MENU
  • Remote Jobs
  • Companies
  • Go Premium
  • Job Alerts
  • Post a Job
  • Log in
  • Sign up
Working Nomads logo Working Nomads
  • Remote Jobs
  • Companies
  • Post Jobs
  • Go Premium
  • Get Free Job Alerts
  • Log in

Security Operations Engineer

Apollo.io

Full-time
Poland
security
operations
engineer
python
aws
Apply for this position

**This is a Permanent role ('Umowa o pracę') and not a B2B contract**

Role Overview

The Security Operations Engineer is a senior individual contributor responsible for detecting, investigating, and responding to security threats across Apollo’s cloud-native and SaaS environments. This role requires strong technical depth, independent judgment, and ownership of complex security investigations from intake through resolution.

This role operates in a fully remote environment and emphasizes clear written communication, operational rigor, and effective collaboration.

Key Responsibilities

Incident Detection, Investigation & Response

  • Monitor, triage, and investigate security alerts and events across cloud infrastructure, SaaS applications, and corporate systems.

  • Conduct end-to-end security investigations, including scoping, containment, eradication, recovery, and documentation.

  • Own investigations independently while collaborating effectively during high-severity incidents.

SIEM, Detection & Workflow Engineering

  • Configure and maintain SIEM detections in Panther, including use cases, correlation rules, alert logic, and tuning.

  • Onboard, validate, and maintain log sources to ensure visibility, accuracy, and reliability.

  • Design and improve investigation and response workflows to streamline triage, escalation, and resolution.

  • Leverage AI-assisted tools to accelerate alert analysis, enrichment, and investigation efficiency.

Threat Hunting & Proactive Security

  • Perform proactive threat-hunting activities to identify malicious or anomalous behavior not surfaced by existing detections.

  • Investigate abuse, fraud, account compromise, and automation misuse scenarios in close collaboration with Fraud teams.

  • Identify detection gaps and propose, implement, and validate improvements.

Automation, Coding & Tooling

  • Build scripts, automations, and tools to reduce manual work and improve response speed and consistency.

  • Use Python extensively for analysis, automation, and internal tooling; Ruby experience is a plus.

  • Contribute to internal detection frameworks, tooling, and shared libraries.

Documentation & Continuous Improvement

  • Produce clear, high-quality documentation for incidents, investigations, and post-incident reviews.

  • Contribute to runbooks, playbooks, and operational standards.

  • Share knowledge, review peer work, and mentor other engineers.

Required Skills & Experience

  • 5+ years of experience in Security Operations, Incident Response, or Security Engineering.

  • Hands-on experience with SIEM platforms (experience with Panther is highly valued), log analysis, and detection engineering.

  • Experience investigating security incidents in cloud-native environments (GCP preferred; AWS and Azure also relevant) and SaaS applications.

  • Experience automating security workflows and investigations.

  • Proficiency in Python; familiarity with Ruby preferred.

  • Ability to operate independently, prioritize effectively, and make sound technical decisions under pressure.

Preferred Qualifications

  • Experience using AI or ML-powered security tools for detection, investigation, or response.

  • Familiarity with vulnerability management concepts and remediation workflows.

  • Relevant certifications such as GCIA, GCIH, GCED, AWS / GCP Security certifications, or Security+.

  • Prior experience working in fully remote, distributed teams.

Apply for this position
Bookmark Report

About the job

Full-time
Poland
Senior Level
Posted 2 hours ago
security
operations
engineer
python
aws

Apply for this position

Bookmark
Report
Enhancv advertisement
+ 1,284 new jobs added today
30,000+
Remote Jobs

Don't miss out — new listings every hour

Join Premium

Security Operations Engineer

Apollo.io

**This is a Permanent role ('Umowa o pracę') and not a B2B contract**

Role Overview

The Security Operations Engineer is a senior individual contributor responsible for detecting, investigating, and responding to security threats across Apollo’s cloud-native and SaaS environments. This role requires strong technical depth, independent judgment, and ownership of complex security investigations from intake through resolution.

This role operates in a fully remote environment and emphasizes clear written communication, operational rigor, and effective collaboration.

Key Responsibilities

Incident Detection, Investigation & Response

  • Monitor, triage, and investigate security alerts and events across cloud infrastructure, SaaS applications, and corporate systems.

