SIEM SOAR Engineer

EY (dawniej Ernst & Young)

Warszawa

Hybrid

PLN 180,000 - 260,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Flexible working model
Hybrid/remote options
Private healthcare
Professional development program
EY Badges
Career Counselor
Psycho-educational platform

Job summary

EY zaprasza do zespołu Cybersecurity Engineering w Warszawie. Twoje zadanie to projektowanie, implementację i optymalizację nowoczesnych platform SIEM i SOAR w międzynarodowych projektach.

Doświadczenie w SIEM/SOAR, ekspertyza z CrowdStrike i Splunk, oraz umiejętność pracy z API i automatyzacją są kluczowe. Oferujemy elastyczny model pracy, szkolenia i wsparcie certyfikacyjne.

Qualifications

  • 4+ years of experience in cybersecurity engineering, security operations, detection engineering, or security consulting.
  • Hands-on with CrowdStrike NG-SIEM, Splunk, XSOAR, Cribl, or Apache NiFi.
  • Strong understanding of cybersecurity operations and threat detection.
  • Experience with SIEM, SOAR, data ingestion, or SOC technologies.
  • Knowledge of incident detection and response processes.
  • Understanding of network security concepts and common attack techniques.
  • Experience with API integrations.
  • Knowledge of Windows, Linux, and cloud environments.
  • Ability to analyze security events and design detection logic.
  • Strong communication and stakeholder management skills.
  • Excellent command of English and Polish (B2/C1).

Responsibilities

  • Design and implement enterprise SIEM architectures.
  • Lead deployments of CrowdStrike NG-SIEM and Splunk solutions.
  • Onboard security data sources into SIEM ecosystems using native ingestion methods as well as third‑party solutions such as Cribl and Apache NiFi.
  • Develop onboarding strategies and deployment roadmaps for enterprise environments.
  • Create detection logic, correlation rules, dashboards, and automated queries.
  • Design and implement automations within enterprise SOAR platforms.
  • Lead deployments of XSOAR, CrowdStrike Fusion, and Splunk SOAR solutions.
  • Integrate SIEM platforms and third‑party security technologies into SOAR ecosystems.
  • Fine‑tune response workflows and collaborate with SOC teams.
  • Support clients in improving SIEM and SOAR maturity and transforming their security operations capabilities.
  • Improve detection coverage and threat visibility across complex IT environments.
  • Design integrations using APIs and automation frameworks.
  • Support platform upgrades, migrations, and cybersecurity transformation initiatives.
  • Prepare technical documentation, operating procedures, and architecture diagrams.
  • Advise clients on security best practices and platform optimization.
  • Participate in projects related to XDR, Security DevOps, AI Security, Cloud Security, and SASE/SSE technologies.

Skills

Cybersecurity
Threat detection
SIEM/SOAR
Incident detection
APIs
Windows/Linux/Cloud
Communication

Tools

CrowdStrike NG-SIEM
Splunk
Cortex XSOAR
Cribl
Apache NiFi

Job description

Nasze wymagania:


  • 4+ years of experience in Cybersecurity Engineering, Security Operations, Detection Engineering, or Security Consulting.

  • Hands-on experience with at least one of the following solutions: CrowdStrike NG-SIEM, Splunk, XSOAR, Cribl, or Apache NiFi.

  • Strong understanding of cybersecurity operations and threat detection principles.

  • Experience with SIEM, SOAR, Data Ingestion, or SOC technologies.

  • Knowledge of incident detection and response processes.

  • Understanding of network security concepts and common attack techniques.

  • Experience integrating security technologies and working with APIs.

  • Knowledge of Windows, Linux, and cloud environments.

  • Ability to analyze security events and design detection logic.

  • Strong communication and stakeholder management skills.

  • Very good command of English and Polish (B2/C1 level).


Mile widziane:


  • Experience designing security architectures and large-scale security deployments.

  • Experience with cloud security technologies (Azure, AWS, GCP).

  • Knowledge of XDR and Detection Engineering.

  • Experience with AI Security solutions and governance frameworks.

  • Experience with SASE/SSE technologies, such as Zscaler.

  • Familiarity with PowerShell and Python scripting.

  • Industry certifications such as CrowdStrike, Microsoft Security (SC-200, SC-100, AZ-500), Splunk, CISSP, GCIH, GCIA, or Security+.


O projekcie:

Join our Cybersecurity Engineering team and help organizations strengthen their security posture through the design, implementation, and optimization of modern SIEM and SOAR platforms. As part of our growing cybersecurity practice, you will work on complex international projects across multiple industries, supporting clients in building mature security operations capabilities, improving threat detection, and automating incident response processes.


