Senior Manager of Security Operations & Engineering
Jacobs · Kraków, Poland
Apply directly with the employer or job board. Applications are never handled here.
Location Krakow, All PL Regions, Poland Capabilities Information Technology Office Setup Hybrid Job ID #44779
Industry Enterprise Functions At Jacobs, we're challenging today to reinvent tomorrow by solving the world's most critical problems for thriving cities, resilient environments, mission-critical outcomes, operational advancement, scientific discovery and cutting-edge manufacturing, turning abstract ideas into realities that transform the world for good.
Your impact At Jacobs, we are dedicated to pushing the boundaries of innovation and delivering exceptional solutions to our clients. As a leader in our industry, we recognize the critical importance of synergies between cybersecurity, infrastructure, data, applications, and cloud technologies in today's digital landscape.
As Senior Manager of Security Operations & Engineering, you will own the overall performance of the Jacobs Security Operations function - providing technical and managerial leadership over the SOC Manager (who runs 24x7 monitoring, detection, and incident response through a team of cybersecurity analysts) and the Tier 3 Operations Engineering team (who own the SIEM platform and the underlying security technology stack). This role bridges operational security leadership with deep technical engineering oversight and is charged with modernizing SOC capabilities through the strategic integration of AI and automation, while ensuring the fundamentals of SOC operations (monitoring, triage, incident response, documentation, and metrics) remain strong day to day.
The ideal candidate is not just an operator of security tools but a builder of next-generation SOC capability - someone who can evaluate, pilot, and operationalize AI-driven detection, triage, and response capabilities while maintaining the rigor, compliance, and reliability required of a mission-critical security function.
Responsibilities:
- Lead and develop Security Operations and Security Engineering teams, ensuring effective 24/7 monitoring, incident response, escalation management, and continuous service improvement.
- Own the strategy, performance, and operational excellence of the organization's SOC, including staffing, talent development, process optimization, and service delivery metrics.
- Oversee the security technology ecosystem, including SIEM, SOAR, EDR/XDR, threat intelligence, vulnerability management, and related monitoring platforms.
- Drive detection engineering initiatives by improving detection coverage, log onboarding, content management, threat hunting capabilities, and security monitoring effectiveness.
- Define and execute the SOC automation and AI strategy, leveraging emerging technologies to improve threat detection, investigation, response, and analyst productivity.
- Serve as an escalation point for major security incidents, coordinating response efforts across security, engineering, IT, and business stakeholders.
- Establish and monitor operational KPIs, SLAs, and performance metrics to continually improve security operations and incident response outcomes.
- Manage vendor relationships, technology roadmaps, budgets, and platform investments to ensure scalable and cost-effective security operations.
- Partner closely with Security Architecture, Risk, Compliance, Engineering, and Data teams to maintain strong security controls, governance, and regulatory readiness.
- Stay informed on emerging cyber threats, industry trends, and AI advancements, driving innovation across security operations. Here's what you'll need
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field.
- 8+ years of experience in Security Operations, Incident Response, Security Engineering, or Cyber Defense, including leadership experience managing operational and/or engineering teams.
- Proven experience leading 24/7 SOC environments and overseeing both security analysts and engineering-focused teams.
- Deep expertise with SIEM platforms such as Splunk, Microsoft Sentinel, QRadar, Google Chronicle, or Exabeam, including administration, architecture, and detection content development.
- Strong knowledge of security operations technologies including SOAR, EDR/XDR, NDR, IDS/IPS, threat intelligence platforms, vulnerability management solutions, and cloud security tooling.
- Solid understanding of incident response methodologies, threat hunting, detection engineering, MITRE ATT&CK, and security frameworks such as NIST and ISO 27001.
- Experience implementing security automation and orchestration initiatives to improve operational efficiency and response effectiveness.
- Experience defining technology roadmaps, managing vendors, budgets, and enterprise security platforms.
- Excellent stakeholder management and communication skills, with the ability to translate technical concepts into business impact and executive-level reporting.
- Strong leadership capabilities with experience mentoring teams, driving organizational change, and fostering a culture of continuous improvement.
- Experience working in complex, global, or highly regulated enterprise environments.
Nice to have:
- Experience implementing AI and machine learning capabilities within security operations, including anomaly detection, AI-assisted investigations, automated threat triage, or intelligent response workflows.
- Familiarity with generative AI and LLM-based security use cases, including analyst copilots, investigation summarization, natural-language querying, and automated reporting.
- Understanding of AI governance, model risk, explainability, data privacy, and security-specific AI threats such as prompt injection or data poisoning.
- Relevant certifications such as CISSP, CISM, GIAC, GSOC, Splunk, Microsoft Sentinel (SC-200), cloud security certifications (AWS/Azure/GCP), or project/program management certifications (PMP, Agile/Scrum).
We offer:
- Rewarding employment - f****ull-time employment with a salary that matches your qualifications
- Hybrid work model - enjoy the flexibility of working mainly from home
- Flexible hours - start your day anytime between 7:30 and 10:00 AM
- Comprehensive benefits, including Lux Med medical care, psychological support, life insurance, My Benefit cafeteria system, Multisport card co-financing, and a car/bike park sharing system
- Co-financed holidays - enjoy "Wczasy pod Gruszą" for a well-deserved break
- Global projects - engage in exciting international projects
- Inclusive networks - join our diverse employee networks like Women's Network, OneWorld, PRISM, Careers Network, Green Team, SpeakUp, Collectively, and more
- Continuous learning - participate in our Graduate Development Program, Learners’ Community, and self-learning platforms
- Language courses - enhance your skills with courses in English, German, and Polish
We know that if we are inclusive, we’re more connected, and we’re more creative. We accept people for who they are. Find out more about life at Jacobs.
As a Disability Confident employer, we will interview all disabled applicants who meet the criteria for a vacancy.
If you require further support or reasonable adjustments with regards to the recruitment process (for example, you require the application form in a different format), please contact the team recruitmentpoland@jacobs.com
#LI-KK4
Your application experience is important to us, and we’re keen to adapt to make every interaction even better. If you require further support or reasonable adjustments with regards to the recruitment process (for example, you require the application form in a different format), please contact the team via Careers Support.
Keep looking
500+ English-friendly jobs in Kraków
Every one checked for language requirements, updated daily.