Security Consulting Engineer
On-siteKrakow, Łódź Voivodeship, Republic of Poland
Job Summary
Deploy end-to-end Splunk Enterprise Security platforms for enterprise customers, from initial installation through production tuning. Design detection content including correlation searches, risk-based alerting, and automated response actions. Onboard and normalize data from firewalls, EDR tools, and cloud platforms using Splunk Add-ons and CIM. Wire up automated response workflows in Splunk SOAR and collaborate directly with customer SOC teams to translate requirements into working solutions. Contribute to pre-sales scoping, write documentation and runbooks, and implement compliance frameworks such as PCI-DSS, ISO 27001, and GDPR within Splunk ES.
Required Qualifications
- Bachelor's degree
- 5 years of experience
- Master's degree
- 3 years of experience
- PhD
- equivalent hands-on experience
- 2+ years of hands-on experience in one or more of the following: Security platform delivery or SIEM/SOAR operations, SOC operations, security monitoring, or incident response, NOC or network security monitoring (alert triage, event correlation, incident escalation workflows), XDR platform administration or operations (e.g. CrowdStrike Falcon, Microsoft Defender XDR, Palo Alto Cortex XDR, SentinelOne, or equivalent), Security data onboarding or log source integration
- Practical scripting or automation skills
- Python
- Fluent English
- Clear communication skills with customer technical teams
Desired Qualifications
- Splunk credentials (we will support you with getting certified): Cybersecurity Defense Analyst, Cybersecurity Defense Engineer (CDE), Splunk Core Consultant, Splunk SOAR Certified Automation Developer
- Hands-on experience with Splunk Enterprise Security or Splunk SOAR
- Security certifications such as CompTIA Security+, CEH, GIAC GCIH, or equivalent
- Background in SOC operations, security monitoring, incident response, or log analysis
- Familiarity with threat detection frameworks such as MITRE ATT&CK
- Experience with security data onboarding and SIEM log source integration
- Familiarity with competitor SIEM/SOAR platforms (e.g. Microsoft Sentinel, IBM QRadar, Palo Alto XSOAR)
- Additional European language (Polish, German, French, or Arabic)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.