Ernst and Young

Security Engineer EDR

Ernst and Young
Apply
11 days ago
Warsaw, PolandMid Level

Responsibilities

  • Design and implement enterprise XDR architectures.
  • Lead deployments of CrowdStrike Falcon XDR and Microsoft Defender XDR.
  • Integrate endpoints, cloud workloads, identities, email security, and third-party security tools into XDR ecosystems.
  • Develop onboarding strategies and deployment roadmaps for enterprise environments.
  • Fine-tune detection logic, correlation rules, security policies, and response workflows.
  • Design detection use cases, detection content, and security response automation.
  • Improve detection coverage and threat visibility across complex IT environments.
  • Collaborate with SOC teams to enhance threat hunting, incident response, and investigation processes.
  • Design integrations using APIs and automation frameworks.
  • Conduct health assessments and recommend improvements for existing security platforms.
  • Support platform upgrades, migrations, and cybersecurity transformation initiatives.
  • Prepare technical documentation, operating procedures, and architecture diagrams.
  • Advise clients on security best practices and platform optimization.
  • Participate in projects involving SIEM and security analytics, AI security, cloud security, and SASE/SSE technologies.

Requirements

  • At least 4 years of experience in cybersecurity engineering, security operations, detection engineering, or security consulting.
  • Hands-on experience with CrowdStrike Falcon or Microsoft Defender XDR.
  • Strong understanding of cybersecurity operations and threat detection principles.
  • Experience with XDR, EDR, SIEM, or SOC technologies.
  • Knowledge of incident detection and response processes, network security concepts, and common attack techniques.
  • Experience integrating security technologies and working with APIs.
  • Knowledge of Windows, Linux, and cloud environments.
  • Ability to analyze security events and design detection logic.
  • Strong communication and stakeholder management skills.
  • Very good command of English and Polish at B2/C1 level.
  • Preferred experience designing security architectures and large-scale security deployments.
  • Preferred experience with Azure, AWS, or GCP cloud security technologies.
  • Preferred knowledge of SOAR and automation platforms, AI security solutions, governance frameworks, and SASE/SSE technologies such as Zscaler.
  • Familiarity with PowerShell and Python scripting.
  • Industry certifications such as CrowdStrike certifications, Microsoft Security certifications including SC-200, SC-100, or AZ-500, Splunk certifications, CISSP, GCIH, GCIA, or Security+ are preferred.

Benefits

  • Participation in complex international cybersecurity implementation and transformation projects.
  • Exposure to enterprise cybersecurity tools and a broad range of cybersecurity domains.
  • Personalized training programs, learning paths, and professional development programs.
  • Flexible hybrid and remote work options depending on project requirements.
  • Locations include Warsaw, Łódź, Wrocław, and Gdańsk.
  • Professional and financial support for recognized qualifications and certifications.
  • EY Badges certification opportunities and the opportunity to earn an MBA title from Hult International School of Business.
  • One-to-one career guidance through a Career Counselor.
  • Free psycho-educational consultations and educational activities.
  • Private healthcare with additional preventive examinations, life insurance, tickets, team sports, language learning platform, sports cards, and other benefits.

Tech Stack

Categories

Ernst and Young

About Ernst and Young

10,000+ employees
Contact me