Security Consulting Engineer
On-siteKrakow, Łódź Voivodeship, Republic of Poland
Job Summary
Lead end-to-end delivery of enterprise security platform deployments, managing system architecture, configuration, and go-live for Splunk-based programs. Design and automate incident response workflows using SOAR technology, integrating third-party tools like EDR and identity platforms. Build advanced threat detection rules, tune risk-based alerting models, and develop compliance reporting for PCI-DSS, ISO 27001, and GDPR. Normalize complex security data sources into a centralized monitoring environment while engaging with CISO and SOC managers to align technical solutions with business objectives. Identify underutilized features and integrate AI/automation to improve response velocity, contributing to technical scoping and Statements of Work. Available for travel up to 30%.
Required Qualifications
- Bachelor's degree
- 7 years of related experience
- Master's degree
- 4 years
- PhD
- 1 year
- equivalent relevant work experience
- Professional-level certification (e.g., CCNP)
- DevOps/automation certification or equivalent knowledge
- 5+ years of hands-on software implementation experience in a customer-facing professional services role
- Proven technical expertise in XDR/SIEM and monitoring platforms (e.g., Checkmk, Elasticsearch, Dynatrace, AppDynamics, IBM QRadar)
- security content development
- security automation/orchestration
- Experience with scripting or programming (Python, Java, .Net or other)
- REST APIs
- workflow automation
- Experience leading complex customer programs
- communicating technical recommendations to CISO, architect, and engineering audiences
- Available for travel - up to 30%
Desired Qualifications
- Certifications: Professional-level networking or security certifications (e.g., CCNP, CISSP, CEH, GIAC GCIH)
- Automation/DevOps: Cisco DevNet or equivalent automation certifications
- experience with CI/CD pipelines
- Infrastructure as Code (IaC)
- DevSecOps practices
- Splunk Expertise: Hands-on experience with Splunk Enterprise Security
- Splunk SOAR/Phantom
- equivalent enterprise SIEM/SOAR platforms
- (Splunk-specific certifications are a significant advantage)
- Background in SOC operations
- incident response
- threat hunting
- detection engineering
- Experience delivering compliance programs (PCI-DSS, ISO 27001, NIST CSF, GDPR)
- Familiarity with platforms like Microsoft Sentinel
- IBM QRadar
- Palo Alto XSOAR
- Google Chronicle
- Proficiency in an additional European language (Polish, German, French, or Arabic)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.