
SIEM SOAR Engineer
Ernst and Young22 days ago
Warsaw, PolandMid Level
Responsibilities
- Design and implement enterprise SIEM architectures and lead deployments of CrowdStrike NG-SIEM and Splunk.
- Onboard security data sources using native ingestion methods and third-party tools such as Cribl and Apache NiFi.
- Create detection logic, correlation rules, dashboards, automated queries, and SIEM/SOAR use cases.
- Design and implement SOAR automations and lead deployments of XSOAR, CrowdStrike Fusion, and Splunk SOAR.
- Integrate SIEM platforms and security technologies into SOAR ecosystems using APIs and automation frameworks.
- Fine-tune response workflows and collaborate with SOC teams to improve detection coverage, threat visibility, and incident response.
- Conduct platform health assessments, recommend improvements, and support upgrades, migrations, and cybersecurity transformation initiatives.
- Prepare technical documentation, operating procedures, and architecture diagrams, and advise clients on security best practices and platform optimization.
- Participate in projects involving XDR, Security DevOps, AI Security, Cloud Security, and SASE/SSE technologies.
Requirements
- At least 4 years of experience in cybersecurity engineering, security operations, detection engineering, or security consulting.
- Hands-on experience with at least one of CrowdStrike NG-SIEM, Splunk, XSOAR, Cribl, or Apache NiFi.
- Strong understanding of cybersecurity operations, threat detection principles, incident detection and response, network security, and common attack techniques.
- Experience with SIEM, SOAR, data ingestion, SOC technologies, security-technology integrations, and APIs.
- Knowledge of Windows, Linux, and cloud environments, with the ability to analyze security events and design detection logic.
- Strong communication and stakeholder-management skills.
- Very good command of English and Polish at B2/C1 level.
- Preferred qualifications include security architecture and large-scale deployment experience, Azure/AWS/GCP cloud-security experience, XDR and detection-engineering knowledge, AI security and governance experience, SASE/SSE knowledge, PowerShell and Python scripting, and certifications such as CrowdStrike, Microsoft Security, Splunk, CISSP, GCIH, GCIA, or Security+.
Benefits
- Participation in complex international cybersecurity implementation and transformation projects with exposure to enterprise cybersecurity tools and platforms.
- Personalized training, learning paths, professional development programs, and support obtaining recognized qualifications and certificates.
- Flexible hybrid and remote working options depending on project requirements.
- Career counseling, EY Badges, and the opportunity to earn an MBA title from Hult International School of Business.
- Free psycho-educational consultations and access to personal-development activities.
- Benefits may include private healthcare with preventive examinations, life insurance, tickets, team sports, and sports cards.
- Roles are available in Warsaw, Lodz, Wroclaw, Gdansk, and other EY offices in Poland.
About Ernst and Young
Ernst & Young (EY) provides audit/assurance, tax, consulting, strategy and transactions services to enterprises, financial institutions, and public‑sector clients. Structured as a global network of partner‑owned member firms, it sells professional services on a fee basis, including a dedicated Financial Services Organization for banking, insurance, and capital markets. Headquartered in London, EY was formed in 1989 from the merger of Ernst & Whinney and Arthur Young, and operates in 150+ countries.