Security Engineer EDR

Ernst & Young Advisory Services Sdn Bhd

Warszawa

On-site

PLN 180,000 - 260,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

EY Badges
Hybrid/Remote options
Private healthcare and insurance
Career guidance & training
Certification support

Job summary

EY Poland is seeking a Cybersecurity Engineer to design and implement enterprise XDR architectures and lead deployments of CrowdStrike Falcon XDR and Microsoft Defender XDR. You will integrate endpoints, cloud workloads, identities, and security tools, while guiding onboarding strategies and deployment roadmaps for large environments.

You will fine‑tune detection logic, support clients in improving XDR maturity, and collaborate with SOC teams on threat hunting and incident response, contributing

Qualifications

  • 4+ years of experience in Cybersecurity Engineering, Security Operations, Detection Engineering, or Security Consulting.
  • Hands-on experience with at least one of the following solutions: CrowdStrike Falcon, Microsoft Defender XDR.
  • Strong understanding of cybersecurity operations and threat detection principles.
  • Experience with XDR, EDR, SIEM, or SOC technologies.
  • Knowledge of incident detection and response processes.
  • Understanding of network security concepts and common attack techniques.
  • Experience integrating security technologies and working with APIs.
  • Knowledge of Windows, Linux, and cloud environments.
  • Ability to analyze security events and design detection logic.
  • Strong communication and stakeholder management skills.
  • Very good command of English and Polish (B2/C1 level).

Responsibilities

  • Design and implement enterprise XDR architectures.
  • Lead deployments of CrowdStrike Falcon XDR and Microsoft Defender XDR solutions.
  • Integrate endpoints, cloud workloads, identities, email security, and third‑party security tools into XDR ecosystems.
  • Develop onboarding strategies and deployment roadmaps for enterprise environments.
  • Fine‑tune detection logic, correlation rules, security policies, and response workflows.
  • Support clients in improving XDR maturity and transforming their security operations capabilities.
  • Improve detection coverage and threat visibility across complex IT environments.
  • Design and implement use cases, detection content, and security response automation.
  • Optimize and operationalize security monitoring capabilities.
  • Conduct health assessments and recommend improvements for existing security platforms.
  • Collaborate with SOC teams to enhance threat hunting, incident response, and investigation processes.
  • Design integrations using APIs and automation frameworks.
  • Support platform upgrades, migrations, and cybersecurity transformation initiatives.
  • Prepare technical documentation, operating procedures, and architecture diagrams.
  • Advise clients on security best practices and platform optimization.
  • Participate in projects related to SIEM & Security Analytics, AI Security, Cloud Security, and SASE/SSE technologies.

Skills

Cybersecurity engineering
Security operations
Detection engineering
Security consulting
XDR
EDR
SIEM
SOC
Windows
Linux
Cloud environments
APIs
English (B2/C1)
Polish (B2/C1)

Tools

CrowdStrike Falcon
Microsoft Defender XDR

Job description

Join our Cybersecurity Engineering team and help organizations strengthen their security posture through the design, implementation, and optimization of modern Extended Detection and Response (XDR) solutions. As part of our growing cybersecurity practice, you will work on complex international projects across multiple industries, supporting clients in building resilient security operations capabilities and defending against advanced cyber threats.

EY.AI – in this role, you will work in an environment where AI agents are part of the team and everyday project work. You will use solutions tailored to specific domains that help analyze data, generate recommendations, and design solutions. This enables you to move faster from analysis to action and create competitive advantages for clients.

