Security Operations Engineer

Security

Security Operations Engineer

Security
Full-time
Permanent
Mid
Remote

Job description

Role description:

As a Security Operations Engineer, you will play a pivotal role in supporting the expansion of the ALaM program by onboarding new paramount applications into our monitoring scope. You will be instrumental in delivering SIEM use cases, detection logic, and verification activities essential for achieving DORA compliance by the end of 2026.

This role is heavily focused on SIEM engineering, threat modelling, rule optimization, testing, and workshop facilitation. Your expertise and proactive approach will directly contribute to strengthening our security posture, improving alert fidelity, and ensuring robust monitoring capabilities across our critical applications.

Tasks & Responsibilities:

  • Detection Engineering: Build, optimize, and maintain SIEM detection rules (preference for Microsoft Sentinel).

  • Testing & Automation: Test and verify existing and newly created use cases, and automate testing processes through scripting.

  • Application Onboarding: Support the onboarding of paramount applications into the monitoring scope.

  • Requirements Gathering: Work closely with application teams to gather logging requirements and detection inputs.

  • Workshop Facilitation: Run and moderate workshops with application owners to align on security capabilities and threat landscapes.

  • Technical Documentation: Produce comprehensive documentation for detection logic, threat profiles, and verification results.

  • Collaboration: Collaborate effectively with the SOC, engineering teams, and red teams to improve alert fidelity and incident response efficiency.

  • Compliance Delivery: Contribute to Threat Verification activities and deliver outputs according to ALaM and DORA timelines.

Skills and experience you will need:

  • SIEM Expertise: Strong hands-on experience with SIEM platforms, with a strong preference for Microsoft Sentinel.

  • Engineering & Rules: Proven experience in detection engineering, rule creation, and rule testing.

  • Scripting & Automation: Ability to automate testing and validation processes using Python, PowerShell, Bash, or similar languages.

  • Communication Skills: Strong communication skills in English (spoken and written), with the proven ability to confidently lead and moderate workshops.

  • Infrastructure Knowledge: Familiarity with cloud platforms (Azure/AWS), operating systems (Windows, Linux), and databases (SQL/Oracle environments).

  • Independence: Ability to work independently and efficiently in a high-volume onboarding environment.

Technology Stack

  • SIEM & Security: Microsoft Sentinel.

  • Cloud & Infrastructure: Azure, AWS, Windows, Linux, SQL, Oracle.

  • Scripting & Automation: KQL, Python, PowerShell, Bash.

Preferred Qualifications

  • Threat Modelling: Experience in conducting threat modelling and building threat profiles.

  • Regulatory Frameworks: Familiarity with DORA (Digital Operational Resilience Act) compliance requirements

What we offer:

  • The opportunity to participate in a variety of projects

  • Multisport Plus card

  • Private medical care (LUX MED)

  • Group insurance

  • Access to comprehensive psychological support, individual sessions with coaches and psychodietitians, as well as inspiring webinars

  • Remote work from any location, or a hybrid model using our office located in Poznan

  • A home office package to increase remote work comfort (chair, additional monitor, ergonomic mouse, etc.)

  • Modern office equipped with amenities such as a pool table, foosball, darts, and relaxation zones

  • Opportunities to spend time together after work — combining our employees’ passions through ski trips, cycling tours, and sailing adventures

  • Regular company-wide and team-based integration events, as well as many other occasions to meet and exchange ideas with colleagues

  • Celebrations of important moments in the lives of our employees

  • An open approach to new ideas and initiatives, including charity actions

Tech stack

    Polish

    C2

    English

    B2

    Security

    regular

    SIEM

    regular

    Bash

    regular

    Powershell

    regular

    Python

    regular

    Microsoft Sentinel

    regular

Office location

About the company

NTT DATA Business Solutions

Rozumiemy działania naszych klientów i wiemy, jak wspierać ich biznes, aby był gotowy na wyzwania przyszłości. W NTT DATA Business Solutions napędzamy innowacje – od doradztwa i wdrożeń po usługi zarządzane (Managed Serv...
Company profile
Similar offers
Capco Poland

Capco Poland

Remote

Remote

Undisclosed Salary
Security
SIEM
Microsoft Sentinel
Python
Powershell
Bash
Azure
AWS
Windows
Linux
MidMidB2BB2BFull-timeFull-time
New
ADVERTISEMENT: Recommended by Just Join IT
Similar offers
Capco Poland

Capco Poland

Remote

Remote

Undisclosed Salary
Security
SIEM
Microsoft Sentinel
Python
Powershell
Bash
Azure
AWS
Windows
Linux
MidMidB2BB2BFull-timeFull-time
New
Link Group

Link Group

Remote

Remote

40,19 - 48,23USD/h
Security
IAM
PAM
Entra ID
JIT
JEA
MidMidB2BB2BFull-timeFull-time
New
GR8_TECH

GR8_TECH

Remote

Remote

Undisclosed Salary
Security
Bash
Powershell
ISO 27001
Python
MidMidPermanent, B2BPermanent, B2BFull-timeFull-time
New
BTC Software Systems Sp.z o.o.

BTC Software Systems Sp.z o.o.

Poznań

Remote

Remote

Undisclosed Salary
AWS
Powershell
Azure
GCP
SIEM
Python
MidMidPermanentPermanentFull-timeFull-time
New
FUN CRAFTERS SP. Z O O.

FUN CRAFTERS SP. Z O O.

Kraków

Remote

Remote

Undisclosed Salary
SIEM
EDR platform
Linux
Windows
MidMidB2B, PermanentB2B, PermanentFull-timeFull-time
New
ADVERTISEMENT: Recommended by Just Join IT