SIEM & SOAR Engineer — Hybrid/Remote Cybersecurity

Ernst & Young Advisory Services Sdn Bhd

Warszawa

Hybrid

PLN 180,000 - 260,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Hybrid/Remote work
EY Badges
Career Counselor
Private healthcare
Life insurance
Team sports & fitness

Job summary

EY Poland is seeking a cybersecurity engineer to design and implement enterprise SIEM and SOAR solutions, deploying CrowdStrike NG-SIEM, Splunk, and XSOAR across international projects. You will onboard data sources, create detections, and automate responses while collaborating with SOC teams to mature security operations.

The role emphasizes working with Windows, Linux, and cloud environments, plus strong English and Polish communication.

Qualifications

  • 4+ years of experience in Cybersecurity Engineering, Security Operations, Detection Engineering, or Security Consulting.
  • Hands-on experience with at least one of CrowdStrike NG-SIEM, Splunk, XSOAR, Cribl, or Apache NiFi.
  • Strong understanding of cybersecurity operations and threat detection principles.
  • Experience with SIEM, SOAR, Data Ingestion, or SOC technologies.
  • Knowledge of incident detection and response processes.
  • Understanding of network security concepts and common attack techniques.
  • Experience integrating security technologies and working with APIs.
  • Knowledge of Windows, Linux, and cloud environments.
  • Ability to analyze security events and design detection logic.
  • Strong communication and stakeholder management skills.
  • Very good command of English and Polish (B2/C1 level).

Responsibilities

  • Design and implement enterprise SIEM architectures.
  • Lead deployments of CrowdStrike NG-SIEM and Splunk solutions.
  • Onboard security data sources into SIEM ecosystems using native ingestion methods as well as third‑party solutions such as Cribl and Apache NiFi.
  • Develop onboarding strategies and deployment roadmaps for enterprise environments.
  • Create detection logic, correlation rules, dashboards, and automated queries.
  • Design and implement automations within enterprise SOAR platforms.
  • Lead deployments of XSOAR, CrowdStrike Fusion, and Splunk SOAR solutions.
  • Integrate SIEM platforms and third‑party security technologies into SOAR ecosystems.
  • Fine‑tune response workflows and collaborate with SOC teams.
  • Support clients in improving SIEM and SOAR maturity and transforming their security operations capabilities.
  • Improve detection coverage and threat visibility across complex IT environments.
  • Design integrations using APIs and automation frameworks.
  • Support platform upgrades, migrations, and cybersecurity transformation initiatives.
  • Prepare technical documentation, operating procedures, and architecture diagrams.
  • Advise clients on security best practices and platform optimization.
  • Participate in projects related to XDR, Security DevOps, AI Security, Cloud Security, and SASE/SSE technologies.

Skills

Strong communication
Stakeholder management
English proficiency
Polish proficiency

Tools

CrowdStrike NG-SIEM
Splunk
XSOAR
Cribl
Apache NiFi

Job description

EY Poland is seeking a cybersecurity engineer to design and implement enterprise SIEM and SOAR solutions, deploying CrowdStrike NG-SIEM, Splunk, and XSOAR across international projects. You will onboard data sources, create detections, and automate responses while collaborating with SOC teams to mature security operations.

The role emphasizes working with Windows, Linux, and cloud environments, plus strong English and Polish communication.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SIEM & SOAR Engineer — Remote & Global Security Ops
SIEM & SOAR Engineer — Remote & Global Security Ops

EY • Warszawa

Hybrid
PLN 180,000 - 270,000
Flexible working
Hybrid/remote options
Professional development
+2
SIEM/ SOAR Engineer
SIEM/ SOAR Engineer

Ernst & Young Advisory Services Sdn Bhd • Warszawa

Hybrid
PLN 180,000 - 260,000
Hybrid/Remote work
EY Badges
Career Counselor
+3
SIEM SOAR Engineer
SIEM SOAR Engineer

EY • Warszawa

Hybrid
PLN 180,000 - 270,000
Flexible working
Hybrid/remote options
Professional development
+2
Senior Cybersecurity XDR Architect | Remote/Hybrid
Senior Cybersecurity XDR Architect | Remote/Hybrid

EY • Poznań

Hybrid
PLN 180,000 - 260,000
Flexible working model
Hybrid and remote work options
EY Badges and professional development
+1
AI-Driven XDR Security Engineer (Hybrid/Remote)
AI-Driven XDR Security Engineer (Hybrid/Remote)

EY • Warszawa

Hybrid
PLN 180,000 - 240,000
Flexible working model
Hybrid and remote work options
Professional development programs
+1
Insider Threat Detection Senior Analyst (SIEM) – Remote
Insider Threat Detection Senior Analyst (SIEM) – Remote

EY • Katowice

Hybrid
PLN 180,000 - 240,000
Senior Insider Threat Analyst – SIEM & Investigations (Hybrid)
Senior Insider Threat Analyst – SIEM & Investigations (Hybrid)

EY • Wrocław

Hybrid
PLN 180,000 - 240,000
Cyber Detection & Response Manager — Lead & Innovate (Remote)
Cyber Detection & Response Manager — Lead & Innovate (Remote)

Ernst & Young Advisory Services Sdn Bhd • Katowice

Hybrid
PLN 320,000 - 480,000
Security Automation Specialist / SOAR Consultant
Security Automation Specialist / SOAR Consultant

Winged IT • Warszawa

Hybrid
PLN 150,000 - 210,000
Security Engineer EDR
Security Engineer EDR

EY • Poznań

Hybrid
PLN 180,000 - 260,000
Flexible working model
Hybrid and remote work options
EY Badges and professional development
+1