Cyber Detection & Response Engineering Lead Expert

Ernst & Young Advisory Services Sdn Bhd

Katowice

Hybrid

PLN 320,000 - 520,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Continuous learning
Career development
Global opportunities
Diversity and inclusion

Job summary

EY GDS Poland invites a Cyber Detection & Response Engineering Lead Expert to shape and deliver security monitoring, detection, and response capabilities across diverse technologies and environments.

The role blends consulting, delivery, and people-management responsibilities, leading complex CDR engagements and shaping security solutions for clients. Strong leadership and English proficiency are essential.

Qualifications

  • Strong cybersecurity expertise across detection & response, security operations, incident response, or related consulting services.
  • Hands-on experience across multiple CDR areas: SIEM, detection engineering, security automation, incident response, governance, operating model design.
  • Experience leading cybersecurity projects, workstreams, or multidisciplinary delivery teams.
  • Ability to design CDR solutions addressing business requirements.
  • Understanding of applying AI within CDR, its opportunities, limits, validation needs, and human oversight.
  • Knowledge of detection use-case development, security data management, incident response, and security operations processes.
  • Experience contributing to proposals, RFP responses, solutioning, effort estimation, or business development.
  • Strong communication, leadership, and problem-solving skills.
  • Professional proficiency in English.

Responsibilities

  • Design practical solutions across security monitoring, detection engineering, incident response, automation, and security operations.
  • Apply AI-enabled capabilities to improve detection, investigation, response, automation, and security operations with validation.
  • Lead SIEM, SOAR, EDR, XDR, log management, integration, migration, and detection content activities.
  • Translate client requirements and risks into clear solution designs, delivery plans, and roadmaps.
  • Facilitate workshops and communicate recommendations to technical teams and stakeholders.
  • Lead, coach, and review consultants, supporting their development.
  • Contribute to proposals, RFP responses, solution development, and client discussions.
  • Develop reusable CDR methods, accelerators, service offerings, and delivery assets.

Skills

Cybersecurity
Leadership
Consulting
AI in security
Cloud security

Tools

SIEM
SOAR
EDR
XDR
Log management

Job description

Cyber Detection & Response Engineering Lead Expert

Other locations: Primary Location Only

Date: 26 Aug 2026

Cyber Detection & Response Engineering Lead Expert

Location: Katowice - 2 days office / 3 days remote

Let us introduce you the job offer by EY GDS Poland - a member of the global integrated service delivery center network by EY.

We are delighted to invite you to join the Cybersecurity Detection & Response (CDR) team within the GDS PL Consulting division. This role focuses on leading the design, delivery, and improvement of security monitoring, detection, investigation, and response capabilities across different technologies and operating environments.
You will work in a dynamic consulting environment on assignments that may include CDR solution design, security operations transformation, SIEM and SOAR implementation, detection engineering, incident response improvement, operating models, governance, automation, and AI-enabled security capabilities.

The opportunity

As a Cybersecurity Manager, you will lead complex CDR engagements and workstreams, combining technical knowledge with consulting, delivery, and limited people-management responsibilities. Depending on client needs, you may shape a security solution, lead an implementation, assess an existing SOC or CSIRT capability, define a target operating model, or guide the improvement of detection and response processes.
We are looking for professionals with strong experience across multiple CDR domains who can adapt to different technologies, client environments, and delivery challenges. You will provide direction to delivery teams, engage senior stakeholders, contribute to proposals and solutioning, and support the continued development of the CDR practice.

Your key responsibilities
  • Design practical solutions across security monitoring, detection engineering, incident response, automation, and security operations.
  • Apply AI-enabled capabilities to improve detection, investigation, response, automation, and security operations, with appropriate validation and human oversight.
  • Guide SIEM, SOAR, EDR, XDR, log management, integration, migration, and detection content activities.
  • Translate client requirements, risks, and operational challenges into clear solution designs, delivery plans, and improvement roadmaps.
  • Facilitate workshops and communicate recommendations to technical teams, business stakeholders.
  • Lead, coach, and review the work of consultants while supporting their professional and technical development.
  • Contribute to proposals, RFP responses, solution development, effort estimation, presentations, and client discussions.
  • Develop reusable CDR methods, accelerators, service offerings, and delivery assets.
Skills and attributes for success

Success in this role requires a combination of strong cybersecurity expertise, leadership, and consulting capabilities. The ideal candidate is a proactive and adaptable professional who can effectively engage stakeholders at all levels, translate complex technical topics into business value, and lead teams through challenging delivery engagements. A growth mindset, strong communication skills, and a passion for innovation, including the responsible use of AI in cybersecurity operations, will be key to succeeding in this position.