EY.AI - in this role, you will work in an environment where AI agents are part of the team and everyday project work. You will use solutions tailored to specific domains that help analyze data, generate recommendations, and design solutions. This enables you to move faster from analysis to action and create competitive advantages for clients.


Zakres obowiązków:


  • Design and implement enterprise SIEM architectures.

  • Lead deployments of CrowdStrike NG-SIEM and Splunk solutions.

  • Onboard security data sources into SIEM ecosystems using native ingestion methods as well as third-party solutions such as Cribl and Apache NiFi.

  • Develop onboarding strategies and deployment roadmaps for enterprise environments.

  • Create detection logic, correlation rules, dashboards, and automated queries.

  • Design and implement automations within enterprise SOAR platforms.

  • Lead deployments of XSOAR, CrowdStrike Fusion, and Splunk SOAR solutions.

  • Integrate SIEM platforms and third-party security technologies into SOAR ecosystems.

  • Fine-tune response workflows and collaborate with SOC teams.

  • Support clients in improving SIEM and SOAR maturity and transforming their security operations capabilities.

  • Improve detection coverage and threat visibility across complex IT environments.

  • Design and implement use cases, detection content, and response automation.

  • Conduct health assessments and recommend improvements for existing security platforms.

  • Design integrations using APIs and automation frameworks.

  • Support platform upgrades, migrations, and cybersecurity transformation initiatives.

  • Prepare technical documentation, operating procedures, and architecture diagrams.

  • Advise clients on security best practices and platform optimization.

  • Participate in projects related to XDR, Security DevOps, AI Security, Cloud Security, and SASE/SSE technologies.


Oferujemy:


  • Participation in complex international cybersecurity implementation and transformation projects.

  • Exposure to a wide range of technologies and cybersecurity domains, allowing you to build your own career path.

  • Opportunity to gain hands‑on experience with enterprise‑level cybersecurity tools and platforms.

  • Personalized training programs and learning paths.

  • Participation in a professional development program.

  • Flexible working model, including hybrid and remote work options depending on project requirements.

  • Locations: Warsaw, Lodz, Wroclaw, Gdansk, and other EY offices in Poland.

  • Professional and financial support in obtaining recognised qualifications and certificates.

  • EY Badges - global certification of your competencies and the opportunity to earn an MBA title from the prestigious Hult International School of Business.

  • Career Counselor - professional, one-to-one guidance on career building and development.

  • Psycho-educational platform - a package of free consultations with specialists in the broad field of mental health and personal development and access to educational activities.

  • Benefit programme offering private healthcare with additional preventive examinations, life insurance, tickets, team sports, sports cards and much more (available online and offline).

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SIEM SOAR Engineer
SIEM SOAR Engineer

EY • Warszawa

Hybrid
PLN 180,000 - 270,000
Flexible working
Hybrid/remote options
Professional development
+2
Cybersecurity Operations Consultant
Cybersecurity Operations Consultant

EY (dawniej Ernst & Young) • Warszawa

Hybrid
PLN 180,000 - 320,000
Private healthcare
Life insurance
Work with enterprise-grade security
+3
SIEM/ SOAR Engineer
SIEM/ SOAR Engineer

Ernst & Young Advisory Services Sdn Bhd • Warszawa

Hybrid
PLN 180,000 - 260,000
Hybrid/Remote work
EY Badges
Career Counselor
+3
Cryptography Security Consultant
Cryptography Security Consultant

EY (dawniej Ernst & Young) • Warszawa

On-site
PLN 180,000 - 260,000
Narzędzia AI w pracy
EY Badges – certyfikacja kompetencji
Career Counselor
Security Engineer EDR
Security Engineer EDR

EY • Rzeszów

Hybrid
PLN 140,000 - 210,000
Hybrid and remote work options
EY Badges
Career Counselor
+1
Security Engineer EDR
Security Engineer EDR

EY • Poznań

Hybrid
PLN 180,000 - 260,000
Flexible working model
Hybrid and remote work options
EY Badges and professional development
+1
Security Engineer EDR
Security Engineer EDR

EY • Katowice

Hybrid
PLN 180,000 - 300,000
Hybrid/Remote work options
Professional development program
EY Badges & MBA opportunity
+1
Security Engineer EDR
Security Engineer EDR

EY • Warszawa

Hybrid
PLN 180,000 - 300,000
Hybrid and remote work options
Professional development program
EY Badges and certifications
+1
Security Engineer EDR
Security Engineer EDR

EY • Łódź

Hybrid
PLN 180,000 - 280,000
Flexible work model
Private healthcare
Life insurance
+2
Security Engineer EDR
Security Engineer EDR

EY • Wrocław

Hybrid
PLN 180,000 - 240,000
Hybrid/Remote options
EY Badges
Career Counselor
+1