SOC L2 · Detection Engineering · Vuln Research

Jakub Kozub
read the source.

SOC L2 Analyst @ Jagiellonian University — Threat Hunting · DFIR · SIEM/XDR · Detection Engineering
OSS Vulnerability Research (HackerOne) · MSc IT (AI phishing detection) · EN↔PL Linguist

Cracow Metropolitan Area, Poland 4× CTF podium · 2× 1st MSc IT · AI phishing detection Resolved WordPress report + first bounties
L2
SOC Analyst
Threat Hunting · DFIR
CTF podium
incl. 2× 1st place
5
Blue-team
certifications
3
Languages
EN · ES · PL

01 / whoami

From the alert to the source code.

I'm a SOC L2 analyst who doesn't stop at the alert — I read the source. By day I work detection and threat hunting: triaging incidents, tuning and writing detections, and running down what the logs only hint at. Reading code to understand why something is actually exploitable is the habit that pulled me from defense into vulnerability research — and it's made me better at both.

Outside of work I hunt authorization flaws — missing and incorrect access control — in open-source software that a lot of people quietly rely on. My research focuses on WordPress, Elastic, GitLab and Matomo. I like this bug class because it's subtle: it almost never shows up in a scanner, and finding it means genuinely understanding the application's logic and trust boundaries.

Discipline matters to me — I reproduce every proof-of-concept in a lab before I file, and I'd rather send one clean, reproducible report than ten noisy ones. So far that approach has earned a resolved WordPress report and my first bounties through HackerOne's coordinated-disclosure programs — an early but real start that I'm actively building on.

“I'd rather send one clean, reproducible report than ten noisy ones.”// disclosure discipline

I think about every bug from the defender's side too: not just that it can be exploited, but how you'd detect and contain it in production. That's the perspective I bring to application security and detection engineering.

// profile

Role
SOC L2 Analyst
Org
Jagiellonian University
Based
Cracow, Poland
Focus
Detection engineering, threat hunting, DFIR
Research
Access-control flaws in WordPress, Elastic, GitLab, Matomo
Disclosure
HackerOne · lab-verified PoCs
Langs
EN · ES · PL

02 / capability matrix

What I work with

Blue-team operations and offensive research, plus the linguistics and engineering background that feed both.

A1 Threat Detection & Hunting

Cyber Threat Hunting (CTH) Detection Engineering SIEM tools XDR MITRE ATT&CK Network Traffic Analysis DNS / BGP monitoring

A2 Incident Response & DFIR

Incident Response DFIR / digital forensics SOAR Malware analysis Alert triage & validation

A3 Network & Perimeter Security

WAF NGFW IDS / IPS Load balancing

A4 Vulnerability Research

Authorization / access-control testing Lab-based PoC reproduction Coordinated disclosure (HackerOne) WordPress · Elastic · GitLab · Matomo

A5 Development & Tooling

Python Kotlin (Android) Swift (iOS) HTML / CSS / JS

A6 Linguistics

EN↔PL translation LQA Interpreting Terminology / glossary

03 / career log

Experience

A path from language and teaching into security — the code-reading habit that took me from defense into research runs through all of it.

PresentJun 2026 — Present· Cracow

SOC L2 Analyst

Jagiellonian University — Uniwersytet Jagielloński w Krakowie

Second-line SOC analyst defending the IT infrastructure of Poland's oldest university (est. 1364): detection engineering, threat hunting, forensic investigation.

  • Design and tune detection & alerting rules in the SIEM to improve coverage and cut false positives
  • Proactive threat hunting and DFIR investigations on escalated incidents
  • L2 investigation, validation and prioritization of alerts across endpoint, network and identity telemetry
  • Involved in the university-wide evaluation and selection of a UEM (Unified Endpoint Management) solution
SIEMDetection EngineeringThreat HuntingDFIRUEM
FreelanceMar 2022 — Present

EN→PL Translator & LQA Reviewer

Lionbridge — Mercedes-Benz · Signify · Enterprise Tech

Freelance EN→PL linguist for enterprise clients — translation, review/LQA, terminology; 24–48h SLA; TMS/LCX workflow.

  • Polish linguist on the Mercedes-Benz account (aftersales, dealer & technical comms); priority assignments + LQA arbitration
  • Reviewer for Signify (Philips Hue) — linguistic QA of AEM web content, terminology + glossary for the PL market
  • Glossary creation for technology clients (e.g. Echodyne, radar-tech)
Feb 2026 — May 2026· Warsaw

Junior Detection and Response Analyst

Nomios Poland

MSSP Detection & Response — multi-tenant SOC across on-prem and cloud, orchestrated via a SOAR platform.

