Security Operations Center Engineer

SoftServe

Poland

On-site

PLN 120,000 - 180,000

Full time

Just now
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

SoftServe is seeking an Intermediate Engineer for its CSOC in Poland, focusing on strengthening monitoring and detection using Splunk and Splunk Enterprise Security. You will develop content, tune detections, and collaborate with IT, Security, and Delivery teams to advance threat visibility and incident response.

You will also onboard data sources, validate CIM compliance, and serve as L2 escalation for complex alerts and investigations, while building dashboards and automating workflows to

Qualifications

  • 2+ years in security operations, SOC/CSOC, or related cybersecurity role.
  • Hands-on with Splunk and Splunk Enterprise Security.
  • Familiar with MITRE ATT&CK, NIST CSF, ISO 27001.
  • Experience with Python or PowerShell and automation is a plus.

Responsibilities

  • Develop, configure, and maintain Splunk content including dashboards and correlations.
  • Own detection engineering and tune alerts to reduce false positives.
  • Collaborate with Security, IT, and Delivery teams to improve monitoring and investigations.
  • Onboard and validate security data sources and CIM compliance.
  • Act as L2 escalation for complex alerts and incidents.
  • Build dashboards and reporting to support monitoring and incident response.
  • Support integrations between security platforms and enterprise services.
  • Document technical processes and contribute to automation initiatives.

Skills

Splunk SPL
Detection engineering
Incident investigation
English communication
Python
PowerShell

Education

Bachelor's degree in IT/CS/Cybersecurity

Tools

Splunk
Splunk Enterprise Security
SOAR platforms
AI-enabled tools

Job description

About The Role

Join our Cyber Security Operations Center (CSOC) as an Intermediate Engineer focused on strengthening enterprise security monitoring and detection capabilities through Splunk and Splunk Enterprise Security. In this role, you will enhance SIEM effectiveness, improve detection coverage, support complex incident investigations, and collaborate with Information Security, IT, and Delivery teams to advance security operations, automation, and threat visibility across the organization.

Responsibilities
  • Develop, configure, and maintain Splunk and Splunk Enterprise Security content, including correlation searches, dashboards, reports, data models, knowledge objects, and security analytics
  • Own detection engineering activities by creating, tuning, and optimizing SIEM detection content to improve alert fidelity, expand threat coverage, and reduce false positives
  • Collaborate with Information Security, IT, Delivery teams, and CSOC analysts to strengthen monitoring capabilities, improve investigations, and enhance operational effectiveness
  • Onboard, normalize, and validate security data sources, ensuring data quality, correct field extraction, CIM compliance, and reliable monitoring coverage
  • Act as an L2 escalation point, investigating complex security alerts and incidents, supporting threat analysis, and providing guidance to L1 analysts during investigations
  • Build dashboards, analytics, and reporting solutions that support security monitoring, incident response, performance tracking, and detection engineering initiatives
  • Implement integrations between security platforms and enterprise services, support operational issue resolution, validate SIEM functionality after updates, and coordinate with platform support teams when needed
  • Leverage scripting, automation, SOAR, and AI-enabled technologies to streamline investigations, support operational workflows, contribute to continuous improvement initiatives, and maintain technical documentation
Requirements
  • At least 2 years of hands‑on experience in security operations, SOC/CSOC analysis, SIEM engineering, detection engineering, security engineering, or a related cybersecurity role
  • Strong practical experience with Splunk and Splunk Enterprise Security, including confident use of Splunk Search Processing Language (SPL)
  • Experience creating and tuning correlation searches, security alerts, dashboards, reports, notable events, and detection content within SIEM platforms
  • Knowledge of security data onboarding, normalization, field extraction, data quality management, log‑source coverage, and Splunk Common Information Model (CIM) concepts
  • Solid understanding of incident investigation, alert triage, Windows and Linux environments, and common security technologies including EDR, IDS/IPS, firewalls, email security, and identity services
  • Familiarity with MITRE ATT&CK and understanding of security frameworks such as NIST CSF and ISO 27001
  • Experience with Python, PowerShell, SOAR platforms, automation technologies, or similar tools, with the ability to utilize AI‑enabled tools effectively
  • Strong analytical, problem‑solving, and technical documentation skills, with the ability to independently investigate moderately complex issues and communicate effectively in English at B1/B2 level or higher
  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Management Information Systems, or a related field; relevant security and Splunk certifications are considered an advantage

SoftServe is an equal opportunity employer. Qualified applicants will receive consideration regardless of race, color, ancestry, ethnicity, national origin, religion, sex, sexual orientation, gender identity or expression, age, citizenship, disability, health condition, marital or family status, veteran status, or any other characteristic protected by applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Splunk SIEM Engineer - CSOC Detection & Automation
Splunk SIEM Engineer - CSOC Detection & Automation

SoftServe • Poland

On-site
PLN 120,000 - 180,000
Cyber Security Architect
Cyber Security Architect

Experis ManpowerGroup Sp. z o.o. • Warszawa

Remote
PLN 180,000 - 300,000
Multisport Card
Life insurance
Private healthcare
+1
Lead Security Operations Engineer
Lead Security Operations Engineer

Jobtailor • Wrocław

On-site
PLN 180,000 - 240,000
Cyber Security Architect
Cyber Security Architect

Experis ManpowerGroup Sp. z o.o. • Poland

Remote
PLN 180,000 - 240,000
Multisport Card
Life insurance
Private healthcare
+1
CyberSecurity L&M Service Specialist
CyberSecurity L&M Service Specialist

Arche Consulting Sp. z o.o. • Warszawa

On-site
PLN 180,000 - 260,000
Remote Cybersecurity Architect: SIEM & SOC Lead (German)
Remote Cybersecurity Architect: SIEM & SOC Lead (German)

Experis ManpowerGroup Sp. z o.o. • Poland

On-site
PLN 180,000 - 240,000
Senior Customer Trust Analyst
Senior Customer Trust Analyst

Cisco Systems, Inc. • Kraków

Hybrid
PLN 180,000 - 260,000
Security Detection Engineer
Security Detection Engineer

SoftServe • Poland

On-site
PLN 180,000 - 280,000
Junior SOC Security Engineer
Junior SOC Security Engineer

your Jared • Warszawa

Hybrid
PLN 123,000 - 156,000
Fully remote work
Flexible contracting: B2B or Contract
Cyber Security Engineer
Cyber Security Engineer

Interact Software • Poland

On-site
PLN 120,000 - 180,000