Gainsight logo

Gainsight

Lead Security Operations Engineer

Hybrid

Part remote, part office, you need to live within commuting distance of a named location.

Hybrid · POL - Wrocław

Employer listed it 3 weeks ago · Added yesterday

Been open since 3 weeks ago, still checked daily, but it has been live a while.

Salary

$25,000–$28,500 a month

Location

Hybrid · POL - Wrocław

Timezone

Not stated

Contract

Full-time

Experience

Lead

Category

Software

Published by the employer

Remote flexibility

Hybrid

This role is only partly remote, the employer expects time in the office around POL - Wrocław, Hybrid, so you need to live within commuting distance.

What the employer says

  • Source listing states candidate location: "POL - Wrocław, Hybrid"
  • Listing mentions "Hybrid"

What Nomaders makes of it

  • Not suitable if you plan to move between countries

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

We’re building the AI-driven future of customer success, from retention to growth!

We’re building the AI-driven future of customer success, from retention to growth! Gainsight is the AI-powered retention engine behind the world’s most customer-centric companies. The Gainsight CustomerOS platform orchestrates the customer journey from onboarding to outcomes to advocacy. More than 2,000 companies trust Gainsight’s applications and AI agents to drive learning, adoption, community connection, and success for their customers. To explore how our suite of solutions is shaping the future of customer success, check out the link .

About This Role:

We’re looking for a full-time Lead Security Operations Engineer to join our Security team reporting to the Senior Manager, AI Response and Threat. This role is a hybrid role based out of Wroclaw, Poland location.

In this role, you'll play a key role in maturing our security operations program by owning detection strategy, leading response to major incidents, and mentoring the analysts and engineers on the team. This is a great opportunity for someone who thrives in a fast-growing, cloud-first environment and enjoys working cross-functionally with teams like DevOps, Engineering, and IT. The ideal candidate brings strong skills in incident response leadership, detection engineering across SIEM, EDR, and SOAR platforms, and cloud security architecture.

What You'll Do:

Experienced in owning complex or high-severity incidents end-to-end, from initial triage through containment, remediation, and post-incident review, while keeping stakeholders informed throughout

Deep familiarity with security considerations across AWS, Azure, or GCP environments, including how detection and response strategies need to adapt to cloud-native infrastructure

Lead incident response for significant security events: scoping and containment through to post-incident review. You will conduct host, network, and memory forensics yourself and produce clear, accurate reporting for both technical and non-technical stakeholders.

Comfortable working closely with DevOps and Engineering teams to embed security controls directly into infrastructure, CI/CD pipelines, and system design, rather than layering security on after the fact

Invested in developing the skills and judgment of analysts and engineers on the team, helping the broader group operate with greater independence and technical depth over time

Able to translate complex technical findings into clear, actionable insight for executive leadership, customers, or other non-technical stakeholders, especially under the pressure of an active incident

Experienced in assessing, selecting, and integrating security tools (SIEM, EDR, SOAR, cloud-native platforms) in a way that improves coverage without adding unnecessary complexity or cost

This role may require occasional travel (up to 10-20%) for team meetings, training, or company events. This is not a complete list of responsibilities, and the scope of the role may evolve with the needs of the team and business.

What We're Looking For:

6+ years of experience in security operations, with progressive responsibility across triage, incident response, and detection engineering

Proven experience leading or mentoring a team, formally or informally, including technical guidance and coaching

Deep expertise with SIEM, EDR, and SOAR platforms, including hands-on rule-writing, tuning, and automation development

Strong incident response leadership experience, including managing complex or high-severity incidents end-to-end

Solid understanding of cloud security architecture (AWS, Azure, or GCP), and experience working with DevOps and Engineering to embed security into CI/CD pipelines and infrastructure

Scripting or automation proficiency (Python, PowerShell, or similar) to build and scale response workflows

Deep familiarity with attacker tactics and techniques (MITRE ATT&CK) and how to translate them into detection logic

Excellent communication skills, with the ability to brief executives and technical teams alike during incidents and planning discussions

Nice-to-have skills or experience:

Requirements

  • ·Hands-on experience with cloud-native detection and posture tools (e.g., AWS GuardDuty, Azure Sentinel, Wiz, Prisma Cloud)
  • ·Familiarity with container and orchestration security (Docker, Kubernetes) and associated attack surfaces
  • ·Experience with threat intelligence platforms and proactive threat hunting using frameworks like MITRE ATT&CK or Sigma rules
  • ·Exposure to purple team or adversary simulation exercises (e.g., Atomic Red Team, Caldera) to validate detection coverage
  • ·Relevant certifications (e.g., GCIH, GCFA, GCTI, CISSP, OSCP)

Benefits

No benefits package published with this listing. Ask about it at first interview.

How to apply

  1. 1Check the flexibility label above, hybrid, matches where you plan to live and work.
  2. 2Tailor your CV to the role at Gainsight, mentioning your remote working experience.
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 1d ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open software roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

$25,000–$28,500 a month · You'll be taken to the employer's careers page.