  • Conduct end-to-end security investigations, including scoping, containment, eradication, recovery, and documentation.

  • Own investigations independently while collaborating effectively during high-severity incidents.

SIEM, Detection & Workflow Engineering

  • Configure and maintain SIEM detections in Panther, including use cases, correlation rules, alert logic, and tuning.

  • Onboard, validate, and maintain log sources to ensure visibility, accuracy, and reliability.

  • Design and improve investigation and response workflows to streamline triage, escalation, and resolution.

  • Leverage AI-assisted tools to accelerate alert analysis, enrichment, and investigation efficiency.

Threat Hunting & Proactive Security

  • Perform proactive threat-hunting activities to identify malicious or anomalous behavior not surfaced by existing detections.

  • Investigate abuse, fraud, account compromise, and automation misuse scenarios in close collaboration with Fraud teams.

  • Identify detection gaps and propose, implement, and validate improvements.

Automation, Coding & Tooling

  • Build scripts, automations, and tools to reduce manual work and improve response speed and consistency.

  • Use Python extensively for analysis, automation, and internal tooling; Ruby experience is a plus.

  • Contribute to internal detection frameworks, tooling, and shared libraries.

Documentation & Continuous Improvement

  • Produce clear, high-quality documentation for incidents, investigations, and post-incident reviews.

  • Contribute to runbooks, playbooks, and operational standards.

  • Share knowledge, review peer work, and mentor other engineers.

Required Skills & Experience

  • 5+ years of experience in Security Operations, Incident Response, or Security Engineering.

  • Hands-on experience with SIEM platforms (experience with Panther is highly valued), log analysis, and detection engineering.

  • Experience investigating security incidents in cloud-native environments (GCP preferred; AWS and Azure also relevant) and SaaS applications.

  • Experience automating security workflows and investigations.

  • Proficiency in Python; familiarity with Ruby preferred.

  • Ability to operate independently, prioritize effectively, and make sound technical decisions under pressure.

Preferred Qualifications

  • Experience using AI or ML-powered security tools for detection, investigation, or response.

  • Familiarity with vulnerability management concepts and remediation workflows.

  • Relevant certifications such as GCIA, GCIH, GCED, AWS / GCP Security certifications, or Security+.

  • Prior experience working in fully remote, distributed teams.

Working Nomads

Post Jobs
Premium Subscription
Sponsorship
Reviews
Job Alerts

Job Skills
Jobs by Location
Jobs by Experience Level
API
FAQ
Privacy policy
Terms and conditions
Contact us
About us

Jobs by Category

Remote Administration jobs
Remote Consulting jobs
Remote Customer Success jobs
Remote Development jobs
Remote Design jobs
Remote Education jobs
Remote Finance jobs
Remote Legal jobs
Remote Healthcare jobs
Remote Human Resources jobs
Remote Management jobs
Remote Marketing jobs
Remote Sales jobs
Remote System Administration jobs
Remote Writing jobs

Jobs by Position Type

Remote Full-time jobs
Remote Part-time jobs
Remote Contract jobs

Jobs by Region

Remote jobs Anywhere
Remote jobs North America
Remote jobs Latin America
Remote jobs Europe
Remote jobs Middle East
Remote jobs Africa
Remote jobs APAC

Jobs by Skill

Remote Accounting jobs
Remote Assistant jobs
Remote Copywriting jobs
Remote Cyber Security jobs
Remote Data Analyst jobs
Remote Data Entry jobs
Remote English jobs
Remote Entry Level jobs
Remote Spanish jobs
Remote Project Management jobs
Remote QA jobs
Remote SEO jobs

Jobs by Country

Remote jobs Australia
Remote jobs Argentina
Remote jobs Belgium
Remote jobs Brazil
Remote jobs Canada
Remote jobs Colombia
Remote jobs France
Remote jobs Germany
Remote jobs Ireland
Remote jobs India
Remote jobs Japan
Remote jobs Mexico
Remote jobs Netherlands
Remote jobs New Zealand
Remote jobs Philippines
Remote jobs Poland
Remote jobs Portugal
Remote jobs Singapore
Remote jobs Spain
Remote jobs UK
Remote jobs USA


Working Nomads curates remote digital jobs from around the web.

© 2026 Working Nomads.