT environment, and you are fully comfortable handling structured on-call responsibilities outside of core business hours.
You Understand Detection & Analysis Tools: You possess a strong foundational knowledge of security monitoring, including practical, hands-on exposure to enterprise SIEM platforms and endpoint detection and response (EDR) tools.
You Know Cloud & Environment Security: You bring a practical understanding of protecting assets on AWS, working with Kubernetes deployments in AWS, and monitoring Google Workspace or similar corporate cloud environments.
You Leverage Frameworks & Scripting: You possess a clear operational understanding of the MITRE ATT&CK Framework and use scripting languages (such as Python, PowerShell, or Bash) to automate tasks and streamline security operations.
You Are a Reliable Communicator: You possess good verbal and written communication skills in English, with a track record of writing structured technical reports and routine handling stakeholder interactions.
As we build our new office in Bucharest, we are committed to providing a competitive benefits package tailored to local market practices. Please ask your Talent Acquisition Partner to learn more
about what we plan to offer at the start:
● 22 days of holiday a year, increasing up to 25 days depending on your tenure (every 3 years)
● Private medical coverage with options to add your family
● Daily meal allowance of 30 RON per working day
● Subsidy of public transport ticket
● Office-first working model (at least 3 days a week)
Skills Required
- Professional experience in a SOC or CSIRT environment (ideally 1+ years) and handling structured on-call responsibilities outside core business hours
- Hands-on exposure to enterprise SIEM platforms
- Hands-on exposure to Endpoint Detection and Response (EDR) tools
- Practical understanding of protecting assets on AWS
- Experience with Kubernetes deployments in AWS
- Experience monitoring Google Workspace or similar corporate cloud environments
- Operational understanding of the MITRE ATT&CK Framework
- Scripting skills in Python, PowerShell, or Bash to automate security operations
- Good verbal and written communication skills in English and experience writing technical/forensic investigation reports
Zalando Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Zalando and has not been reviewed or approved by Zalando.
-
Leave & Time Off Breadth — Paid time off includes a sizable annual allowance that can grow with tenure, plus additional paid days for volunteering. This breadth is highlighted as supportive of work–life balance.
-
Wellbeing & Lifestyle Benefits — Mental health support, round‑the‑clock counseling for employees and households, and broad fitness/wellness access are emphasized as robust. Substantial product discounts and partner offers add meaningful lifestyle value.
-
Parental & Family Support — Structured support around parental leave—such as buddy programs, re‑onboarding, and paid child sick days—helps ease family responsibilities. Flexible and part‑time leadership options further accommodate parents.
Zalando Insights
What We Do
Welcome to Zalando. Here’s some key info about us: Our position and vision: - We’re Europe’s leading online platform for fashion and lifestyle - Founded in Berlin in 2008, we bring head-to-toe fashion to more than 50 million active customers in 25 markets; offering clothes, footwear, accessories, and beauty - Our vision is to become The Starting Point For Fashion. Our offering: - Our assortment of international brands ranges from world-famous names to local labels - Our platform is a one-stop fashion destination for inspiration, innovation, and interaction - As Europe’s most fashionable tech company, we work hard to find digital solutions for every aspect of the fashion journey: for our customers, partners, and friends of our brand. - Our logistics network with 12 centrally located fulfillment centers allows us to efficiently serve our customers throughout Europe, supported by warehouses in Italy, France, Poland, and Sweden with a focus on local customer needs. Our beliefs: - Our ambition is to combine our passion for self-expression through fashion with our unwavering commitments to sustainability and D&I - We believe that our integration of fashion, operations, and online technology gives us the capability to deliver a compelling value proposition to both our customers and fashion brand partners.







