
Cyber Detection & Response Engineering Lead
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in Poland.
β’ Design and implement solutions in the areas of security monitoring, detection engineering, incident response, security operations, and security automation.
β’ Lead intricate Cyber Detection & Response projects and offer technical guidance to multidisciplinary delivery teams.
β’ Evaluate SOC and CSIRT capabilities, pinpoint areas for improvement, and establish target operating models along with transformation roadmaps.
β’ Develop and enhance threat detection abilities by creating use cases, correlation rules, monitoring strategies, and response procedures.
β’ Assist in the implementation, migration, integration, and optimization of SIEM, SOAR, EDR, XDR, and log management platforms.
β’ Utilize AI-driven cybersecurity capabilities to enhance threat detection, alert triage, investigation processes, and security automation while ensuring validation, governance, and human oversight.
β’ Convert business objectives, operational challenges, and security risks into solution architectures and implementation plans.
β’ Conduct workshops, technical discussions, and executive presentations.
β’ Mentor and provide technical coaching to consultants and engineers.
β’ Contribute to proposals, RFP responses, effort estimations, solution design, and client-facing interactions.
β’ Create reusable methodologies, frameworks, accelerators, and service offerings.
β’ Extensive background in Cyber Detection & Response, Security Operations, Incident Response, or related cybersecurity consulting services.
β’ Practical expertise in security monitoring, detection engineering, incident response, security automation, governance, and SOC or CSIRT transformation initiatives.
β’ Demonstrated ability to lead cybersecurity programs, projects, workstreams, or multidisciplinary delivery teams.
β’ Strong comprehension of security operations processes, detection lifecycle management, security data management, and incident handling procedures.
β’ Capacity to design comprehensive security solutions that align with organizational goals, operational needs, and cyber risk factors.
β’ Practical knowledge of AI applications in cybersecurity, including their benefits, limitations, risks, governance requirements, validation processes, and ethical use.
β’ Experience in supporting proposals, RFP responses, solution architecture, effort estimation, and client presentations.
β’ Exceptional communication and stakeholder management abilities.
β’ Strong analytical thinking, problem-solving skills, and a commitment to continuous improvement.
β’ Professional proficiency in English (C1).
β’ Familiarity with SIEM platforms such as Microsoft Sentinel, Splunk, IBM QRadar, ArcSight, or similar.
β’ Experience with SOAR, EDR/XDR, threat detection, log management, cloud security, and security analytics platforms.
β’ Knowledge of Microsoft Azure, AWS, or GCP.
β’ Understanding of KQL, SPL, SQL, Python, PowerShell, or other automation and scripting technologies.
β’ Nice to have: experience with SOAR implementation, security integrations and API-based automation, cloud-native monitoring, AI-enabled security capabilities, MITRE ATT&CK, NIST CSF, cybersecurity certifications, consulting experience, and proficiency in German, French, or Spanish.
β’ Comprehensive health and wellness programs.
β’ Opportunities for professional development and training.
β’ Flexible work arrangements to promote work-life balance.
β’ Collaborative and innovative work environment.
β’ Competitive compensation and performance-based bonuses.
NationsBenefits
QAVION GROUP
Weflow | getweflow.com
Travoom
Get handpicked remote jobs straight to your inbox weekly.