Security Operations Engineer II

UiPath UiPath · Enterprise · Bucharest, Romania · Engineering

Security Operations Engineer II role focused on threat management, incident response, and automation within an enterprise environment. The role involves end-to-end incident handling, proactive threat hunting, playbook development, and managing security tooling. It also requires experience with AI/LLM tools for security tasks and a DevOps/IaC mindset for automation.

What you'd actually do

  1. Own incidents end-to-end - from real-time triage of SIEM, EDR, network, identity, and cloud telemetry, through containment and eradication across those domains, to written and verbal communication with technical and non-technical stakeholders.
  2. Conduct root cause analysis and close the loop with Product, Engineering, Technology, Corporate and Security teams so each incident produces durable detections, controls, or playbook updates that prevent recurrence.
  3. Conduct proactive threat hunting across enterprise, and cloud telemetry to identify and mitigate threats before they manifest as incidents.
  4. Develop and maintain incident response playbooks and runbooks, and exercise them through drills and tabletops that surface gaps in readiness.
  5. Manage, tune and contribute to detection and response tooling stack (SIEM, EDR, SOAR, case management), contributing to roadmap and configuration standards. Provide technical guidance and mentorship to junior IR analysts and adjacent security teams.
  6. Automate routine SecOps tasks with a DevOps/IaC mindset and integrate security tooling via APIs, including SOAR playbooks and supporting services.

Skills

Required

  • Incident response frameworks (NIST 800-61, SANS PICERL)
  • Modern attacker TTPs, malware behavior, and MITRE ATT&CK
  • Operating system internals (Windows, Linux, macOS)
  • Networking protocols
  • Identity systems
  • Cloud platforms (AWS, Azure, or GCP)
  • Malware analysis and digital forensics methodology
  • SIEM (Sentinel, Splunk, Chronicle, Elastic)
  • EDR (Defender XDR, CrowdStrike, SentinelOne)
  • Python, PowerShell, Bash, or Node scripting
  • KQL queries or similar languages

Nice to have

  • Azure cloud platform
  • Coding agents (Claude Code, Copilot, Cursor)
  • LLM-based tools for security tasks

What the JD emphasized

  • Minimum 3 years of experience in Security Operations roles (SOC analyst, incident responder, detection engineer, threat hunter, or equivalent).
  • Demonstrated ownership of incidents end-to-end, including containment decisions and stakeholder communication.
  • Hands-on experience with at least one major SIEM (Sentinel, Splunk, Chronicle, Elastic) and at least one EDR (Defender XDR, CrowdStrike, SentinelOne).
  • Working scripting ability in one of the following: Python, PowerShell, Bash, or Node;
  • Working ability to author and tune KQL queries or similar languages for Analytics and Hunting rules.
  • Practical experience using coding agents and/or LLM tooling in a professional workflow.