Employer: International Pharmaceutical Company
Location: Remotely from Poland
Working hours: 3:00 PM–11:00 PM Polish time
Cooperation model: B2B
Start date: ASAP
Recruitment process: 2-3 online interviews
For our client, a leading global biopharmaceutical company, we are looking for a Security Automation Specialist / SOAR Consultant to support security operations, automation, and incident response processes within a large international organization.
Our client operates across 70 countries and employs more than 66000 people worldwide, with approximately 2500 employees in Poland, including teams working in technology and global business functions. The company has a strong international presence, and Poland is one of its key global and regional hubs.
The role combines SOAR engineering, security automation, SIEM support, and operational consulting. We are looking for someone with around 2–3 years of relevant experience, hands-on experience with any SOAR platform, and a strong interest in developing further with Torq.
Your role is:
- Designing, maintaining, and improving automated security workflows within a SOAR environment.
- Supporting SOC and incident response processes through automation.
- Handling security-related tickets, operational requests, and workflow issues.
- Automating use cases such as phishing, malware, suspicious authentication activity, and other security alerts.
- Integrating security tools using REST APIs, webhooks, and custom connectors.
- Enriching alerts with data from SIEM, EDR, identity, ticketing, and threat intelligence platforms.
- Troubleshooting and optimizing existing security automations.
- Working with security teams to identify processes that can be automated and improved.
- Building hands-on expertise in Torq as part of the project.
Your skills and experiences:
- 2–3 years of experience in Security Operations, Security Engineering, Security Automation, SOC, or a similar area.
- Hands-on experience with at least one SOAR platform, e.g. Torq, Palo Alto XSOAR, Splunk SOAR, Tines, Swimlane, or another comparable solution.
- Torq experience is not required — practical SOAR experience and willingness to learn Torq are sufficient.
- Good understanding of SOC processes and incident response workflows.
- Experience with REST APIs, JSON, authentication mechanisms, and webhooks.
- Experience with at least one SIEM platform such as Microsoft Sentinel, Splunk, QRadar, or Elastic.
- Knowledge of EDR technologies such as CrowdStrike, Microsoft Defender for Endpoint, SentinelOne, or Carbon Black.
- Scripting skills in Python, PowerShell, or a similar language.
- Familiarity with Azure, AWS, or GCP.
- Very good communication skills and ability to work independently in an international environment.
- Fluent English.
Our client offers:
- Great opportunity for personal development in a stable and friendly large multinational company.
- Career growth and additional education.