SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff InfoSec Engineer

Qualtrics - Krakow, Poland - Hybrid - posted 2026-09-24

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Qualtrics is seeking a Staff InfoSec Engineer to lead the Security Operations Center (SOC) team in Kraków, responsible for 24x7 monitoring, detection, triage, and incident response across the global environment. This is a hands-on leadership role where you will own day-to-day operations, build and mentor a high-performing team of security analysts and incident responders, and continuously mature detection and response capabilities to keep pace with evolving threats. Key Responsibilities: - Lead and manage the Security Operations Center, including 24x7 monitoring, detection, triage, and incident response functions - Hire, coach, and develop a team of CDU (Cyber Defense Unit) analysts and incident responders; build career paths and a strong on-call/rotation culture - Conduct hands-on technical coaching, run mock incident drills, and build skill matrices for junior analysts - Own CDU metrics and KPIs (MTTD, MTTR, alert volume/fidelity, coverage) and report on program health to security leadership - Drive continuous improvement of detection logic, playbooks, and automation in partnership with detection engineering and threat intelligence teams - Serve as an escalation point and incident commander for high-severity security incidents, coordinating cross-functional response - Partner with Threat Intelligence, Detection Engineering, IT, Legal, and Product/Engineering teams to close gaps in visibility and response - Manage relationships with any outsourced/MSSP or co-managed CDU partners, ensuring SLAs and quality standards are met - Evaluate and help select CDU tooling (SIEM, SOAR, EDR, XDR, ticketing) and drive adoption of automation to reduce analyst toil - Own CDU-related audit, compliance, and customer trust requirements (e.g., SOC 2, ISO 27001, FedRAMP as applicable) - Build and maintain incident response runbooks, tabletop exercises, and post-incident review processes - Participate in an on-call rotation for incidents and provide leadership presence during major security events - Shape security operations strategy, ensuring alignment with organizational goals - Evaluate and implement cutting-edge security tools, techniques, and automation - Build strong cross-functional partnerships and foster a collaborative environment The role offers opportunities to participate in leading security conferences, thought leadership initiatives, and industry working groups; gain direct exposure to executive-level decision-making; and expand your leadership toolkit by managing skilled security professionals. Qualtrics operates a hybrid work model with three days per week in the office (Mondays, Thursdays, plus one day selected by your organizational leader). REQUIREMENTS: Required: - 7+ years in security operations, incident response, or a related security discipline, including 4+ years in a people-management or team-lead role - Demonstrated experience running or scaling a 24x7 CDU function, whether in-house, hybrid, or via MSSP oversight - Strong technical grounding in SIEM/SOAR platforms, EDR/XDR, network and cloud security monitoring, and the MITRE ATT&CK framework - Experience leading incident response for significant security events, including coordination with legal, communications, and executive stakeholders - Track record of hiring, developing, and retaining security talent - Excellent communication skills — able to translate technical detail into risk-based language for non-technical leaders - Experience with cloud environments (AWS, Azure, or GCP) and SaaS security operations Nice to Have: - Experience in a SaaS or enterprise software company handling customer data at scale - Familiarity with compliance frameworks relevant to Qualtrics' customer base (SOC 2, ISO 27001, FedRAMP, GDPR) - Relevant certifications (CISSP, GCIH, GCFA, CISM, or similar) - Experience building or maturing threat detection and threat hunting programs - Background in scripting/automation (Python, PowerShell) to support SOAR workflows

Similar roles