Security Operations Engineer II
$189,000–$252,000 year
On-siteWarsaw, Mazovia, Poland
Job Summary
Conduct initial triage and investigation of security alerts using established playbooks across Linux, MacOS, and Kubernetes environments within the 24/7 SOC. Utilize SIEM, EDR, and other security tooling to detect, investigate, and respond to suspicious activity in real-time, escalating complex incidents to senior engineers. Support incident response activities including analysis, containment, and remediation while contributing detection content and documenting investigations to maintain accurate runbooks. Collaborate with threat intelligence teams to stay aware of emerging threats and contribute findings to post-incident reviews. Rotate through on-call schedules for overnights and weekends in compliance with local Polish labor regulations.
Required Qualifications
- Degree in Computer Science, Computer Engineering, Cyber Security, Information Technology or similar experience
- 1–2+ years of experience in security operations, SOC analysis, incident response, forensics, or a related field
- Working knowledge of Linux and MacOS systems, including logging and common forensic artifacts
- Exposure to Kubernetes and an interest in securing containerized environments
- Familiarity with modern security tools and platforms such as SIEM, EDR, IDS/IPS, and firewalls
- Solid understanding of network protocols, firewalls, VPNs, proxies, and other security technologies
- Strong analytical skills with the ability to work with and interpret data and turn it into actionable insights
- Good communication and collaboration skills, with the ability to stay effective in high-pressure situations
- Must be able to lift 50 lbs
- Must be available for weekend shifts
- Must be able to effectively lead and coach others
- Must be able to perform initial triage and investigation of security alerts using established playbooks and SOPs across Linux, MacOS, and Kubernetes environments
- Must be able to utilize and query SIEM, EDR, and other security tooling to detect, investigate, and respond to suspicious activity in real-time
- Must be able to support incident response activities — analysis, containment, and remediation
- Must be able to contribute findings and observations to post-incident reviews to help improve security defenses
- Must be able to document investigations thoroughly and help keep runbooks and SOPs accurate and up to date
- Must be able to collaborate with threat intelligence and detection engineering teams to stay aware of emerging threats
- Must be able to continuously build your skills across the threat landscape, security tooling, and CoreWeave's environment
- Must be able to perform triage, escalation, and first-line incident response on day-to-day security events
- Must be able to contribute to our detection and response capabilities under the guidance of senior engineers
- Must be able to work in a 24/7/365 SOC with a rotating on-call schedule for overnights/weekends
- Must be able to ensure compliance with local Polish labor regulations regarding shift work and on-call periods
- Must be able to escalate complex or novel incidents to senior engineers
- Must be able to contribute to detection content (detections-as-code) with review from senior team members
- Must be able to help improve security defenses
- Must be able to keep runbooks and SOPs accurate and up to date
- Must be able to stay effective in high-pressure situations
- Must be able to work with and interpret data and turn it into actionable insights
- Must be able to collaborate with threat intelligence and detection engineering teams
- Must be able to build your skills across the threat landscape, security tooling, and CoreWeave's environment
- Must be able to perform triage, escalation, and first-line incident response on day-to-day security events
- Must be able to contribute to our detection and response capabilities under the guidance of senior engineers
- Must be able to work in a 24/7/365 SOC with a rotating on-call schedule for overnights/weekends
- Must be able to ensure compliance with local Polish labor regulations regarding shift work and on-call periods
- Must be able to escalate complex or novel incidents to senior engineers
- Must be able to contribute to detection content (detections-as-code) with review from senior team members
- Must be able to help improve security defenses
- Must be able to keep runbooks and SOPs accurate and up to date
- Must be able to stay effective in high-pressure situations
- Must be able to work with and interpret data and turn it into actionable insights
- Must be able to collaborate with threat intelligence and detection engineering teams
- Must be able to build your skills across the threat landscape, security tooling, and CoreWeave's environment
- Must be able to perform triage, escalation, and first-line incident response on day-to-day security events
- Must be able to contribute to our detection and response capabilities under the guidance of senior engineers
- Must be able to work in a 24/7/365 SOC with a rotating on-call schedule for overnights/weekends
- Must be able to ensure compliance with local Polish labor regulations regarding shift work and on-call periods
- Must be able to escalate complex or novel incidents to senior engineers
- Must be able to contribute to detection content (detections-as-code) with review from senior team members
- Must be able to help improve security defenses
- Must be able to keep runbooks and SOPs accurate and up to date
- Must be able to stay effective in high-pressure situations
- Must be able to work with and interpret data and turn it into actionable insights
- Must be able to collaborate with threat intelligence and detection engineering teams
- Must be able to build your skills across the threat landscape, security tooling, and CoreWeave's environment
- Must be able to perform triage, escalation, and first-line incident response on day-to-day security events
- Must be able to contribute to our detection and response capabilities under the guidance of senior engineers
- Must be able to work in a 24/7/365 SOC with a rotating on-call schedule for overnights/weekends