  • Tier 1/2 monitoring and incident triage in SLA-driven workflows — correlating endpoint, SIEM, network and app-security telemetry
  • Investigated alerts across cloud, on-prem and remote-access (RDP, VPN); escalated validated threats into orchestrated IR
  • Coordinated cases across multiple ticketing systems for several client organizations in parallel
  • Produced complex incident reports and technical security documentation
SOARSIEMCloud + on-premIncident ResponseMulti-tenant SOC
Jul 2024 — Jan 2026· Warsaw· 1 yr 7 mo

Cybersecurity Analyst — SOC L1 → L2

Agro Aplikacje
Oct 2024 — Jan 2026

Cybersecurity Analyst | SOC L1/L2 (SIEM, XDR, WAF, Threat Detection)

Sole analyst on independent 12-hour SOC shifts (24/7, day and night).

  • Threat detection, investigation & IR across SIEM, XDR, WAF, NGFW and IPS/IDS — incl. malware analysis and mitigation
  • Continuous monitoring of network traffic, BGP, DNS and web-app performance/load balancing
  • Vulnerability reporting combining automated scanner findings with manual triage
  • Detailed incident reports for internal stakeholders and regulatory compliance
  • 4× CTF podium/final while in this role, including two 1st places
  • Performance bonus (Jun 2025) for exceeding expectations
Jul 2024 — Oct 2024

Cybersecurity Analyst | SOC L1 (SIEM, NGFW, WAF, IDS/IPS)

First role in a 24/7 SOC; fast onboarding under senior analysts.

  • Investigated/triaged events across SIEM, WAF, XDR, NGFW, IDS/IPS; malware analysis + IOCs; network/BGP/DNS monitoring; incident reports
  • 2nd place — XDR CTF (Trend Micro UK), three months into the role
SIEMXDRWAFNGFWIDS/IPSMalware analysis24/7 SOC
May 2021 — Sep 2023· Monterey, CA

Medical Interpreter

LanguageLine Solutions

Real-time consecutive EN↔PL interpretation for medical appointments, emergency calls, mental-health sessions and hospital procedures.

  • Interpreted complex medical terminology/diagnoses/treatment plans under HIPAA and a strict code of ethics (telemedicine, triage, mental-health, insurance)
  • Foundation of composure under pressure and disciplined handling of sensitive data that carries into SOC work
Dec 2015 — Feb 2021· Warsaw

Founder & English Teacher

Learn With Us Sp. z o.o. — Language School

Founded and ran a Warsaw-based language school.

  • Built the business from scratch: client acquisition, course design, pricing and day-to-day operations
  • Taught conversational English and Cambridge exam prep (FCE/CAE); delivered written/oral translations
  • Suspended operations due to the COVID-19 pandemic
Jan 2015 — Mar 2016· Warsaw

English Teacher

Mobile English
Oct 2013 — Nov 2014· Warsaw

Planning Assistant · Internship Trainee

KPMG
  • Planning Assistant — Feb 2014 — Nov 2014
  • Internship Trainee — Oct 2013 — Jan 2014

04 / scoreboard

CTF honors & awards

Four podium finishes and a national final across SIEM, threat-intel and XDR competitions — two of them first place.

1
ThreatOps CTF
SIEM / Threat Intelligence
1st Place
1
SIEM / Threat Intelligence Cloud CTF
Cloud detection & intel
1st Place
2
XDR CTF
Trend Micro UK
2nd Place
3
Trend Micro Vision One European CTF
European final
3rd Place
Splunk SIEM CTF
Warsaw
Finalist

05 / education

Education

MSc, Information Technology
Akademia Humanistyczno-Ekonomiczna w Łodzi
Oct 2024 — Jun 2026
Thesis on AI phishing detection.
Postgraduate, Cybersecurity
University of Warsaw — Uniwersytet Warszawski
Aug 2023 — Mar 2024
Postgraduate, Interdisciplinary Studies in Translation
University of Warsaw
2019 — 2020
Postgraduate, Business English
SWPS University — Uniwersytet SWPS
2015 — 2016
MA, English Philology
University of Warsaw
2013 — 2015

06 / certifications

Certifications

eC
eCTHP — Certified Threat Hunting Professional
INE
CD
CDSA — Certified Defensive Security Analyst
Hack The Box
BT
BTL1 — Blue Team Level 1
Security Blue Team
CS
CSCSO
Security certification
PP
Certified Phishing Prevention Specialist
Phishing defense

07 / projects & open source

What I build & break

Focused tooling for access-control research, coordinated disclosure work, and a shipped mobile app.

Security tooling OSS

Small, focused open-source tools for access-control / authorization research and evidence hygiene, published on GitHub.

OSS vulnerability research HackerOne

Coordinated-disclosure research into authorization flaws — focus on WordPress, Elastic, GitLab and Matomo. A resolved WordPress report and first bounties.

MATURA Android · iOS

An offline vocabulary game app for the Polish "matura" English exam — built for Android (Kotlin) and iOS (Swift).

jakubkozub.com Web

This site — a hand-built personal CV: no framework, self-contained, responsive, theme-aware and print-ready.

08 / languages

Languages

English
Full Professional
Spanish
Professional Working
Polish
Native / Bilingual

09 / establish connection

Let's talk detection & disclosure.

Open to conversations about detection engineering, DFIR, application security and coordinated vulnerability disclosure.

kuba1k@gmail.com