Cyber Detection & Response Engineering Lead Expert
- Hiring from
- Poland
- Work type
- Remote
- Posted
- Sep 30, 2026
Tech Stack:
Security Operations & Detection
SIEM: Microsoft Sentinel, Splunk, IBM QRadar, ArcSight or similar
SOAR platforms
EDR & XDR technologies
Threat detection & monitoring solutions
Log management & security analytics platforms
Cloud Security
Microsoft Azure, AWS, GCP
Cloud-native security monitoring solutions
Frameworks & Methodologies
MITRE ATT&CK
NIST Cybersecurity Framework (NIST CSF)
Incident Response methodologies
SOC & CSIRT operating models
Scripting & Query Languages
KQL, SPL, SQL, Python, PowerShell
Other automation and scripting technologies
Required Qualifications:
Extensive experience within Cyber Detection & Response, Security Operations, Incident Response, or related cybersecurity consulting services.
Hands-on expertise across multiple CDR domains, including security monitoring, detection engineering, incident response, security automation, governance, and SOC or CSIRT transformation initiatives.
Proven experience leading cybersecurity programs, projects, workstreams, or multidisciplinary delivery teams.
Strong understanding of security operations processes, detection lifecycle management, security data management, and incident handling procedures.
Ability to design end-to-end security solutions aligned with organizational objectives, operational requirements, and cyber risk considerations.
Practical understanding of the application of AI within cybersecurity, including benefits, limitations, risks, governance requirements, validation processes, and responsible use.
Experience supporting business development activities such as proposals, RFP responses, solution architecture, effort estimation, and client presentations.
Excellent communication and stakeholder management skills, with the ability to engage effectively with both technical specialists and executive leadership.
Strong analytical thinking, problem-solving capabilities, and a continuous improvement mindset.
Professional proficiency in English (C1).
Nice to Have:
Experience implementing SOAR solutions and security workflow automation.
Knowledge of security integrations and API-based automation.
Experience with cloud-native security monitoring solutions.
Understanding of AI-enabled capabilities within SIEM, SOAR, EDR, and XDR platforms.
Familiarity with industry-recognized frameworks such as MITRE ATT&CK and NIST CSF.
Relevant cybersecurity certifications.
Previous experience in a consulting environment.
Professional proficiency in German, French, or Spanish.
Project Description:
We are seeking an experienced Cyber Detection & Response Engineering Lead Expert to join our Cybersecurity Detection & Response (CDR) practice.
In this role, you will lead the design, implementation, and continuous improvement of advanced security monitoring, detection engineering, incident response, and automation capabilities across diverse technology environments.
As a senior cybersecurity professional, you will work closely with clients, delivery teams, and stakeholders to develop scalable security operations capabilities, drive SOC/CSIRT transformations, and implement innovative detection and response solutions leveraging modern security platforms and AI-enabled technologies.
Main Responsibilities:
Design and deliver solutions across security monitoring, detection engineering, incident response, security operations, and security automation.
Lead complex Cyber Detection & Response engagements and provide technical direction to multidisciplinary delivery teams.
Assess existing SOC and CSIRT capabilities, identify improvement opportunities, and define target operating models and transformation roadmaps.
Develop and enhance threat detection capabilities through detection use cases, correlation rules, monitoring strategies, and response procedures.
Support the implementation, migration, integration, and optimization of SIEM, SOAR, EDR, XDR, and log management platforms.
Apply AI-enabled cybersecurity capabilities to improve threat detection, alert triage, investigation processes, and security automation while ensuring proper validation, governance, and human oversight.
Translate business objectives, operational challenges, and security risks into practical solution architectures and delivery plans.
Facilitate workshops, technical discussions, and executive presentations for business and technical stakeholders.
Provide mentorship and technical coaching to consultants and engineers, supporting their professional and technical development.
Contribute to proposals, RFP responses, effort estimations, solution design activities, and client-facing discussions.
Develop reusable methodologies, frameworks, accelerators, and service offerings that enhance delivery quality and consistency across projects.