Lead Security Operations Engineer

Talanto

Wrocław

Hybrid

PLN 279,000 - 318,000

Full time

1 hour ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Private medical care
Multisport Card
Flexible remote work options
Recharge Holidays

Job summary

Talanto is seeking a Lead Security Operations Engineer in a hybrid role based out of Wroclaw, Poland. You will own complex incidents end-to-end, drive detection engineering across SIEM/EDR/SOAR, and partner with DevOps and Engineering to embed security in pipelines and infrastructure.

The ideal candidate has 6+ years in security operations, strong incident leadership, and experience with cloud platforms (AWS/Azure/GCP).

Qualifications

  • 6+ years of experience in security operations with triage, incident response, and detection engineering.
  • Proven experience leading or mentoring a team, including technical guidance and coaching.
  • Deep expertise with SIEM, EDR, and SOAR platforms, including hands-on rule-writing, tuning, and automation.

Responsibilities

  • Own complex or high-severity incidents end-to-end from triage to containment, remediation, and post-incident review.
  • Have cloud security expertise across AWS, Azure, or GCP and integrate detection/response into cloud-native infra.
  • Lead incident response for significant security events and produce clear reports for technical and non-technical stakeholders.
  • Embed security controls into infrastructure, CI/CD pipelines, and system design with DevOps and Engineering.
  • Mentor analysts and engineers to raise overall technical depth and independence.
  • Translate complex findings into actionable insights for executives, customers, and stakeholders during incidents.

Skills

Incident response leadership
SIEM
EDR
SOAR
Cloud security architecture
Scripting (Python/PowerShell)
MITRE ATT&CK
Communication

Tools

Docker
Kubernetes

Job description

25,000 – 28,500 PLN

Important: if an employer asks you to log into their system via iCloud or Google, send a code, an SMS or Telegram password, run some code, or install software — refuse. These are signs of fraud.

We’re building the AI-driven future of customer success, from retention to growth!

We’re building the AI-driven future of customer success, from retention to growth! ••••••••• is the AI-powered retention engine behind the world’s most customer-centric companies. The ••••••••• CustomerOS platform orchestrates the customer journey from onboarding to outcomes to advocacy. More than 2,000 companies trust ••••••••• ’s applications and AI agents to drive learning, adoption, community connection, and success for their customers. To explore how our suite of solutions is shaping the future of customer success, check out thelink .

About This Role:

We’re looking for a full-time Lead Security Operations Engineer to join our Security team reporting to the Senior Manager, AI Response and Threat. This role is a hybrid role based out of Wroclaw, Poland location.

In this role, you'll play a key role in maturing our security operations program by owning detection strategy, leading response to major incidents, and mentoring the analysts and engineers on the team. This is a great opportunity for someone who thrives in a fast-growing, cloud-first environment and enjoys working cross-functionally with teams like DevOps, Engineering, and IT. The ideal candidate brings strong skills in incident response leadership, detection engineering across SIEM, EDR, and SOAR platforms, and cloud security architecture.

What You'll Do:

Experienced in owning complex or high-severity incidents end-to-end, from initial triage through containment, remediation, and post-incident review, while keeping stakeholders informed throughout

Deep familiarity with security considerations across AWS, Azure, or GCP environments, including how detection and response strategies need to adapt to cloud-native infrastructure

Lead incident response for significant security events: scoping and containment through to post-incident review. You will conduct host, network, and memory forensics yourself and produce clear, accurate reporting for both technical and non-technical stakeholders.

Comfortable working closely with DevOps and Engineering teams to embed security controls directly into infrastructure, CI/CD pipelines, and system design, rather than layering security on after the fact

Invested in developing the skills and judgment of analysts and engineers on the team, helping the broader group operate with greater independence and technical depth over time

Able to translate complex technical findings into clear, actionable insight for executive leadership, customers, or other non-technical stakeholders, especially under the pressure of an active incident

Experienced in assessing, selecting, and integrating security tools (SIEM, EDR, SOAR, cloud-native platforms) in a way that improves coverage without adding unnecessary complexity or cost

This role may require occasional travel (up to 10-20%) for team meetings, training, or company events. This is not a complete list of responsibilities, and the scope of the role may evolve with the needs of the team and business.