Your scope of duties
  • Design and implement enterprise XDR architectures.
  • Lead deployments of CrowdStrike Falcon XDR and Microsoft Defender XDR solutions.
  • Integrate endpoints, cloud workloads, identities, email security, and third‑party security tools into XDR ecosystems.
  • Develop onboarding strategies and deployment roadmaps for enterprise environments.
  • Fine‑tune detection logic, correlation rules, security policies, and response workflows.
  • Support clients in improving XDR maturity and transforming their security operations capabilities.
  • Improve detection coverage and threat visibility across complex IT environments.
  • Design and implement use cases, detection content, and security response automation.
  • Optimize and operationalize security monitoring capabilities.
  • Conduct health assessments and recommend improvements for existing security platforms.
  • Collaborate with SOC teams to enhance threat hunting, incident response, and investigation processes.
  • Design integrations using APIs and automation frameworks.
  • Support platform upgrades, migrations, and cybersecurity transformation initiatives.
  • Prepare technical documentation, operating procedures, and architecture diagrams.
  • Advise clients on security best practices and platform optimization.
  • Participate in projects related to SIEM & Security Analytics, AI Security, Cloud Security, and SASE/SSE technologies.
Our requirements
  • 4+ years of experience in Cybersecurity Engineering, Security Operations, Detection Engineering, or Security Consulting.
  • Hands‑on experience with at least one of the following solutions:
  • CrowdStrike Falcon
  • Strong understanding of cybersecurity operations and threat detection principles.
  • Experience with XDR, EDR, SIEM, or SOC technologies.
  • Knowledge of incident detection and response processes.
  • Understanding of network security concepts and common attack techniques.
  • Experience integrating security technologies and working with APIs.
  • Knowledge of Windows, Linux, and cloud environments.
  • Ability to analyze security events and design detection logic.
  • Strong communication and stakeholder management skills.
  • Very good command of English and Polish (B2/C1 level).
Nice to have
  • Experience designing security architectures and large‑scale security deployments.
  • Experience with cloud security technologies (Azure, AWS, GCP).
  • Knowledge of SOAR and automation platforms.
  • Experience with AI Security solutions and governance frameworks.
  • Experience with SASE/SSE technologies (e.g. Zscaler).
  • Familiarity with PowerShell and Python scripting.
  • Industry certifications such as:
  • CrowdStrike certifications
  • Microsoft Security certifications (SC-200, SC-100, AZ-500)
  • Splunk certifications
  • CISSP, GCIH, GCIA, Security+
What we offer
  • Participation in complex international cybersecurity implementation and transformation projects.
  • Exposure to a wide range of technologies and cybersecurity domains, allowing you to build your own career path.
  • Opportunity to gain hands‑on experience with enterprise‑level cybersecurity tools and platforms.
  • Personalized training programs and learning paths.
  • Flexible working model, including hybrid and remote work options depending on project requirements.
  • Professional and financial support in obtaining recognised qualifications and certificates.
  • EY Badges - global certification of your competencies and the opportunity to earn an MBA title from the prestigious Hult International School of Business.
  • Career Counselor - professional, one‑to‑one guidance on career building and development.
  • Psycho‑educational platform - a package of free consultations with specialists in the broad field of mental health and personal development and access to educational activities.
  • Benefit programme offering private healthcare with additional preventive examinations, life insurance, tickets, team sports, language learning platform, sports cards and much more (available online and offline).
About EY Poland

We are a global consulting and technology company.

We make a difference by transforming services, products, organisations, and even the rules of the game. We combine business expertise, technology, artificial intelligence, and human talent to help organisations solve complex problems, make better decisions, and implement positive change.

We provide confidence in data, opinions, standards, technologies, and security.

Every day we take on challenges, analyse opportunities, prompt, research, collaborate, ask better questions, plan, model, code, experiment, and learn, creating solutions that are critical for our clients.

This is a place where lifelong friendships, professional relationships, and unforgettable experiences are built. This is where you work on meaningful and challenging projects alongside supportive and exceptional people.

We care about the environment, not only the business one. As part of our sustainability commitments, we have reduced our global greenhouse gas emissions by 40% compared to our 2019 baseline.

EY is an equal opportunity employer. We value and promote diversity of knowledge, experience, and perspectives across our community. We foster an environment built on respect, openness, and collaboration, where everyone can grow and make a meaningful impact. Through our “Higher Level Without Barriers” programme, we support employees with disabilities in achieving their professional ambitions and goals.

EY provides equal opportunities to all candidates throughout the recruitment process, regardless of gender, age, race, religion, sexual orientation, national origin, disability, or any other legally protected characteristic, in accordance with applicable law.

Select how often (in days) to receive an alert:

EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer EDR
Security Engineer EDR

EY • Kraków

Hybrid
PLN 180,000 - 240,000
Health insurance
EY Badges
Career development program
+2
Security Engineer EDR
Security Engineer EDR

EY • Katowice

Hybrid
PLN 180,000 - 300,000
Hybrid/Remote work options
Professional development program
EY Badges & MBA opportunity
+1
Security Engineer EDR
Security Engineer EDR

EY • Wrocław

Hybrid
PLN 180,000 - 240,000
Hybrid/Remote options
EY Badges
Career Counselor
+1
Security Engineer EDR
Security Engineer EDR

EY • Łódź

Hybrid
PLN 180,000 - 280,000
Flexible work model
Private healthcare
Life insurance
+2
Security Engineer EDR
Security Engineer EDR

EY • Poznań

Hybrid
PLN 180,000 - 260,000
Flexible working model
Hybrid and remote work options
EY Badges and professional development
+1
Security Engineer EDR
Security Engineer EDR

EY • Rzeszów

Hybrid
PLN 140,000 - 210,000
Hybrid and remote work options
EY Badges
Career Counselor
+1
Security Engineer EDR
Security Engineer EDR

EY • Warszawa

Hybrid
PLN 180,000 - 300,000
Hybrid and remote work options
Professional development program
EY Badges and certifications
+1
Security Engineer EDR
Security Engineer EDR

EY • Województwo pomorskie

Hybrid
PLN 180,000 - 300,000
Private healthcare with preventiveExa
EY Badges – global certification
Career Counselor
Security Engineer EDR at EY
Security Engineer EDR at EY

EY • Warszawa

Hybrid
PLN 180,000 - 240,000
Flexible working model
Hybrid and remote work options
Professional development programs
+1
SIEM/ SOAR Engineer
SIEM/ SOAR Engineer

Ernst & Young Advisory Services Sdn Bhd • Warszawa

Hybrid
PLN 180,000 - 260,000
Hybrid/Remote work
EY Badges
Career Counselor
+3