
Security Engineer EDR
Ernst and Young11 days ago
Warsaw, PolandMid Level
Responsibilities
- Design and implement enterprise XDR architectures.
- Lead deployments of CrowdStrike Falcon XDR and Microsoft Defender XDR.
- Integrate endpoints, cloud workloads, identities, email security, and third-party security tools into XDR ecosystems.
- Develop onboarding strategies and deployment roadmaps for enterprise environments.
- Fine-tune detection logic, correlation rules, security policies, and response workflows.
- Design detection use cases, detection content, and security response automation.
- Improve detection coverage and threat visibility across complex IT environments.
- Collaborate with SOC teams to enhance threat hunting, incident response, and investigation processes.
- Design integrations using APIs and automation frameworks.
- Conduct health assessments and recommend improvements for existing security platforms.
- Support platform upgrades, migrations, and cybersecurity transformation initiatives.
- Prepare technical documentation, operating procedures, and architecture diagrams.
- Advise clients on security best practices and platform optimization.
- Participate in projects involving SIEM and security analytics, AI security, cloud security, and SASE/SSE technologies.
Requirements
- At least 4 years of experience in cybersecurity engineering, security operations, detection engineering, or security consulting.
- Hands-on experience with CrowdStrike Falcon or Microsoft Defender XDR.
- Strong understanding of cybersecurity operations and threat detection principles.
- Experience with XDR, EDR, SIEM, or SOC technologies.
- Knowledge of incident detection and response processes, network security concepts, and common attack techniques.
- Experience integrating security technologies and working with APIs.
- Knowledge of Windows, Linux, and cloud environments.
- Ability to analyze security events and design detection logic.
- Strong communication and stakeholder management skills.
- Very good command of English and Polish at B2/C1 level.
- Preferred experience designing security architectures and large-scale security deployments.
- Preferred experience with Azure, AWS, or GCP cloud security technologies.
- Preferred knowledge of SOAR and automation platforms, AI security solutions, governance frameworks, and SASE/SSE technologies such as Zscaler.
- Familiarity with PowerShell and Python scripting.
- Industry certifications such as CrowdStrike certifications, Microsoft Security certifications including SC-200, SC-100, or AZ-500, Splunk certifications, CISSP, GCIH, GCIA, or Security+ are preferred.
Benefits
- Participation in complex international cybersecurity implementation and transformation projects.
- Exposure to enterprise cybersecurity tools and a broad range of cybersecurity domains.
- Personalized training programs, learning paths, and professional development programs.
- Flexible hybrid and remote work options depending on project requirements.
- Locations include Warsaw, Łódź, Wrocław, and Gdańsk.
- Professional and financial support for recognized qualifications and certifications.
- EY Badges certification opportunities and the opportunity to earn an MBA title from Hult International School of Business.
- One-to-one career guidance through a Career Counselor.
- Free psycho-educational consultations and educational activities.
- Private healthcare with additional preventive examinations, life insurance, tickets, team sports, language learning platform, sports cards, and other benefits.