Lead Security Operations Engineer

Jobtailor

Wrocław

On-site

PLN 180,000 - 240,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking a senior Security Operations lead in Wroclaw to own and mature the detection strategy, drive incident response from triage to remediation, and report clearly to technical and non-technical stakeholders.

You will work with DevOps and Engineering to embed security controls in CI/CD, mentor analysts, and develop automation across SIEM, EDR, and SOAR in a cloud-first environment.

Qualifications

  • 6+ years of security operations experience with progression from triage to detection engineering
  • Proven experience leading or mentoring a team, formally or informally
  • Deep expertise with SIEM, EDR, and SOAR platforms, including hands-on rule-writing, tuning, and automation
  • Strong incident response leadership experience managing complex or high-severity incidents end-to-end
  • Solid understanding of cloud security architecture in AWS, Azure, or GCP environments
  • Experience embedding security into CI/CD pipelines and infrastructure with DevOps/Engineering
  • Scripting or automation proficiency in Python or PowerShell
  • Familiarity with MITRE ATT&CK techniques and attacker TTPs
  • Excellent communication skills for briefing executives and technical teams
  • Up to 10–20% travel
  • Nice-to-have: cloud-native detection, container security, threat intel platforms, threat hunting, purple team, certs, network security, vulnerability management, DLP/insider threat detection

Responsibilities

  • Own and mature the security operations detection strategy
  • Lead major incident response from triage through remediation and post-incident review
  • Conduct host, network, and memory forensics
  • Produce clear reporting for technical and non-technical stakeholders
  • Collaborate with DevOps/Engineering to embed security controls in CI/CD pipelines and system design
  • Mentor analysts and engineers to deepen their technical depth
  • Translate technical findings into actionable insights for executives and customers
  • Assess, select, and integrate SIEM, EDR, SOAR, and cloud-native tools
  • Work cross-functionally in a cloud-first environment with DevOps, Engineering, and IT

Skills

Security operations leadership
Incident response management
SIEM, EDR, SOAR expertise
Cloud security architecture
Python/PowerShell scripting

Tools

SIEM
EDR
SOAR
Cloud-Native Security Tools
CI/CD tooling

Job description

Responsibilities
  • Own and mature the security operations detection strategy
  • Lead major and significant incident response from triage, scoping, and containment through remediation and post-incident review
  • Conduct host, network, and memory forensics
  • Produce clear reporting for technical and non-technical stakeholders
  • Collaborate with DevOps and Engineering to embed security controls in infrastructure, CI/CD pipelines, and system design
  • Mentor analysts and engineers and develop their technical depth and independence
  • Translate technical findings into actionable insights for executives, customers, and other non-technical stakeholders
  • Assess, select, and integrate SIEM, EDR, SOAR, and cloud-native security tools
  • Work cross-functionally in a cloud-first environment with DevOps, Engineering, and IT
Requirements
  • 6+ years of experience in security operations, with progressive responsibility across triage, incident response, and detection engineering
  • Proven experience leading or mentoring a team, formally or informally
  • Deep expertise with SIEM, EDR, and SOAR platforms, including hands-on rule-writing, tuning, and automation development
  • Strong incident response leadership experience managing complex or high-severity incidents end-to-end
  • Solid understanding of cloud security architecture in AWS, Azure, or GCP environments
  • Experience working with DevOps and Engineering to embed security into CI/CD pipelines and infrastructure
  • Scripting or automation proficiency in Python, PowerShell, or similar
  • Deep familiarity with attacker tactics and techniques using MITRE ATT&CK
  • Excellent communication skills for briefing executives and technical teams
  • Occasional travel availability of up to 10–20%
  • Nice-to-have: cloud-native detection and posture tools, container and orchestration security, threat intelligence platforms, threat hunting, purple team or adversary simulation, relevant certifications, network security architecture, vulnerability management, and DLP or insider threat detection experience
Core Competencies

Demonstrates expertise in security operations, incident response, and detection engineering, with a strong focus on integrating security controls in cloud environments and CI/CD pipelines. Proficient in mentoring teams and translating technical findings for diverse stakeholders.

Highest-signal resume keywords
  • Security Operations Leadership
  • Incident Response Management
  • SIEM, EDR, SOAR Expertise
  • Cloud Security Architecture
  • Scripting Proficiency in Python
Hard Skills
  • Incident Response
  • Triage
  • Host Forensics
  • Network Forensics
  • Memory Forensics
  • Rule-Writing
  • Automation Development
  • Cloud Security
  • Threat Hunting
  • Vulnerability Management
Soft Skills
  • Communication Skills
  • Mentoring
  • Collaboration
Industry Keywords
  • Cloud Security Architecture
  • DevOps
  • Incident Response
  • Threat Intelligence
  • DLP
Tools & Technologies
  • SIEM
  • EDR
  • SOAR
  • Cloud-Native Security Tools
  • CI/CD Pipelines
  • MITRE ATT&CK
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Research Analyst
Threat Research Analyst

Sigmasoftware2 • Poland

On-site
PLN 120,000 - 180,000
Network Security Engineer
Network Security Engineer

Uvation • Poland

On-site
PLN 100,000 - 120,000
Security Detection Engineer
Security Detection Engineer

SoftServe • Poland

On-site
PLN 180,000 - 280,000
Senior Software Engineer – Technical Lead
Senior Software Engineer – Technical Lead

Jobtailor • Kraków

On-site
PLN 180,000 - 240,000
Cyber Security Engineer
Cyber Security Engineer

Interact Software • Poland

On-site
PLN 120,000 - 180,000
Software Engineer and Security Researcher
Software Engineer and Security Researcher

Commit • Warszawa

Hybrid
PLN 190,000 - 270,000
Application Security Engineer
Application Security Engineer

LionHires Recruitment • Poland

On-site
PLN 180,000 - 240,000
Cyber Security Architect
Cyber Security Architect

Experis ManpowerGroup Sp. z o.o. • Warszawa

Remote
PLN 180,000 - 300,000
Multisport Card
Life insurance
Private healthcare
+1
Lead Azure AI Security Engineer
Lead Azure AI Security Engineer

EPAM • Poland

On-site
PLN 85,000 - 110,000
Cyber Security Architect
Cyber Security Architect

Experis ManpowerGroup Sp. z o.o. • Poland

Remote
PLN 180,000 - 240,000
Multisport Card
Life insurance
Private healthcare
+1