Remote job
Security Operations Engineer
Job details
About this role
Role overview Poland-based contract role supporting a strategic security program that onboards key applications into enhanced monitoring and detection capabilities. Work sits at the intersection of SIEM engineering, threat modelling, and security operations, with a strong focus on detection accuracy and regulatory alignment to DORA milestones by the end of 2026. Delivered remotely on a B2B contract basis.
Responsibilities - Design, build, and tune SIEM detection rules with a focus on Microsoft Sentinel. - Develop and execute test cases for detection logic and automate validation through scripting. - Support onboarding of critical applications into the security monitoring ecosystem. - Collaborate with application teams to define logging requirements and detection use cases. - Facilitate workshops with stakeholders to align on threat scenarios and security capabilities. - Produce documentation covering detection logic, threat models, and validation results, and partner with SOC and red teams to improve alert fidelity and incident response.
Requirements - Hands-on experience with SIEM platforms, with strong preference for Microsoft Sentinel. - Track record creating, tuning, and testing detection rules. - Proficiency in Python, PowerShell, Bash, or similar for automation use cases. - Strong English communication skills with the confidence to lead stakeholder workshops. - Understanding of Azure, AWS, Windows, Linux, and database environments such as SQL and Oracle. - Ability to work independently in a dynamic, high-volume onboarding environment.
Nice to have - Experience with threat modelling and defining threat profiles. - Familiarity with DORA or other regulatory frameworks in financial services.
Benefits and work setup - Fully remote delivery from Poland on a B2B contract. - Flexible collaboration model with exposure to diverse consulting projects.