9 hours ago
Kraków, PolandSenior
Responsibilities
- Perform Tier 2 monitoring, detection, triage, and incident response in a 24x7 security operations function.
- Develop security operations metrics and KPIs, including MTTD, MTTR, alert volume and fidelity, coverage, and program health reporting.
- Improve detection logic, playbooks, and automation with detection engineering and threat intelligence teams.
- Act as an escalation point and incident commander for high-severity security incidents.
- Coordinate with Threat Intelligence, Detection Engineering, IT, Legal, and Product/Engineering teams.
- Manage outsourced or co-managed CDU/MSSP partners and ensure SLA and quality standards.
- Evaluate SIEM, SOAR, EDR, XDR, and ticketing tools and increase automation adoption.
- Own CDU audit, compliance, and customer trust requirements, including SOC 2, ISO 27001, and FedRAMP as applicable.
- Maintain incident response runbooks, tabletop exercises, and post-incident review processes.
- Participate in an on-call rotation and provide leadership during major security events.
- Lead, mentor, hire, develop, and retain security professionals.
Requirements
- At least 5 years of experience in security operations, incident response, or a related security discipline.
- At least 2 years of people-management or team-lead experience.
- Experience scaling a 24x7 CDU function in-house, hybrid, or through MSSP oversight.
- Strong technical grounding in SIEM/SOAR, EDR/XDR, network and cloud security monitoring, and MITRE ATT&CK.
- Experience leading incident response for significant security events and coordinating with legal, communications, and executive stakeholders.
- Experience hiring, developing, and retaining security talent.
- Ability to communicate technical details in risk-based language for non-technical leaders.
- Experience with AWS, Azure, or GCP and SaaS security operations.
- Experience in a SaaS or enterprise software company handling customer data at scale is preferred.
- Familiarity with SOC 2, ISO 27001, FedRAMP, and GDPR is preferred.
- Relevant certifications such as CISSP, GCIH, GCFA, CISM, or similar are preferred.
- Experience building or maturing threat detection and threat hunting programs is preferred.
- Python or PowerShell scripting and automation experience for SOAR workflows is preferred.
Benefits
- 20 or 26 annual leave days per year, plus one additional day per year of service up to five days.
- Private medical, health, and dental insurance for employees and dependants.
- Commuter assistance of up to 80 PLN net per month for public transportation.
- Company savings plans through PPK and PPO.
- Qualtrics Engineer Development program with engineering learning activities of up to 10% of work time each quarter.
- Wellness reimbursement of up to 800 PLN gross per quarter and Multispot card options.
- Employee assistance, counselling, wellbeing, group life, and income protection programs.
- Experience bonus of 7000 PLN gross per year.
- Glasses and contact lens reimbursement, free office meals and refreshments, and tax-deductible expenses up to 50% depending on role.
- Hybrid work model requiring office attendance three days per week: Mondays, Thursdays, and one additional day selected by the organizational leader.
Tech Stack
Categories
About Qualtrics
Qualtrics builds an experience management platform that collects signals from surveys, digital interactions, and service channels, then applies analytics to improve customer, employee, product, and brand outcomes for large organizations. It sells cloud software and services via subscriptions to enterprises and public-sector customers; founded in 2002, the company is co-headquartered in Provo, Utah, and Seattle, Washington, and is privately held under Silver Lake ownership.
