Security Consulting Engineer
Cisco
- Location
- Krakow, Poland
- Work model
- On-Site
- Level
- Senior
- Posted
- 1d ago
Skills
About this role
Meet the Team: You’ll be joining the Splunk Security practice in Krakow - a group of passionate experts dedicated to solving complex security challenges. We pride ourselves on being a collaborative, mentor-heavy environment where we learn from each other as much as we learn from our customers. Whether we’re architecting a new Security Operations Center (SOC) or prototyping a new automation workflow, we tackle these problems as a team, ensuring that everyone has the support they need to succeed and grow.
Your Impact
As a Senior Software Consulting Engineer, you are the bridge between cutting-edge technology and real-world security outcomes. You will lead high-impact engagements with enterprise customers, helping them design and implement Splunk-based security programs that truly work. You will: Lead end-to-end delivery: Manage enterprise security platform deployments, including system architecture, configuration, security content development, and go-live. Design & Automate: Build automated incident response workflows using SOAR technology, integrating third-party tools like EDR, identity platforms, and ticketing systems. Develop Detection Content: Build and tune advanced threat detection rules (e.g., MITRE ATT&CK), risk-based alerting models, and compliance reporting (PCI-DSS, ISO 27001, GDPR, NIST CSF). Data Onboarding: Normali s e complex security data sources - firewalls, EDR, cloud platforms -i nto a centrali s ed monitoring environment. Strategic Advisory: Engage at the CISO and SOC manager level to align technical solutions with business security objectives and present architecture recommendations based on risk and value. Drive Adoption & Innovation: Identify underutili s ed features, integrate AI/automation to improve response velocity, and collaborate with Cisco product teams to influence future development. Knowledge Sharing: Develop reusable tools, playbooks, and documentation while mentoring junior consultants to elevate the entire practice. Pre-Sales Support: Contribute to technical scoping and the development of Statements of Work (SOW). Available for travel - up to 30% Minimum Qualifications: Bachelor's degree + 7 years of related experience, OR Master's degree + 4 years, OR PhD + 1 year, OR equivalent relevant work experience. Professional-level certification (e.g., CCNP ), DevOps /automation certification or equivalent knowledge 5+ years of hands-on software implementation experience in a customer-facing professional services role Proven technical expertise in XDR/ SIEM and monitoring platforms (e.g., Checkmk , Elasticsearch , Dynatrace, AppDynamics, IBM QRadar ), security content development, and security automation/orchestration Experience with scripting or programming (Python , Java, .Net or other ), REST APIs, and workflow automation. Experience lead ing complex customer programs and communicat ing technical recommendations to CISO, architect, and engineering audiences.
Preferred Qualifications
Certifications: Professional-level networking or security certifications (e.g., CCNP, CISSP, CEH, GIAC GCIH). Automation/DevOps: Cisco DevNet or equivalent automation certifications; experience with CI/CD pipelines, Infrastructure as Code ( IaC ), or DevSecOps practices. Splunk Expertise: Hands-on experience with Splunk Enterprise Security, Splunk SOAR/Phantom, or equivalent enterprise SIEM/SOAR platforms. (Splunk-specific certifications are a significant advantage). Background in SOC operations, incident response, threat hunting, or detection engineering. Experience delivering compliance programs (PCI-DSS, ISO 27001, NIST CSF, GDPR). Familiarity with platforms like Microsoft Sentinel, IBM QRadar , Palo Alto XSOAR, or Google Chronicle. Languages: Proficiency in an additional