To qualify for the role, you must have
  • Strong professional experience in cybersecurity detection and response, security operations, incident response, or related consulting services
  • Demonstrable hands‑on experience across multiple CDR areas, such as SIEM, detection engineering security automation, incident response, transformation, governance, or operating model design
  • Experience leading cybersecurity projects, workstreams, or multidisciplinary delivery teams
  • Ability to design CDR solutions that address business requirements
  • Understanding of how AI can be applied within CDR, including its opportunities, limitations, security risks, validation requirements, and need for human oversight
  • Strong understanding of detection use‑case development, security data management, incident response, and security operations processes
  • Experience contributing to proposals, RFP responses, solutioning, effort estimation, or business development activities
  • Strong communication, presentation, leadership, and problem‑solving skills
  • Professional proficiency in English.
Ideally, you'll also have
  • Experience with SOAR, security workflow automation, or security tool integrations
  • Working knowledge of query and scripting languages
  • Experience using AI-enabled capabilities within SIEM, SOAR, EDR, XDR, or related cybersecurity platforms
  • Familiarity with MITRE ATT&CK, NIST CSF, and established incident response methodologies
  • Experience with cloud security monitoring across Microsoft Azure, AWS, or Google Cloud
  • Relevant cybersecurity or technology certifications
  • Consulting background
What we look for

We are looking for an experienced cybersecurity professional who combines strong technical expertise in Cyber Detection & Response with leadership and consulting capabilities. The ideal candidate is comfortable leading complex engagements, working with diverse stakeholders, and driving meaningful security improvements in challenging environments. They demonstrate a collaborative mindset, commercial awareness, and a passion for developing people while delivering high-quality client outcomes. We value individuals who are curious, adaptable, and eager to embrace innovation, including the responsible adoption of AI-enabled security capabilities.

What we offer

EY Global Delivery Services (GDS) is a dynamic and truly global delivery network. We work across nine locations - Argentina, Hungary, India, the Philippines, Poland, Sri Lanka, Mexico, Spain and the United Kingdom - and with teams from all EY service lines, geographies and sectors, playing a vital role in the delivery of the EY growth strategy. From accountants to coders to advisory consultants, we offer a wide variety of fulfilling career opportunities that span all business disciplines. In GDS, you will collaborate with EY teams on exciting projects and work with well‑known brands from across the globe. We'll introduce you to an ever‑expanding ecosystem of people, learning, skills and insights that will stay with you throughout your career.

  • Continuous learning: You'll develop the mindset and skills to navigate whatever comes next.
  • Success as defined by you: We'll provide the tools and flexibility, so you can make a meaningful impact, your way.
  • Transformative leadership: We'll give you the insights, coaching and confidence to be the leader the world needs.
  • Diverse and inclusive culture: You'll be embraced for who you are and empowered to use your voice to help others find theirs.
About EY
EY | Building a better working world

EY exists to build a better working world, helping to create long‑term value for clients, people and society and build trust in the capital markets.

Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.

Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.

We'll introduce you to an ever‑expanding ecosystem of people, learning, skills and insights that will stay with you throughout your career.

In compliance with the requirements of the Whistleblower Protection Act, our company has established the Procedure for reporting breaches of law and undertaking appropriate follow-up actions. Any misconduct should be reported through the EY Ethics Hotline.

Select how often (in days) to receive an alert:

EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Manager - Cyber Detection & Response
Cybersecurity Manager - Cyber Detection & Response

EY • Katowice

On-site
PLN 180,000 - 240,000
Senior Cybersecurity Risk & Compliance Consultant
Senior Cybersecurity Risk & Compliance Consultant

Ernst & Young Advisory Services Sdn Bhd • Katowice

Hybrid
PLN 180,000 - 240,000
CBS Security Consultant - SDLC
CBS Security Consultant - SDLC

Ernst & Young Advisory Services Sdn Bhd • Wrocław

Hybrid
PLN 180,000 - 280,000
Security Awareness Specialist (Training & Content Development)
Security Awareness Specialist (Training & Content Development)

Ernst & Young Advisory Services Sdn Bhd • Wrocław

On-site
PLN 90,000 - 130,000
Vulnerability & Application Security Engineer
Vulnerability & Application Security Engineer

Ernst & Young Advisory Services Sdn Bhd • Wrocław

On-site
PLN 150,000 - 210,000
Senior Cloud Security Consultant
Senior Cloud Security Consultant

Ernst & Young Advisory Services Sdn Bhd • Wrocław

Hybrid
PLN 180,000 - 280,000
Senior DevOps Engineer
Senior DevOps Engineer

Ernst & Young Advisory Services Sdn Bhd • Katowice

On-site
PLN 120,000 - 160,000
Continuous learning opportunities
Diverse and inclusive culture
Transformative leadership development
IT Risk Consultant with European languages
IT Risk Consultant with European languages

Ernst & Young Advisory Services Sdn Bhd • Katowice

Hybrid
PLN 180,000 - 240,000
Cyber & Investigative Services - Insider Threat Detection Senior Analyst
Cyber & Investigative Services - Insider Threat Detection Senior Analyst

Ernst & Young Advisory Services Sdn Bhd • Katowice

On-site
PLN 180,000 - 240,000
Data Protection Manager
Data Protection Manager

Ernst & Young Advisory Services Sdn Bhd • Katowice

On-site
PLN 260,000 - 470,000