← Back to all jobs
29d 4h left to apply
C

Security Operations Engineer (She/ He/ They)

Capco🌍 Remote WorldwideEstimated: $80,000 - $120,000

✨ AI Insights & Summary

This role at Capco Poland presents a fantastic opportunity to join a leading global consultancy focused on finance and energy markets, and contribute to a critical security program aimed at enhancing monitoring capabilities and ensuring regulatory compliance. You'll be at the forefront of implementing DORA requirements by 2026, working with cutting-edge SIEM technology like Microsoft Sentinel. If you're a security professional passionate about detection engineering, threat modeling, and driving operational resilience, this role offers significant impact and exposure to key regulatory frameworks.

Security Operations Engineer (DORA Focus)

About Capco Poland

Capco is a fully independent, global management and technology consultancy. For 25 years, we have combined innovative thinking with deep industry knowledge to deliver business consulting, digital transformation, and technology services to Finance and Energy markets. Our collaborative and efficient approach helps clients reduce costs and manage risk and regulatory change while increasing revenues. We are thinkers, innovators, and disruptors. We are small enough to care but large enough to matter.

Role Overview

We are seeking a highly skilled Security Operations Engineer to support the expansion of a strategic security program focused on onboarding critical applications into enhanced monitoring capabilities. In this role, you will play a key part in building and optimizing SIEM detection capabilities, supporting threat verification, and enabling regulatory alignment with DORA (Digital Operational Resilience Act) requirements by the end of 2026. You will work at the intersection of SIEM engineering, threat modeling, and security operations, contributing directly to improving detection accuracy and strengthening overall security posture.

Key Responsibilities

  • Detection Engineering: Design, build, and optimize SIEM detection rules (with a focus on Microsoft Sentinel)
  • Testing & Automation: Develop and execute test cases for detection logic; automate validation processes using scripting
  • Application Onboarding: Support onboarding of critical applications into the security monitoring ecosystem
  • Requirements Gathering: Collaborate with application teams to define logging requirements and detection use cases
  • Workshop Facilitation: Lead and moderate workshops with stakeholders to align on threat scenarios and security capabilities
  • Technical Documentation: Produce clear and comprehensive documentation covering detection logic, threat models, and validation results
  • Collaboration: Work closely with SOC, engineering, and red teams to enhance alert fidelity and incident response effectiveness
  • Compliance Delivery: Contribute to threat verification and ensure deliverables meet ALaM program and DORA milestones

Required Skills and Experience

  • SIEM Expertise: Hands-on experience with SIEM platforms (strong preference for Microsoft Sentinel)
  • Detection Engineering: Proven track record in creating, tuning, and testing detection rules
  • Scripting & Automation: Proficiency in Python, PowerShell, Bash, or similar for automation use cases
  • Communication: Strong English communication skills with the ability to confidently lead stakeholder workshops
  • Technical Knowledge: Understanding of cloud (Azure, AWS), operating systems (Windows, Linux), and database environments (SQL, Oracle)
  • Autonomy: Ability to work independently in a dynamic, high-volume onboarding environment

Technology Stack

  • SIEM & Security: Microsoft Sentinel
  • Cloud & Infrastructure: Azure, AWS, Windows, Linux, SQL, Oracle
  • Scripting & Automation: KQL, Python, PowerShell, Bash

Nice to have

  • Experience in threat modelling and defining threat profiles
  • Familiarity with DORA or other regulatory frameworks in financial services

Important Information

We have been informed of several recruitment scams targeting the public. We strongly advise you to verify identities before engaging in recruitment related communication. All official Capco communication will be conducted via a Capco recruiter.

Offer

We offer a flexible collaboration model based on a B2B contract, with the opportunity to work on diverse projects.

#LI-REMOTE

Apply Now

This job is active but will expire soon. Click below to apply on the company's website.

Apply for this role ↗

Share Job

Know someone who would be a perfect fit? Share this opportunity.

Job Overview

Posted6/19/2026
CategoryCybersecurity
SourceJobsCollider

FAQ

Is this position remote?

The Security Operations Engineer (She/ He/ They) role is a remote opportunity. The location specified is Remote Worldwide.

What is the salary?

The salary is not explicitly stated, but is competitive and based on experience.

How do I apply?

You can apply by clicking the "Apply for this role" button above to submit your application on the hiring website.

Similar Opportunities

a

Junior SOC Analyst

accesa.euRemote Worldwide🔄 Hybrid
Competitive
Cybersecurity
View Job →
M

Vergabemanager (m/w/d) Öffentliche Ausschreibung

MY Humancapital GmbHMunich🏠 Remote
Competitive
Cybersecurity
View Job →
Plain Concepts

AI Security Governance Architect

Plain ConceptsSpain🏠 Remote
Competitive
Cybersecurity
View Job →