- Must be able to ensure compliance with local Polish labor regulations regarding shift work and on-call periods
- Must be able to escalate complex or novel incidents to senior engineers
- Must be able to contribute to detection content (detections-as-code) with review from senior team members
- Must be able to help improve security defenses
- Must be able to keep runbooks and SOPs accurate and up to date
- Must be able to stay effective in high-pressure situations
- Must be able to work with and interpret data and turn it into actionable insights
- Must be able to collaborate with threat intelligence and detection engineering teams
- Must be able to build your skills across the threat landscape, security tooling, and CoreWeave's environment
- Must be able to perform triage, escalation, and first-line incident response on day-to-day security events
- Must be able to contribute to our detection and response capabilities under the guidance of senior engineers
- Must be able to work in a 24/7/365 SOC with a rotating on-call schedule for overnights/weekends
- Must be able to ensure compliance with local Polish labor regulations regarding shift work and on-call periods
- Must be able to escalate complex or novel incidents to senior engineers
- Must be able to contribute to detection content (detections-as-code) with review from senior team members
- Must be able to help improve security defenses
- Must be able to keep runbooks and SOPs accurate and up to date
- Must be able to stay effective in high-pressure situations
- Must be able to work with and interpret data and turn it into actionable insights
- Must be able to collaborate with threat intelligence and detection engineering teams
- Must be able to build your skills across the threat landscape, security tooling, and CoreWeave's environment
- Must be able to perform triage, escalation, and first-line incident response on day-to-day security events
- Must be able to contribute to our detection and response capabilities under the guidance of senior engineers
- Must be able to work in a 24/7/365 SOC with a rotating on-call schedule for overnights/weekends
- Must be able to ensure compliance with local Polish labor regulations regarding shift work and on-call periods
- Must be able to escalate complex or novel incidents to senior engineers
- Must be able to contribute to detection content (detections-as-code) with review from senior team members
- Must be able to help improve security defenses
- Must be able to keep runbooks and SOPs accurate and up to date
- Must be able to stay effective in high-pressure situations
- Must be able to work with and interpret data and turn it into actionable insights
- Must be able to collaborate with threat intelligence and detection engineering teams
- Must be able to build your skills across the threat landscape, security tooling, and CoreWeave's environment
- Must be able to perform triage, escalation, and first-line incident response on day-to-day security events
- Must be able to contribute to our detection and response capabilities under the guidance of senior engineers
- Must be able to work in a 24/7/365 SOC with a rotating on-call schedule for overnights/weekends
- Must be able to ensure compliance with local Polish labor regulations regarding shift work and on-call periods
- Must be able to escalate complex or novel incidents to senior engineers
- Must be able to contribute to detection content (detections-as-code) with review from senior team members
- Must be able to help improve security defenses
- Must be able to keep runbooks and SOPs accurate and up to date
- Must be able to stay effective in high-pressure situations
- Must be able to work with and interpret data and turn it into actionable insights
- Must be able to collaborate with threat intelligence and detection engineering teams
- Must be able to build your skills across the threat landscape, security tooling, and CoreWeave's environment
- Must be able to perform triage, escalation, and first-line incident response on day-to-day security events
- Must be able to contribute to our detection and response capabilities under the guidance of senior engineers
- Must be able to work in a 24/7/365 SOC with a rotating on-call schedule for overnights/weekends
- Must be able to ensure compliance with local Polish labor regulations regarding shift work and on-call periods
- Must be able to escalate complex or novel incidents to senior engineers
- Must be able to contribute to detection content (detections-as-code) with review from senior team members
- Must be able to help improve security defenses
- Must be able to keep runbooks and SOPs accurate and up to date
- Must be able to stay effective in high-pressure situations
- Must be able to work with and interpret data and turn it into actionable insights
- Must be able to collaborate with threat intelligence and detection engineering teams
- Must be able to build your skills across the threat landscape, security tooling, and CoreWeave's environment
- Must be able to perform triage, escalation, and first-line incident response on day-to-day security events
- Must be able to contribute to our detection and response capabilities under the guidance of senior engineers
- Must be able to work in a 24/7/365 SOC with a rotating on-call schedule for overnights/weekends
- Must be able to ensure compliance with local Polish labor regulations regarding shift work and on-call periods
- Must be able to escalate complex or novel incidents to senior engineers
- Must be able to contribute to detection content (detections-as-code) with review from senior team members
- Must be able to help improve security defenses
- Must be able to keep runbooks and SOPs accurate and up to date
- Must be able to stay effective in high-pressure situations
- Must be able to work with and interpret data and turn it into actionable insights
- Must be able to collaborate with threat intelligence and detection engineering teams
- Must be able to build your skills across the threat landscape, security tooling, and CoreWeave's environment
- Must be able to perform triage, escalation, and first-line incident response on day-to-day security events
