Ernst and Young

SIEM SOAR Engineer

Ernst and Young
Apply
22 days ago
Warsaw, PolandMid Level

Responsibilities

  • Design and implement enterprise SIEM architectures and lead deployments of CrowdStrike NG-SIEM and Splunk.
  • Onboard security data sources using native ingestion methods and third-party tools such as Cribl and Apache NiFi.
  • Create detection logic, correlation rules, dashboards, automated queries, and SIEM/SOAR use cases.
  • Design and implement SOAR automations and lead deployments of XSOAR, CrowdStrike Fusion, and Splunk SOAR.
  • Integrate SIEM platforms and security technologies into SOAR ecosystems using APIs and automation frameworks.
  • Fine-tune response workflows and collaborate with SOC teams to improve detection coverage, threat visibility, and incident response.
  • Conduct platform health assessments, recommend improvements, and support upgrades, migrations, and cybersecurity transformation initiatives.
  • Prepare technical documentation, operating procedures, and architecture diagrams, and advise clients on security best practices and platform optimization.
  • Participate in projects involving XDR, Security DevOps, AI Security, Cloud Security, and SASE/SSE technologies.

Requirements

  • At least 4 years of experience in cybersecurity engineering, security operations, detection engineering, or security consulting.
  • Hands-on experience with at least one of CrowdStrike NG-SIEM, Splunk, XSOAR, Cribl, or Apache NiFi.
  • Strong understanding of cybersecurity operations, threat detection principles, incident detection and response, network security, and common attack techniques.
  • Experience with SIEM, SOAR, data ingestion, SOC technologies, security-technology integrations, and APIs.
  • Knowledge of Windows, Linux, and cloud environments, with the ability to analyze security events and design detection logic.
  • Strong communication and stakeholder-management skills.
  • Very good command of English and Polish at B2/C1 level.
  • Preferred qualifications include security architecture and large-scale deployment experience, Azure/AWS/GCP cloud-security experience, XDR and detection-engineering knowledge, AI security and governance experience, SASE/SSE knowledge, PowerShell and Python scripting, and certifications such as CrowdStrike, Microsoft Security, Splunk, CISSP, GCIH, GCIA, or Security+.

Benefits

  • Participation in complex international cybersecurity implementation and transformation projects with exposure to enterprise cybersecurity tools and platforms.
  • Personalized training, learning paths, professional development programs, and support obtaining recognized qualifications and certificates.
  • Flexible hybrid and remote working options depending on project requirements.
  • Career counseling, EY Badges, and the opportunity to earn an MBA title from Hult International School of Business.
  • Free psycho-educational consultations and access to personal-development activities.
  • Benefits may include private healthcare with preventive examinations, life insurance, tickets, team sports, and sports cards.
  • Roles are available in Warsaw, Lodz, Wroclaw, Gdansk, and other EY offices in Poland.

Tech Stack

Categories

Ernst and Young

About Ernst and Young

10,000+ employees

Ernst & Young (EY) provides audit/assurance, tax, consulting, strategy and transactions services to enterprises, financial institutions, and public‑sector clients. Structured as a global network of partner‑owned member firms, it sells professional services on a fee basis, including a dedicated Financial Services Organization for banking, insurance, and capital markets. Headquartered in London, EY was formed in 1989 from the merger of Ernst & Whinney and Arthur Young, and operates in 150+ countries.

Contact me