SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Qualtrics is seeking a Staff InfoSec Engineer to lead the Security Operations Center (SOC) team in Kraków, responsible for 24x7 monitoring, detection, triage, and incident response across the global environment. This is a hands-on leadership role where you will own day-to-day operations, build and mentor a high-performing team of security analysts and incident responders, and continuously mature detection and response capabilities to keep pace with evolving threats.
Key Responsibilities:
- Lead and manage the Security Operations Center, including 24x7 monitoring, detection, triage, and incident response functions
- Hire, coach, and develop a team of CDU (Cyber Defense Unit) analysts and incident responders; build career paths and a strong on-call/rotation culture
- Conduct hands-on technical coaching, run mock incident drills, and build skill matrices for junior analysts
- Own CDU metrics and KPIs (MTTD, MTTR, alert volume/fidelity, coverage) and report on program health to security leadership
- Drive continuous improvement of detection logic, playbooks, and automation in partnership with detection engineering and threat intelligence teams
- Serve as an escalation point and incident commander for high-severity security incidents, coordinating cross-functional response
- Partner with Threat Intelligence, Detection Engineering, IT, Legal, and Product/Engineering teams to close gaps in visibility and response
- Manage relationships with any outsourced/MSSP or co-managed CDU partners, ensuring SLAs and quality standards are met
- Evaluate and help select CDU tooling (SIEM, SOAR, EDR, XDR, ticketing) and drive adoption of automation to reduce analyst toil
- Own CDU-related audit, compliance, and customer trust requirements (e.g., SOC 2, ISO 27001, FedRAMP as applicable)
- Build and maintain incident response runbooks, tabletop exercises, and post-incident review processes
- Participate in an on-call rotation for incidents and provide leadership presence during major security events
- Shape security operations strategy, ensuring alignment with organizational goals
- Evaluate and implement cutting-edge security tools, techniques, and automation
- Build strong cross-functional partnerships and foster a collaborative environment
The role offers opportunities to participate in leading security conferences, thought leadership initiatives, and industry working groups; gain direct exposure to executive-level decision-making; and expand your leadership toolkit by managing skilled security professionals.
Qualtrics operates a hybrid work model with three days per week in the office (Mondays, Thursdays, plus one day selected by your organizational leader).
REQUIREMENTS:
Required:
- 7+ years in security operations, incident response, or a related security discipline, including 4+ years in a people-management or team-lead role
- Demonstrated experience running or scaling a 24x7 CDU function, whether in-house, hybrid, or via MSSP oversight
- Strong technical grounding in SIEM/SOAR platforms, EDR/XDR, network and cloud security monitoring, and the MITRE ATT&CK framework
- Experience leading incident response for significant security events, including coordination with legal, communications, and executive stakeholders
- Track record of hiring, developing, and retaining security talent
- Excellent communication skills — able to translate technical detail into risk-based language for non-technical leaders
- Experience with cloud environments (AWS, Azure, or GCP) and SaaS security operations
Nice to Have:
- Experience in a SaaS or enterprise software company handling customer data at scale
- Familiarity with compliance frameworks relevant to Qualtrics' customer base (SOC 2, ISO 27001, FedRAMP, GDPR)
- Relevant certifications (CISSP, GCIH, GCFA, CISM, or similar)
- Experience building or maturing threat detection and threat hunting programs
- Background in scripting/automation (Python, PowerShell) to support SOAR workflows