EU remote
Security Operations Engineer II
About this role
CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators to build and scale AI with confidence. Trusted by leading AI labs, startups, and global enterprises, CoreWeave combines superior infrastructure performance with deep technical expertise to accelerate breakthroughs and turn compute into capability. Founded in 2017, CoreWeave became a publicly traded company (Nasdaq: CRWV) in March 2025.
Learn more at www.coreweave.com . We're proud to be a Living Wage accredited Employer. About the role: We are seeking a Security Operations Engineer II specializing in security event triaging and incident response to join our 24x7 Security Operations team based in our Warsaw, Poland office. In this role, you will independently perform triage, escalation, and first-line incident response on day-to-day security events, and contribute to our detection and response capabilities under the guidance of senior engineers.
In this role, you will: Be part of a 24/7/365 SOC, that includes a rotating on-call schedule for overnights/weekends, ensuring compliance with local Polish labor regulations regarding shift work and on-call periods. Perform initial triage and investigation of security alerts using established playbooks and SOPs across Linux, MacOS, and Kubernetes environments, escalating complex or novel incidents to senior engineers.
Utilize and query SIEM, EDR, and other security tooling to detect, investigate, and respond to suspicious activity in real-time. Support incident response activities — analysis, containment, and remediation — and contribute to detection content (detections-as-code) with review from senior team members. Contribute findings and observations to post-incident reviews to help improve security defenses. Document investigations thoroughly and help keep runbooks and SOPs accurate and up to date.
Collaborate with threat intelligence and detection engineering teams to stay aware of emerging threats. Continuously build your skills across the threat landscape, security tooling, and CoreWeave's environment. Who You Are: Degree in Computer Science, Computer Engineering, Cyber Security, Information Technology or similar experience. 1–2+ years of experience in security operations, SOC analysis, incident response, forensics, or a related field (relevant internship and academic experience considered).