Gainsight
Lead Security Operations Engineer
Part remote, part office, you need to live within commuting distance of a named location.
Hybrid · POL - Wrocław
Employer listed it 3 weeks ago · Added yesterday
Been open since 3 weeks ago, still checked daily, but it has been live a while.
Salary
$25,000–$28,500 a month
Location
Hybrid · POL - Wrocław
Timezone
Not stated
Contract
Full-time
Experience
Lead
Category
Software
Published by the employer
Remote flexibility
Hybrid
This role is only partly remote, the employer expects time in the office around POL - Wrocław, Hybrid, so you need to live within commuting distance.
What the employer says
- Source listing states candidate location: "POL - Wrocław, Hybrid"
- Listing mentions "Hybrid"
What Nomaders makes of it
- Not suitable if you plan to move between countries
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
We’re building the AI-driven future of customer success, from retention to growth!
We’re building the AI-driven future of customer success, from retention to growth! Gainsight is the AI-powered retention engine behind the world’s most customer-centric companies. The Gainsight CustomerOS platform orchestrates the customer journey from onboarding to outcomes to advocacy. More than 2,000 companies trust Gainsight’s applications and AI agents to drive learning, adoption, community connection, and success for their customers. To explore how our suite of solutions is shaping the future of customer success, check out the link .
About This Role:
We’re looking for a full-time Lead Security Operations Engineer to join our Security team reporting to the Senior Manager, AI Response and Threat. This role is a hybrid role based out of Wroclaw, Poland location.
In this role, you'll play a key role in maturing our security operations program by owning detection strategy, leading response to major incidents, and mentoring the analysts and engineers on the team. This is a great opportunity for someone who thrives in a fast-growing, cloud-first environment and enjoys working cross-functionally with teams like DevOps, Engineering, and IT. The ideal candidate brings strong skills in incident response leadership, detection engineering across SIEM, EDR, and SOAR platforms, and cloud security architecture.
What You'll Do:
Experienced in owning complex or high-severity incidents end-to-end, from initial triage through containment, remediation, and post-incident review, while keeping stakeholders informed throughout
Deep familiarity with security considerations across AWS, Azure, or GCP environments, including how detection and response strategies need to adapt to cloud-native infrastructure
Lead incident response for significant security events: scoping and containment through to post-incident review. You will conduct host, network, and memory forensics yourself and produce clear, accurate reporting for both technical and non-technical stakeholders.
Comfortable working closely with DevOps and Engineering teams to embed security controls directly into infrastructure, CI/CD pipelines, and system design, rather than layering security on after the fact
Invested in developing the skills and judgment of analysts and engineers on the team, helping the broader group operate with greater independence and technical depth over time
Able to translate complex technical findings into clear, actionable insight for executive leadership, customers, or other non-technical stakeholders, especially under the pressure of an active incident
Experienced in assessing, selecting, and integrating security tools (SIEM, EDR, SOAR, cloud-native platforms) in a way that improves coverage without adding unnecessary complexity or cost
This role may require occasional travel (up to 10-20%) for team meetings, training, or company events. This is not a complete list of responsibilities, and the scope of the role may evolve with the needs of the team and business.
What We're Looking For:
6+ years of experience in security operations, with progressive responsibility across triage, incident response, and detection engineering
Proven experience leading or mentoring a team, formally or informally, including technical guidance and coaching
Deep expertise with SIEM, EDR, and SOAR platforms, including hands-on rule-writing, tuning, and automation development
Strong incident response leadership experience, including managing complex or high-severity incidents end-to-end
Solid understanding of cloud security architecture (AWS, Azure, or GCP), and experience working with DevOps and Engineering to embed security into CI/CD pipelines and infrastructure
Scripting or automation proficiency (Python, PowerShell, or similar) to build and scale response workflows
Deep familiarity with attacker tactics and techniques (MITRE ATT&CK) and how to translate them into detection logic
Excellent communication skills, with the ability to brief executives and technical teams alike during incidents and planning discussions
Nice-to-have skills or experience:
Requirements
- ·Hands-on experience with cloud-native detection and posture tools (e.g., AWS GuardDuty, Azure Sentinel, Wiz, Prisma Cloud)
- ·Familiarity with container and orchestration security (Docker, Kubernetes) and associated attack surfaces
- ·Experience with threat intelligence platforms and proactive threat hunting using frameworks like MITRE ATT&CK or Sigma rules
- ·Exposure to purple team or adversary simulation exercises (e.g., Atomic Red Team, Caldera) to validate detection coverage
- ·Relevant certifications (e.g., GCIH, GCFA, GCTI, CISSP, OSCP)
Benefits
No benefits package published with this listing. Ask about it at first interview.
How to apply
- 1Check the flexibility label above, hybrid, matches where you plan to live and work.
- 2Tailor your CV to the role at Gainsight, mentioning your remote working experience.
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 1d ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
$25,000–$28,500 a month · You'll be taken to the employer's careers page.