Staff Security Engineer I, Poland
Indexed description
About SHEIN
SHEIN is a global online fashion and lifestyle retailer, providing an extensive range of affordable, SHEIN-branded apparel and products sourced from a global network of vendors. Since our founding in 2012, we have expanded to serve customers in over 160 countries worldwide. Our EMEA headquarters are in Dublin, and we now operate over 15 offices across the EMEA region.
At SHEIN, our culture is driven by our core values: Customer First, Take Ownership, Deliver Results, Make Change, and Celebrate Diversity. These are not just words, they are the principles that guide our work as we strive to meet the needs of our customers around the world.
Learn more about SHEIN by following us at https://careers.shein.com/ and Homepage - SHEIN Group.
Position Summary
As a SOC Security Operations Engineer, you will be part of our global security operations function, responsible for monitoring, detecting, investigating, and responding to security threats across the company's IT and business systems. You will help build and continuously improve our detection and response capabilities as part of an aligned, follow-the-sun operating model.
Key Responsibilities
- Own day-to-day security operations (SOC), building and running the mechanisms for risk identification, monitoring, alerting, response, and post-incident review, supporting 7×24 security operations coverage.
- Contribute to the security operations roadmap and standards, driving security risks into a unified operations framework covering log onboarding, detection rules, alert triage, incident response, knowledge management, and operational metrics.
- Perform continuous monitoring and triage of security alerts, with a focus on intrusion attempts, malware, anomalous logins, lateral movement, data exfiltration, and privilege abuse.
- Build and operate detection and response capabilities, including detection rules, attack samples, evaluation use cases, response SOPs, and automated remediation workflows, improving the SOC's ability to detect, analyze, and close out security incidents.
- Conduct pre-production security assessments and operational readiness checks for third-party components, open-source software, and systems going live, delivering risk conclusions, remediation recommendations, and post-launch monitoring requirements.
- Participate in intrusion detection and incident response, performing attack-chain reconstruction, impact analysis, forensics, and root-cause analysis, and driving vulnerability remediation and continuous monitoring.
- Stay current with developments in security offense/defense, threat intelligence, and detection engineering, translating them into operational detection rules, triage logic, and automation capabilities aligned to real SOC scenarios.
- Collaborate with application security, data security, platform engineering, IT, and business teams to drive the detection, classification, response, review, and knowledge capture of security incidents, continuously improving security operations maturity and metrics.
Qualifications and Experience
- Bachelor's degree or above in Cyber security, Computer Science, or a related field, with hands-on experience in security operations (SOC), incident response, or application security.
- Solid understanding of common attack techniques and defense strategies, with core SOC skills in intrusion detection, malware analysis, log analysis, and threat hunting.
- Familiarity with log and alert analysis across mainstream operating systems, network protocols, cloud platforms, and common security tooling, with the ability to distinguish real attacks from false positives.
- Proven security operations or incident response experience, able to independently perform alert analysis, attack-chain reconstruction, risk classification, remediation recommendations, post-incident reports, and detection-rule tuning.
- Working knowledge of common web security vulnerabilities, with some capability in penetration testing, code review, or interface security testing, able to assess risks in application backends, API gateways, authentication, and data flows.
- Proficiency in Python, able to write security detection scripts, log-analysis scripts, and automation/triage tools.
- Good English/Chinese reading, writing, and communication skills, able to collaborate within cross-regional (Europe / APAC) teams; comfortable with global SOC shift work or cross-time-zone collaboration.
What We Offer:
- Competitive salary;
- Globally diverse team;
- Full-time contract structure: 3-month probation, then 1-year fixed-term, followed by a permanent contract;
- Clear promotion path;
- Performance-driven yearly bonus;
- Unlimited access to company training and learning resources;
- No formal dress code — wear what makes you comfortable.
Benefits:
- Private medical care at Luxmed;
- Fully employer-funded life & health insurance at Nationale-Nederlander;
- Multisport card;
- Subsidized lunches for 1 PLN (meat, vegetarian, or Chinese options);
- 30% discount at SHEIN;
- Free parking;
- Company benefit fund;
- Employee referral program;
- Multiple team-building activities throughout the year;
- Fruits and healthy snacks at work.
Please note that pay information, including salary bands, will be shared with candidates upon invitation to the first interview.
Please note that the final salary offered within the stated range will be determined following a thorough assessment of a candidate's overall profile, including but not limited to qualifications for the role, technical and soft skills, and level of experience.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search