Cyber Security Services Incident Response Engineer

Stefanini EMEA

Poland

On-site

PLN 180,000 - 240,000

Full time

6 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Stefanini Group in Poland is seeking a skilled Incident Response Engineer to join our Security Operations Center (SOC) delivering MSSP services. You will manage security incidents, develop response playbooks, and tailor configurations to client needs.

The role requires 5+ years in cybersecurity operations, experience in SOC/24/7 environments, and strong knowledge of SIEM/EDR, SentinelOne SDL, and Microsoft Entra ID.

Qualifications

  • Minimum 5 years in cybersecurity operations and incident response.
  • Experience in SOC/MSSP environments with 24/7 operations.
  • Excellent written and spoken English.

Responsibilities

  • Own assigned security alerts and incidents, providing advisory feedback.
  • Lead investigation and response across endpoints, identity, network, cloud.
  • Analyze indicators of compromise and adversary behaviors.
  • Investigate identity sign-in activity and telemetry patterns.
  • Use SDL and PowerQuery for advanced searches and threat analysis.
  • Document actions, evidence, decisions, and recovery activities.

Skills

Incident response
SIEM/EDR/NDR
Threat hunting
Communication
Playbooks & documentation
Automation concepts
Team collaboration
Decision making under crisis

Education

Bachelor's degree in CS/IT/Engineering or related field
High school + Baccalaureate diploma

Tools

SentinelOne SDL
PowerQuery
Microsoft Entra ID

Job description

Stefanini Group is seeking a skilled Cyber Security Services (CSS) Incident Response (IR) Engineer to join our Security Operations Center (SOC), which operates as a Managed Security Service Provider (MSSP).

As a CSS IR Engineer, you will manage security incidents, develop incident response processes, and enhance security configurations tailored to client needs. Your expertise will be crucial in reducing false positives and identifying security gaps within the client's IT infrastructure.

Work Schedule: Two rotating 8-hour shifts within the 7:00 a.m.-7:00 p.m. CET coverage window.

Job responsibilities:
  • Own assigned security alerts, incidents, and escalated security tickets by providing advisory feedback and mitigating encountered technical issues.
  • Lead the investigation and response to security incidents across endpoint, identity, email, network, cloud, and other available telemetry source.
  • Analyze endpoint activity to identify indicators of compromise and adversary behaviors, including malicious execution, persistence, privilege escalation, and lateral movement.
  • Investigate suspicious user and identity activity by analyzing Microsoft Entra ID authentication logs, sign-in activity, access patterns, anomalies, and other identity‑related telemetry.
  • Use SentinelOne Singularity Data Lake (SDL) and SDL PowerQuery to perform advanced searches, correlate events, analyze threats, and support security investigations.
  • Document investigative actions, evidence, analysis, decisions, communications, containment measures, and recovery activities throughout the incident lifecycle.
  • Prepare detailed P1 and P2 incident reports covering the incident timeline, root cause, impact assessment, actions taken, current status, and lessons learned.
  • Provide feedback to client security team on detection logic, alert quality, false positives, telemetry gaps, and monitoring improvement, recommending rule‑tuning adjustments and new detection use cases based on emerging threats, vulnerabilities, observed activity, and attack patterns.
  • Produce weekly operational reports on alert volumes and status, operational trends, investigation outcomes, false‑positive rates by detection source.
  • Execute containment, eradication, and recovery activities in accordance with approved procedures and incident response playbooks.
  • Conduct forensic analysis and develop investigation hypotheses using structured incident response and threat hunting methodologies.
  • Support threat hunting and proactive detection initiatives based on emerging tactics, techniques, and procedures (TTPs).
  • Participate in security operations meetings and present incident findings, operational trends, detection performance, service‑level results, and improvement recommendations.
  • Identify and track security gaps, recommend mitigation measures, and support SOAR automation workflows by providing operational feedback and identifying suitable automation opportunities to enhance operational efficiency.
  • Contribute to the development, maintenance, and refinement of standard operating procedures, incident response playbooks, investigation guides, workflows, and process documentation.
  • Support monthly security tool and log‑source health checks and provide mean time to resolution (MTTR) metrics by incident severity and lifecycle stage.
  • Collaborate with security analysts, incident responders, threat hunters, technology owners, and stakeholders across multiple teams and time zones to implement security best practices.
  • Provide technical guidance, coaching, and mentoring to junior analysts, fostering a collaborative and learning‑focused environment.
Job Requirements:

Education:

  • Preferred: Bachelor's degree in computer science, Information Technology, Engineering, or a related field.
  • Minimum education requirement: High school studies completed with Baccalaureate diploma.
  • Excellent English communication skills, both verbal and written, for professional communication and documentation.

