Unlock Full Resume Report

New offer - be the first one to apply!

September 23, 2026

Security Operations Engineer

Mid • Remote

Kraków, MA, Poland

Quick Facts

  • Role: Security Operations Engineer

Description

You will monitor, detect, and respond to threats across infrastructure and services, owning security monitoring and incident response. Responsibilities include SIEM operations, alert triage, and threat investigation, while partnering closely with DevOps to improve detection and strengthen security.

Responsibilities

  • Monitor and triage security alerts from SIEM, EDR, and cloud security tools

  • Investigate security incidents, contain threats, and contribute to post-incident reviews

  • Maintain and tune detection rules to improve signal quality and reduce false positives

  • Track and coordinate vulnerability remediation across infrastructure and services

  • Perform access control reviews, privileged account audits, and maintain IAM hygiene

  • Maintain security runbooks, playbooks, and incident response documentation

  • Support SOC 2 and ISO 27001 audits, including evidence collection, control validation, and gap remediation

  • Conduct scheduled internal security assessments and assist with penetration test scoping

  • Collaborate with DevOps on system and cloud configuration hardening

Requirements

  • 2+ years in a security operations, SOC, or similar role

  • Experience with at least one SIEM platform (Elastic SIEM, Splunk, Datadog Security, or Microsoft Sentinel)

  • Experience with alert triage, log analysis, and basic threat hunting

  • Familiarity with MITRE ATT&CK for incident classification

  • Experience with at least one EDR platform (CrowdStrike Falcon, SentinelOne, or Wazuh)

  • Experience with vulnerability scanning tools (Nessus, OpenVAS, or Qualys)

  • Working knowledge of AWS or GCP security controls (Security Groups, IAM, CloudTrail, GuardDuty)

  • Operational-level Windows and Linux administration (log analysis, process inspection, basic hardening)

  • Familiarity with containerized environments (Docker, Kubernetes) from a security perspective

  • Experience supporting SOC 2 or ISO 27001 audits

  • Ability to write clear incident reports, runbooks, and policy documentation

  • Experience with access review processes and IAM audits

  • Scripting proficiency in Bash or Python for operational automation

Benefits

  • Competitive salary

  • Remote-first, async-friendly team

  • Dedicated budget for security tooling and training

  • Clear growth path toward Senior SecOps or DevSecOps Engineer with increasing ownership of detection engineering, automation, and security architecture

Similar jobs you might like