What We're Looking For:

6+ years of experience in security operations, with progressive responsibility across triage, incident response, and detection engineering

Proven experience leading or mentoring a team, formally or informally, including technical guidance and coaching

Deep expertise with SIEM, EDR, and SOAR platforms, including hands-on rule-writing, tuning, and automation development

Strong incident response leadership experience, including managing complex or high-severity incidents end-to-end

Solid understanding of cloud security architecture (AWS, Azure, or GCP), and experience working with DevOps and Engineering to embed security into CI/CD pipelines and infrastructure

Scripting or automation proficiency (Python, PowerShell, or similar) to build and scale response workflows

Deep familiarity with attacker tactics and techniques (MITRE ATT&CK) and how to translate them into detection logic

Excellent communication skills, with the ability to brief executives and technical teams alike during incidents and planning discussions

Nice-to-have skills or experience:

Hands-on experience with cloud-native detection and posture tools (e.g., AWS GuardDuty, Azure Sentinel, Wiz, Prisma Cloud)

Familiarity with container and orchestration security (Docker, Kubernetes) and associated attack surfaces

Experience with threat intelligence platforms and proactive threat hunting using frameworks like MITRE ATT&CK or Sigma rules

Exposure to purple team or adversary simulation exercises (e.g., Atomic Red Team, Caldera) to validate detection coverage

Working knowledge of network security architecture, including segmentation, zero trust principles, and cloud network security groups

Experience with vulnerability management programs, including scanning, prioritization, and remediation tracking

Experience working with data loss prevention (DLP) tools and insider threat detection

Why You’ll Love It Here:

••••••••• is a place where innovation is shaped through collaboration, curiosity, and a shared focus on solving real-world problems. With a growing suite of products across customer success, product experience, community, education, and AI-powered relationship intelligence, we continue to evolve with the needs of our customers. When people with diverse strengths, a strong sense of community, and true passion for our mission come together, they drive greater impact and create lasting value. What underpins it all is a culture that offers the stability, trust, and support that people need - not just to do the job, but to show up as themselves and feel connected to the work they do. Gainsters love working here for several reasons. Here are a few:

Our Compensation and Benefits:At ••••••••• , we believe great work happens when teammates feel fully supported.

The starting base salary range for this role is PLN 25,000 - 28,500 monthly. Actual compensation may vary based on factors such as skills, experience, and location. In addition to base pay, this role is eligible for an annual bonus and participation in ••••••••• ’s equity program.

We offer a comprehensive benefits package including premium private medical care with priority appointments, Multisport Cards to support your physical well-being, and flexible remote work options. Partners can be included in both health and wellness programs. You'll also enjoy dedicated Recharge Holidays - one long weekend each quarter to relax and reset.

Our Core Values:We are guided by our values and our mission to be living proof you can win in business while being Human-First. Learn morehere .

Our Growth Opportunities:From mentoring to career development opportunities, we’re passionate about helping our teammates learn, grow, and thrive.

Our Parody Videos:No explanation needed. Just watch themhere!

Additional Information:

We’re committed to creating an inclusive, fair, and transparent hiring process. As an equal opportunity employer, we celebrate diversity and are committed to creating a welcoming experience for all candidates.

If you’re applying for a role through an Employer of Record (EOR) or contractor arrangement, please note that employment terms and benefits are managed by the EOR or may not apply to non-EOR contractors.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Security Operations Engineer
Lead Security Operations Engineer

Gainsight • Wrocław

On-site
PLN 279,000 - 318,000
Private medical care
Multisport Card
Remote work options
+3
Senior Security Engineer (AI)
Senior Security Engineer (AI)

Talanto • Katowice

Hybrid
PLN 145,000 - 190,000
Luxmed
Medicover Sport
Worksmile
+1
Lead Application Security Engineer ID71664
Lead Application Security Engineer ID71664

AgileEngine, LLC. • Poznań

On-site
PLN 250,000 - 380,000
Growth without limits
Competitive compensation
Flexibility
+3
Team Lead - Principal Security Detection & Response Analyst Team Lead
Team Lead - Principal Security Detection & Response Analyst Team Lead

LevelBlue, LLC. • Poland

Hybrid
PLN 180,000 - 260,000
Contract of employment
Sport card/ co-financing of vacation
Life insurance
+5
Lead Application Security Engineer ID71664
Lead Application Security Engineer ID71664

AgileEngine, LLC. • Kraków

On-site
PLN 180,000 - 260,000
Growth without limits
Competitive compensation
Flexibility: remote work
+3
Security Engineer, Threat Response
Security Engineer, Threat Response

Asana • Warszawa

Hybrid
Health insurance
Breakfast and lunch catering
Career growth budget
+3
Security Engineer, Threat Response Warsaw
Security Engineer, Threat Response Warsaw

Asana • Warszawa

Hybrid
Health insurance
Breakfast and lunch catering
Vacation allowance
+6
Security Operations Engineer II
Security Operations Engineer II

CoreWeave • Warszawa

On-site
PLN 189,000 - 252,000
Discretionary bonus
Equity awards
Family-level Medical Insurance
+6
Team Lead - Principal Security Detection & Response Analyst Team Lead
Team Lead - Principal Security Detection & Response Analyst Team Lead

LevelBlue • Poland

Hybrid
PLN 180,000 - 240,000
Contract of employment
Sport card
Life insurance
+5
Security Engineer – Incident Response Team (f/m/x)
Security Engineer – Incident Response Team (f/m/x)

Sii Poland • Warszawa

Hybrid
PLN 180,000 - 240,000
Great Place to Work
Profit sharing
Medical care
+4