Unlock Full Resume Report

New offer - be the first one to apply!

September 13, 2026

Lead Security Operations Engineer

Senior • On-site

300,000 - 342,000 PLN/yr

Wrocław, Pl-Ds, Poland

Quick Facts

Lead Security Operations Engineer (hybrid, Wroclaw, Poland). Reporting to the Senior Manager, AI Response and Threat. Full-time role.

Description

Own the detection strategy, lead response to major incidents, and mentor the analysts and engineers on the Security team to mature the security operations program in a fast-growing, cloud-first environment. Work cross-functionally with DevOps, Engineering, and IT to embed security controls into infrastructure and CI/CD pipelines. Conduct host, network, and memory forensics and produce clear reporting for technical and non-technical stakeholders during incidents.

Responsibilities

  • Own complex/high-severity incidents end-to-end: triage, containment, remediation, and post-incident review; keep stakeholders informed.
  • Apply security considerations across AWS, Azure, or GCP and adapt detection/response strategies to cloud-native infrastructure.
  • Lead incident response for significant security events from scoping and containment through post-incident review; perform host, network, and memory forensics.
  • Embed security controls with DevOps and Engineering in infrastructure, CI/CD pipelines, and system design.
  • Mentor analysts and engineers to increase independence and technical depth.
  • Translate complex technical findings into actionable insight for executives, customers, or other non-technical stakeholders, especially under incident pressure.
  • Assess, select, and integrate security tools (SIEM, EDR, SOAR, cloud-native platforms) to improve coverage while minimizing complexity and cost.
  • Occasional travel (up to 10–20%) for team meetings, training, or company events.

Requirements

  • 6+ years of experience in security operations with progressive responsibility across triage, incident response, and detection engineering.
  • Experience leading or mentoring a team (formally or informally), providing technical guidance and coaching.
  • Deep expertise with SIEM, EDR, and SOAR platforms, including hands-on rule-writing, tuning, and automation development.
  • Strong incident response leadership for complex or high-severity incidents end-to-end.
  • Solid understanding of cloud security architecture (AWS, Azure, or GCP) and experience working with DevOps and Engineering to embed security into CI/CD pipelines and infrastructure.
  • Scripting/automation proficiency (Python, PowerShell, or similar) to build and scale response workflows.
  • Deep familiarity with attacker tactics and techniques (MITRE ATT&CK) translated into detection logic.
  • Excellent communication skills to brief executives and technical teams during incidents and planning discussions.

Benefits

  • Starting base salary range: PLN 25,000–28,500 monthly (actual compensation varies by skills, experience, and location).
  • Annual bonus eligibility and participation in equity program.
  • Comprehensive benefits: premium private medical care with priority appointments, Multisport Cards, and flexible remote work options.
  • Recharge Holidays: one long weekend each quarter.
  • Career development and mentoring opportunities.
  • Inclusive hiring process and support for accommodations.

Similar jobs you might like