Senior Detection & Response Engineer

Job Description

Aristocrat is seeking a Senior Detection & Response Engineer to join our Security Operations team.

In this role, you will help strengthen Aristocrat's detection and response capabilities through detection engineering, security automation, and operational process improvement.

You will work within a hybrid Security Operations Center (SOC) model. You will collaborate closely with teams responsible for Security Operations, the Security Engineering group, MSSP partners, and other technical teams. Together, you will improve our ability to detect, investigate, and respond to security threats.

Please note: this role follows a hybrid working model and requires onsite attendance at our Kraków office three days per week.

What You'll Do

Detection Engineering

  • Develop, tune, and maintain detections, correlation rules, analytics, searches, and threat detection content across SIEM, EDR, identity, email, SaaS, and security monitoring platforms.
  • Identify detection gaps and develop new detection use cases to improve security coverage.
  • Improve detection quality, reduce false positives, and enhance alert fidelity.
  • Map detections and use cases to attacker techniques and security frameworks such as MITRE ATT&CK.

Security Automation

  • Design, build, and maintain security automation workflows using Tines and other approved automation platforms.
  • Build integrations using APIs, workflow automation tools, and platform-native capabilities.
  • Automate repetitive operational tasks to improve investigation and response efficiency.
  • Continuously identify opportunities to streamline security processes through automation.

Security Operations & Incident Response

  • Support security investigations and response activities through detection engineering, automation, and technical analysis.
  • Collaborate with threat analysts, MSSP partners, and incident responders to improve operational effectiveness.
  • Contribute to operational improvements that accelerate detection, investigation, and response activities.
  • Assist in measuring and improving the effectiveness of detections, automations, and operational workflows.

Collaboration & Innovation

  • Partner with Security Operations, Security Engineering, IT, and Product Security teams to improve detection and response capabilities.
  • Evaluate and adopt emerging technologies and capabilities that improve analyst efficiency and operational effectiveness.
  • Contribute to the continual evolution of Aristocrat's Security Operations program.

What We're Looking For
  • Experience improving threat detection, security operations, incident response, or related cybersecurity capabilities in a production environment. 
  • Hands-on Detection Engineering experience
  • Strong ability to create, tune, and maintain detections, searches, analytics, or threat hunting content using security-focused query languages. 
  • Experience building and maintaining security automations using Tines, SOAR platforms, or similar workflow automation technologies. 
  • Experience designing, building, or maintaining automation workflows rather than solely operating within automated environments. 
  • Experience integrating systems via APIs, automation platforms, or platform-native capabilities. 
  • Solid understanding of threat detection, security investigations, and incident response concepts expected within a Tier 3 Security Operations environment. 
  • Ability to translate operational challenges into scalable detections, automations, and workflow improvements. 
  • Strong collaboration skills and experience working across Security Operations, Engineering, IT, and MSSP environments. 

What Success Looks Like 
    • Owning and improving detection content and security analytics
    • Increasing detection coverage across the environment. 
    • Reducing operational inefficiencies through automation. 
    • Supporting Security Operations teams with effective detections and workflows. 
    • Driving measurable improvements in detection and response effectiveness. 
    • Contributing as a senior technical member of the Security Operations function. 

Compensation Philosophy

We offer a comprehensive pay and benefits package designed to stay competitive in the market, support your wellbeing, and recognise your contribution to our success. Our approach is underpinned by a pay-for-performance belief in rewarding individual impact. Your specific compensation package will be determined by factors such as your skills, experience, qualifications, and location.


Depending on your role and location, you may be eligible for annual bonuses and incentives, health and wellbeing benefits, paid time off, retirement plans, insurance coverage, and other local or statutory benefits.


Specific details about compensation and benefits for this position will be discussed during the recruitment process.