- Must be able to contribute to our detection and response capabilities under the guidance of senior engineers
- Must be able to work in a 24/7/365 SOC with a rotating on-call schedule for overnights/weekends
- Must be able to ensure compliance with local Polish labor regulations regarding shift work and on-call periods
- Must be able to escalate complex or novel incidents to senior engineers
- Must be able to contribute to detection content (detections-as-code) with review from senior team members
- Must be able to help improve security defenses
- Must be able to keep runbooks and SOPs accurate and up to date
- Must be able to stay effective in high-pressure situations
- Must be able to work with and interpret data and turn it into actionable insights
- Must be able to collaborate with threat intelligence and detection engineering teams
- Must be able to build your skills across the threat landscape, security tooling, and CoreWeave's environment
- Must be able to perform triage, escalation, and first-line incident response on day-to-day security events
- Must be able to contribute to our detection and response capabilities under the guidance of senior engineers
- Must be able to work in a 24/7/365 SOC with a rotating on-call schedule for overnights/weekends
- Must be able to ensure compliance with local Polish labor regulations regarding shift work and on-call periods
- Must be able to escalate complex or novel incidents to senior engineers
- Must be able to contribute to detection content (detections-as-code) with review from senior team members
- Must be able to help improve security defenses
- Must be able to keep runbooks and SOPs accurate and up to date
- Must be able to stay effective in high-pressure situations
- Must be able to work with and interpret data and turn it into actionable insights
- Must be able to collaborate with threat intelligence and detection engineering teams
- Must be able to build your skills across the threat landscape, security tooling, and CoreWeave's environment
- Must be able to perform triage, escalation, and first-line incident response on day-to-day security events
- Must be able to contribute to our detection and response capabilities under the guidance of senior engineers
- Must be able to work in a 24/7/365 SOC with a rotating on-call schedule for overnights/weekends
- Must be able to ensure compliance with local Polish labor regulations regarding shift work and on-call periods
- Must be able to escalate complex or novel incidents to senior engineers
- Must be able to contribute to detection content (detections-as-code) with review from senior team members
- Must be able to help improve security defenses
- Must be able to keep runbooks and SOPs accurate and up to date
- Must be able to stay effective in high-pressure situations
- Must be able to work with and interpret data and turn it into actionable insights
- Must be able to collaborate with threat intelligence and detection engineering teams
- Must be able to build your skills across the threat landscape, security tooling, and CoreWeave's environment
- Must be able to perform triage, escalation, and first-line incident response on day-to-day security events
- Must be able to contribute to our detection and response capabilities under the guidance of senior engineers
- Must be able to work in a 24/7/365 SOC with a rotating on-call schedule for overnights/weekends
- Must be able to ensure compliance with local Polish labor regulations regarding shift work and on-call periods
- Must be able to escalate complex or novel incidents to senior engineers
- Must be able to contribute to detection content (detections-as-code) with review from senior team members
- Must be able to help improve security defenses
- Must be able to keep runbooks and SOPs accurate and up to date
- Must be able to stay effective in high-pressure situations
- Must be able to work with and interpret data and turn it into actionable insights
- Must be able to collaborate with threat intelligence and detection engineering teams
- Must be able to build your skills across the threat landscape, security tooling, and CoreWeave's environment
- Must be able to perform triage, escalation, and first-line incident response on day-to-day security events
- Must be able to contribute to our detection and response capabilities under the guidance of senior engineers
- Must be able to work in a 24/7/365 SOC with a rotating on-call schedule for overnights/weekends
- Must be able to ensure compliance with local Polish labor regulations regarding shift work and on-call periods
- Must be able to escalate complex or novel incidents to senior engineers
- Must be able to contribute to detection content (detections-as-code) with review from senior team members
- Must be able to help improve security defenses
- Must be able to keep runbooks and SOPs accurate and up to date
- Must be able to stay effective in high-pressure situations
- Must be able to work with and interpret data and turn it into actionable insights
- Must be able to collaborate with threat intelligence and detection engineering teams
- Must be able to build your skills across the threat landscape, security tooling, and CoreWeave's environment
- Must be able to perform triage, escalation, and first-line incident response on day-to-day security events
- Must be able to contribute to our detection and response capabilities under the guidance of senior engineers
- Must be able to work in a 24/7/365 SOC with a rotating on-call schedule for overnights/weekends
- Must be able to ensure compliance with local Polish labor regulations regarding shift work and on-call periods
- Must be able to escalate complex or novel incidents to senior engineers
- Must be able to contribute to detection content (detections-as-code) with review from senior team members
- Must be able to help improve security defenses
- Must be able to keep runbooks and SOPs accurate and up to date
- Must be able to stay effective in high-pressure situations
- Must be able to work with and interpret data and turn it into actionable insights
- Must be able to collaborate with threat intelligence and detection engineering teams
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.