SOC L2 · Detection Engineering · Vuln Research
Jakub Kozub
read the source.
SOC L2 Analyst @ Jagiellonian University — Threat Hunting · DFIR · SIEM/XDR · Detection Engineering
OSS Vulnerability Research (HackerOne) · MSc IT (AI phishing detection) · EN↔PL Linguist
Threat Hunting · DFIR
incl. 2× 1st place
certifications
EN · ES · PL
01 / whoami
From the alert to the source code.
I'm a SOC L2 analyst who doesn't stop at the alert — I read the source. By day I work detection and threat hunting: triaging incidents, tuning and writing detections, and running down what the logs only hint at. Reading code to understand why something is actually exploitable is the habit that pulled me from defense into vulnerability research — and it's made me better at both.
Outside of work I hunt authorization flaws — missing and incorrect access control — in open-source software that a lot of people quietly rely on. My research focuses on WordPress, Elastic, GitLab and Matomo. I like this bug class because it's subtle: it almost never shows up in a scanner, and finding it means genuinely understanding the application's logic and trust boundaries.
Discipline matters to me — I reproduce every proof-of-concept in a lab before I file, and I'd rather send one clean, reproducible report than ten noisy ones. So far that approach has earned a resolved WordPress report and my first bounties through HackerOne's coordinated-disclosure programs — an early but real start that I'm actively building on.
“I'd rather send one clean, reproducible report than ten noisy ones.”// disclosure discipline
I think about every bug from the defender's side too: not just that it can be exploited, but how you'd detect and contain it in production. That's the perspective I bring to application security and detection engineering.
// profile
- Role
- SOC L2 Analyst
- Org
- Jagiellonian University
- Based
- Cracow, Poland
- Focus
- Detection engineering, threat hunting, DFIR
- Research
- Access-control flaws in WordPress, Elastic, GitLab, Matomo
- Disclosure
- HackerOne · lab-verified PoCs
- Langs
- EN · ES · PL
02 / capability matrix
What I work with
Blue-team operations and offensive research, plus the linguistics and engineering background that feed both.
A1 Threat Detection & Hunting
A2 Incident Response & DFIR
A3 Network & Perimeter Security
A4 Vulnerability Research
A6 Linguistics
03 / career log
Experience
A path from language and teaching into security — the code-reading habit that took me from defense into research runs through all of it.
SOC L2 Analyst
Second-line SOC analyst defending the IT infrastructure of Poland's oldest university (est. 1364): detection engineering, threat hunting, forensic investigation.
- Design and tune detection & alerting rules in the SIEM to improve coverage and cut false positives
- Proactive threat hunting and DFIR investigations on escalated incidents
- L2 investigation, validation and prioritization of alerts across endpoint, network and identity telemetry
- Involved in the university-wide evaluation and selection of a UEM (Unified Endpoint Management) solution
EN→PL Translator & LQA Reviewer
Freelance EN→PL linguist for enterprise clients — translation, review/LQA, terminology; 24–48h SLA; TMS/LCX workflow.
- Polish linguist on the Mercedes-Benz account (aftersales, dealer & technical comms); priority assignments + LQA arbitration
- Reviewer for Signify (Philips Hue) — linguistic QA of AEM web content, terminology + glossary for the PL market
- Glossary creation for technology clients (e.g. Echodyne, radar-tech)
Junior Detection and Response Analyst
MSSP Detection & Response — multi-tenant SOC across on-prem and cloud, orchestrated via a SOAR platform.
- Tier 1/2 monitoring and incident triage in SLA-driven workflows — correlating endpoint, SIEM, network and app-security telemetry
- Investigated alerts across cloud, on-prem and remote-access (RDP, VPN); escalated validated threats into orchestrated IR
- Coordinated cases across multiple ticketing systems for several client organizations in parallel
- Produced complex incident reports and technical security documentation
Cybersecurity Analyst — SOC L1 → L2
Cybersecurity Analyst | SOC L1/L2 (SIEM, XDR, WAF, Threat Detection)
Sole analyst on independent 12-hour SOC shifts (24/7, day and night).
- Threat detection, investigation & IR across SIEM, XDR, WAF, NGFW and IPS/IDS — incl. malware analysis and mitigation
- Continuous monitoring of network traffic, BGP, DNS and web-app performance/load balancing
- Vulnerability reporting combining automated scanner findings with manual triage
- Detailed incident reports for internal stakeholders and regulatory compliance
- 4× CTF podium/final while in this role, including two 1st places
- Performance bonus (Jun 2025) for exceeding expectations
Cybersecurity Analyst | SOC L1 (SIEM, NGFW, WAF, IDS/IPS)
First role in a 24/7 SOC; fast onboarding under senior analysts.
- Investigated/triaged events across SIEM, WAF, XDR, NGFW, IDS/IPS; malware analysis + IOCs; network/BGP/DNS monitoring; incident reports
- 2nd place — XDR CTF (Trend Micro UK), three months into the role
Medical Interpreter
Real-time consecutive EN↔PL interpretation for medical appointments, emergency calls, mental-health sessions and hospital procedures.
- Interpreted complex medical terminology/diagnoses/treatment plans under HIPAA and a strict code of ethics (telemedicine, triage, mental-health, insurance)
- Foundation of composure under pressure and disciplined handling of sensitive data that carries into SOC work
Founder & English Teacher
Founded and ran a Warsaw-based language school.
- Built the business from scratch: client acquisition, course design, pricing and day-to-day operations
- Taught conversational English and Cambridge exam prep (FCE/CAE); delivered written/oral translations
- Suspended operations due to the COVID-19 pandemic
English Teacher
Planning Assistant · Internship Trainee
- Planning Assistant — Feb 2014 — Nov 2014
- Internship Trainee — Oct 2013 — Jan 2014
04 / scoreboard
CTF honors & awards
Four podium finishes and a national final across SIEM, threat-intel and XDR competitions — two of them first place.
05 / education
Education
06 / certifications
Certifications
07 / projects & open source
What I build & break
Focused tooling for access-control research, coordinated disclosure work, and a shipped mobile app.
Security tooling OSS
Small, focused open-source tools for access-control / authorization research and evidence hygiene, published on GitHub.
OSS vulnerability research HackerOne
Coordinated-disclosure research into authorization flaws — focus on WordPress, Elastic, GitLab and Matomo. A resolved WordPress report and first bounties.
MATURA Android · iOS
An offline vocabulary game app for the Polish "matura" English exam — built for Android (Kotlin) and iOS (Swift).
jakubkozub.com Web
This site — a hand-built personal CV: no framework, self-contained, responsive, theme-aware and print-ready.
08 / languages
Languages
09 / establish connection
Let's talk detection & disclosure.
Open to conversations about detection engineering, DFIR, application security and coordinated vulnerability disclosure.
kuba1k@gmail.com