Experience:

  • Minimum 5 years of experience in cybersecurity operations, including hands‑on experience investigating and responding to security incidents across endpoints, network, cloud, and other technology environments.
  • Demonstrated experience working in a Security Operations Center, Global Security Operations Center, Managed Security Service, or similar 24/7 operational environment.
Mandatory Technical Skills:
  • Strong understanding of cybersecurity principles, incident response methodologies, structured threat hunting and basic digital forensics.
  • Strong knowledge of industry frameworks and best practices, including NIST incident response guidance and structured threat hunting methodologies.
  • Hands‑on proficiency with SentinelOne Singularity Data Lake (SDL), including PowerQuery for investigation, event correlation, and threat analysis.
  • Proficiency with Microsoft Entra ID and security technologies such as SIEM, SEG, EDR, XDR, and NDR.
  • Familiarity with SOAR platforms and security automation concepts.
  • Ability to develop and maintain standard operating procedures, incident response playbooks, workflows, and technical documentation.
Preferred / Nice‑to‑Have Qualifications:
  • Hands‑on certifications in incident response, forensics, threat hunting, or malware analysis - for example GCIH, GCFA, GCDA, GREM, ECIH, CySA+, eCTHP, CDSA, or OSCP. Equivalent practical evidence (published research, open‑source detection contributions) is weighted equally.
Professional Skills:
  • Ability to perform effectively during crises, make sound decisions, recommend effective solutions, and manage competing priorities during security incidents.
  • Ability to work effectively in a complex global environment involving multiple entities, varying levels of IT maturity, and diverse regulatory requirements.
  • Strong communication and collaboration skills, enabling effective interaction with a diverse range of technical and non‑technical stakeholders and internal teams.
  • A customer‑focused mindset dedicated to delivering exceptional service.
  • A collaborative mindset with an interest in internal operations and process improvement.
  • Strong organizational, attention to detail, analytical thinking and a proactive approach to problem‑solving.
  • Ability to quickly adapt to changes, new requirements, or sudden shifts in direction.
  • A commitment to continuous learning and improvement, staying abreast of industry best practices, emerging technologies, and methodologies.
  • Absolute discretion and integrity in handling sensitive customer information and critical infrastructure data.

The preceding job description had been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties and responsibilities required of employees assigned to this job.

Diversity & Inclusion

Here at the Stefanini Group, we value plurality and equity, regardless of race, sexual orientation, disability, age, ancestry, religion, gender, and nationality. We understand and encourage the importance of being you!

About Us

We are the Stefanini group, a global tech consulting company of Brazilian origin that believes in the power of people to transform businesses through technology.

We are present in over 40 countries and operate with the purpose of co‑creating solutions TOGETHER WITH OUR CLIENTS that accelerate results and improve the experience of people and organizations.

Here, we like to say that technology is not the end, but the means: what really matters are the people who drive it all.

Our mindset is AI First, meaning we invest in cutting‑edge technology in everything we do, focusing on results for our clients.

We are a company, A GROUP, that breathes collaboration and offers a dynamic environment where you will learn by doing, grow alongside the team, and have space to contribute with ideas and projects.

More than just talking about digital transformation, we believe in real transformation that starts with people and impacts real businesses.

If you are looking for a place to develop, innovate, and be part of something bigger, the Stefanini Group is your place.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

CSS Vulnerability Analyst
CSS Vulnerability Analyst

Stefanini EMEA • Kraków

On-site
PLN 180,000 - 240,000
Support Engineer with German
Support Engineer with German

Stefanini EMEA • Poland

On-site
PLN 90,000 - 120,000
Private medical subscription
Soft skills and technical training
Flexible benefits budget
+3
Junior Support Engineer with English and Polish
Junior Support Engineer with English and Polish

Stefanini EMEA • Kraków

On-site
PLN 40,000 - 60,000
Private medical subscription
Soft skills and technical training
Monthly flexible benefits budget
+1
IT Operations Analyst
IT Operations Analyst

Stefanini EMEA • Kraków

On-site
PLN 90,000 - 130,000
Private medical subscription
Soft skills and technical training
Flexible benefits budget (Multisport,,
+2
IT Operations Analyst
IT Operations Analyst

Stefanini, Inc • Poland

Hybrid
PLN 120,000 - 180,000
Private medical subscription
Soft skills training
Flexible benefits budget
+2
Solution Lead Applications
Solution Lead Applications

Stefanini EMEA • Kraków

On-site
PLN 180,000 - 260,000
Support Engineer with English
Support Engineer with English

Stefanini, Inc • Poland

Hybrid
PLN 60,000 - 90,000
Private medical subscription
Soft skills and technical training
Flexible benefits budget
+1
Incident Response Engineer — SOC Cyber Security
Incident Response Engineer — SOC Cyber Security

Stefanini EMEA • Poland

On-site
PLN 180,000 - 240,000
Jr. IT Operations Specialist (FSS)
Jr. IT Operations Specialist (FSS)

Stefanini, Inc • Poland

Remote
PLN 90,000 - 130,000
Network Technical Architect
Network Technical Architect

Stefanini EMEA • Poland

On-site
PLN 240,000 - 360,000