Lead Security Operations Engineer

Posted 3 Days Ago
Be an Early Applicant
Wrocław, Dolnośląskie, POL
Hybrid
300K-342K Annually
Senior level
Software
The Role
Leads security operations by owning detection strategy, directing complex incident response, performing forensic investigations, integrating SIEM/EDR/SOAR and cloud security tools, embedding controls into infrastructure and CI/CD pipelines, and mentoring analysts and engineers. Communicates technical findings to executives and customers, improves detection coverage, and develops scalable response automation across cloud environments.
Summary Generated by Built In

We’re building the AI-driven future of customer success, from retention to growth!

We’re building the AI-driven future of customer success, from retention to growth! Gainsight is the AI-powered retention engine behind the world’s most customer-centric companies. The Gainsight CustomerOS platform orchestrates the customer journey from onboarding to outcomes to advocacy. More than 2,000 companies trust Gainsight’s applications and AI agents to drive learning, adoption, community connection, and success for their customers. To explore how our suite of solutions is shaping the future of customer success, check out the link.

About This Role:

We’re looking for a full-time Lead Security Operations Engineer to join our Security team reporting to the Senior Manager, AI Response and Threat. This role is a hybrid role based out of Wroclaw, Poland location.

In this role, you'll play a key role in maturing our security operations program by owning detection strategy, leading response to major incidents, and mentoring the analysts and engineers on the team. This is a great opportunity for someone who thrives in a fast-growing, cloud-first environment and enjoys working cross-functionally with teams like DevOps, Engineering, and IT. The ideal candidate brings strong skills in incident response leadership, detection engineering across SIEM, EDR, and SOAR platforms, and cloud security architecture.

What You'll Do:

  • Experienced in owning complex or high-severity incidents end-to-end, from initial triage through containment, remediation, and post-incident review, while keeping stakeholders informed throughout

  • Deep familiarity with security considerations across AWS, Azure, or GCP environments, including how detection and response strategies need to adapt to cloud-native infrastructure

  • Lead incident response for significant security events: scoping and containment through to post-incident review. You will conduct host, network, and memory forensics yourself and produce clear, accurate reporting for both technical and non-technical stakeholders.

  • Comfortable working closely with DevOps and Engineering teams to embed security controls directly into infrastructure, CI/CD pipelines, and system design, rather than layering security on after the fact

  • Invested in developing the skills and judgment of analysts and engineers on the team, helping the broader group operate with greater independence and technical depth over time

  • Able to translate complex technical findings into clear, actionable insight for executive leadership, customers, or other non-technical stakeholders, especially under the pressure of an active incident

  • Experienced in assessing, selecting, and integrating security tools (SIEM, EDR, SOAR, cloud-native platforms) in a way that improves coverage without adding unnecessary complexity or cost

This role may require occasional travel (up to 10-20%) for team meetings, training, or company events. This is not a complete list of responsibilities, and the scope of the role may evolve with the needs of the team and business.

What We're Looking For:

  • 6+ years of experience in security operations, with progressive responsibility across triage, incident response, and detection engineering

  • Proven experience leading or mentoring a team, formally or informally, including technical guidance and coaching

  • Deep expertise with SIEM, EDR, and SOAR platforms, including hands-on rule-writing, tuning, and automation development

  • Strong incident response leadership experience, including managing complex or high-severity incidents end-to-end

  • Solid understanding of cloud security architecture (AWS, Azure, or GCP), and experience working with DevOps and Engineering to embed security into CI/CD pipelines and infrastructure

  • Scripting or automation proficiency (Python, PowerShell, or similar) to build and scale response workflows

  • Deep familiarity with attacker tactics and techniques (MITRE ATT&CK) and how to translate them into detection logic

  • Excellent communication skills, with the ability to brief executives and technical teams alike during incidents and planning discussions

Nice-to-have skills or experience:

  • Hands-on experience with cloud-native detection and posture tools (e.g., AWS GuardDuty, Azure Sentinel, Wiz, Prisma Cloud)

  • Familiarity with container and orchestration security (Docker, Kubernetes) and associated attack surfaces

  • Experience with threat intelligence platforms and proactive threat hunting using frameworks like MITRE ATT&CK or Sigma rules

  • Exposure to purple team or adversary simulation exercises (e.g., Atomic Red Team, Caldera) to validate detection coverage

  • Relevant certifications (e.g., GCIH, GCFA, GCTI, CISSP, OSCP)

  • Working knowledge of network security architecture, including segmentation, zero trust principles, and cloud network security groups

  • Experience with vulnerability management programs, including scanning, prioritization, and remediation tracking

  • Experience working with data loss prevention (DLP) tools and insider threat detection

Why You’ll Love It Here:

Gainsight is a place where innovation is shaped through collaboration, curiosity, and a shared focus on solving real-world problems. With a growing suite of products across customer success, product experience, community, education, and AI-powered relationship intelligence, we continue to evolve with the needs of our customers. When people with diverse strengths, a strong sense of community, and true passion for our mission come together, they drive greater impact and create lasting value. What underpins it all is a culture that offers the stability, trust, and support that people need - not just to do the job, but to show up as themselves and feel connected to the work they do. Gainsters love working here for several reasons. Here are a few:

Our Compensation and Benefits: At Gainsight, we believe great work happens when teammates feel fully supported.

