Remote
Lead Security Operations Engineer
About this role
We’re building the AI-driven future of customer success, from retention to growth! We’re building the AI-driven future of customer success, from retention to growth! Gainsight is the AI-powered retention engine behind the world’s most customer-centric companies. The Gainsight CustomerOS platform orchestrates the customer journey from onboarding to outcomes to advocacy. More than 2,000 companies trust Gainsight’s applications and AI agents to drive learning, adoption, community connection, and success for their customers.
To explore how our suite of solutions is shaping the future of customer success, check out the link https://www.gainsight.com. About This Role: We’re looking for a full-time Lead Security Operations Engineer to join our Security team reporting to the Senior Manager, AI Response and Threat. This role is a hybrid role based out of Wroclaw, Poland location. In this role, you'll play a key role in maturing our security operations program by owning detection strategy, leading response to major incidents, and mentoring the analysts and engineers on the team.
This is a great opportunity for someone who thrives in a fast-growing, cloud-first environment and enjoys working cross-functionally with teams like DevOps, Engineering, and IT. The ideal candidate brings strong skills in incident response leadership, detection engineering across SIEM, EDR, and SOAR platforms, and cloud security architecture. What You'll Do: - Experienced in owning complex or high-severity incidents end-to-end, from initial triage through containment, remediation, and post-incident review, while keeping stakeholders informed throughout - Deep familiarity with security considerations across AWS, Azure, or GCP environments, including how detection and response strategies need to adapt to cloud-native infrastructure - Lead incident response for significant security events: scoping and containment through to post-incident review.
You will conduct host, network, and memory forensics yourself and produce clear, accurate reporting for both technical and non-technical stakeholders. - Comfortable working closely with DevOps and Engineering teams to embed security controls directly into infrastructure, CI/CD pipelines, and system design, rather than layering security on after the fact - Invested in developing the skills and judgment of analysts and engineers on the team, helping the broader group operate with greater independence and technical depth over time - Able to translate complex technical findings into clear, actionable insight for executive leadership, customers, or other non-technical stakeholders, especially under the pressure of an active incident - Experienced in assessing, selecting, and integrating security tools (SIEM, EDR, SOAR, cloud-native platforms) in a way that improves coverage without adding unnecessary complexity or cost This role may require occasional travel (up to 10-20%) for team meetings, training, or company events.