  • The starting base salary range for this role is PLN 25,000 - 28,500 monthly. Actual compensation may vary based on factors such as skills, experience, and location. In addition to base pay, this role is eligible for an annual bonus and participation in Gainsight’s equity program.

  • We offer a comprehensive benefits package including premium private medical care with priority appointments, Multisport Cards to support your physical well-being, and flexible remote work options. Partners can be included in both health and wellness programs. You'll also enjoy dedicated Recharge Holidays - one long weekend each quarter to relax and reset.

Our Core Values: We are guided by our values and our mission to be living proof you can win in business while being Human-First. Learn more here.

Our Growth Opportunities: From mentoring to career development opportunities, we’re passionate about helping our teammates learn, grow, and thrive.

Our Parody Videos: No explanation needed. Just watch them here!

If this sounds like the right role for you, we’d love to hear from you.

Additional Information:

We’re committed to creating an inclusive, fair, and transparent hiring process. As an equal opportunity employer, we celebrate diversity and are committed to creating a welcoming experience for all candidates.

If you require accommodations or have questions about how your personal data will be used during the hiring process, please contact [email protected].

If you’re applying for a role through an Employer of Record (EOR) or contractor arrangement, please note that employment terms and benefits are managed by the EOR or may not apply to non-EOR contractors.

Skills Required

  • 6+ years of experience in security operations, including triage, incident response, and detection engineering
  • Experience leading or mentoring a security team, formally or informally
  • Hands-on expertise with SIEM, EDR, and SOAR platforms, including rule writing, tuning, and automation
  • Experience leading complex or high-severity incidents end-to-end
  • Understanding of cloud security architecture across AWS, Azure, or GCP
  • Experience embedding security controls into CI/CD pipelines and infrastructure with DevOps and Engineering teams
  • Scripting or automation proficiency using Python, PowerShell, or similar
  • Familiarity with attacker tactics and techniques, including MITRE ATT&CK, and translating them into detection logic
  • Excellent communication skills for briefing executives and technical teams
  • Experience with cloud-native detection and posture tools such as AWS GuardDuty, Azure Sentinel, Wiz, or Prisma Cloud
  • Experience securing containers and orchestration platforms, including Docker and Kubernetes
  • Experience with threat intelligence platforms and proactive threat hunting
  • Experience with purple team or adversary simulation exercises
  • Relevant certifications such as GCIH, GCFA, GCTI, CISSP, or OSCP
  • Working knowledge of network security architecture, segmentation, zero trust, and cloud network security groups
  • Experience with vulnerability management programs
  • Experience with data loss prevention tools and insider threat detection

Gainsight Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Gainsight and has not been reviewed or approved by Gainsight.

  • Healthcare Strength Healthcare coverage is described as comprehensive, including medical, dental, and vision, and is often highlighted as a strong part of the package.
  • Leave & Time Off Breadth Time-off policies are portrayed as generous, with flexible or unlimited PTO, paid holidays, and extras like company recharge days or periodic shutdowns.
  • Parental & Family Support Parental leave and family medical leave are emphasized as generous and supportive for both maternity and paternity needs.

Gainsight Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Francisco, CA
898 Employees
Year Founded: 2009

What We Do

Gainsight’s innovative customer-centric technology is driving the future of customer success. The company’s Customer Cloud offers a powerful set of solutions focused on customer success, product experience, revenue optimization, customer experience, and customer data, that together enable businesses to put the customer at the center of everything they do.

Similar Jobs

Pfizer Logo Pfizer

Director R&D EHS Program Lead

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office or Remote
36 Locations
121990 Employees
177K-294K Annually

SailPoint Logo SailPoint

Consultant

Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Remote or Hybrid
2 Locations
2461 Employees

Capco Logo Capco

Business Analyst

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
Poland
6000 Employees

Sprout Social Logo Sprout Social

Staff Software Engineer

Marketing Tech • Social Media • Software • Analytics • Business Intelligence
Easy Apply
Remote or Hybrid
Poland
1400 Employees
29K-44K Annually

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account