Threat Detection and Response Specialist
About the team
About your manager
Job description & summary
Technical Delivery (~50% of Time)
- Engage in hands-on work with SIEM (primarily Splunk, secondarily Microsoft Sentinel) including configuration, optimization, and troubleshooting.
- Develop and refine detection rules/use cases based on threat landscapes and client requirements.
- Conduct threat hunting activities by proactively searching for threats within client environments.
- Support incident response processes, including analyzing incidents and recommending remediation actions.
- Work with log management architectures, data sources, and log onboarding.
- Assess the maturity of clients' detection and response capabilities.
Client Communication (~30% of Time)
- Independently lead technical workshops and working sessions with client security teams.
- Present technical findings and recommendations with the ability to translate technical jargon into understandable conclusions.
- Participate in status meetings, discussing scope, priorities, and next steps.
- Build and maintain working relationships with client security teams.
Documentation and Business Development (~20% of Time)
- Prepare high-quality deliverables: assessment reports, solution proposals, recommendations, and roadmaps.
- Compile executive summaries and outline business impacts of technical findings.
- Assist in proposal preparation—providing technical input, labor estimation, and scope definition.
- Contribute to the internal knowledge base and aid in the development of service offerings.
What This Role Is NOT
To avoid misunderstandings:
- This is NOT a purely technical role where you'll spend all day in the console. Client communication and documentation are expected.
- This is NOT a purely consulting role where you are only working on slides. We expect hands-on technical work.
- This is NOT a SOC analyst role with rotational shifts. We work on projects, not in monitoring.
- This is NOT a "tool specialist" role focused on a single product. We require breadth and adaptability.
- This is NOT a role where you'll wait a year for something to happen. You'll be involved in projects starting from the first month.
What matters to us
- 3–6 years of experience in the field of cybersecurity (consulting experience not mandatory).
- Practical hands-on experience in at least one of the following areas: SIEM (preferably Splunk), Threat Hunting, Incident Response, Detection Engineering.
- Ability to independently analyze data, draw conclusions, and prepare technical outputs.
- Capable of presenting work results to clients (you don’t need to be a showman, but clear communication is essential).
- Proficient in English at a working level (B2+); Czech is an advantage.
- Structured thinking with the ability to break down problems into parts and design a plan of action.
- Willingness to work in a hybrid model: combining technical work, client interaction, and documentation
What will help you stand out
- Experience with Microsoft Sentinel and cloud security (Azure/AWS).
- Familiarity with SOAR platforms or automation of security processes.
- Certifications such as GIAC (GCIH, GCIA, GCDA), CompTIA CySA+, Splunk certifications, SC-200.
- Previous experience in a consulting or professional services environment.
- Knowledge of the MITRE ATT&CK framework and its practical application.
How this role will advance your career
- Deep understanding of the Threat Detection & Response (TDR) domain from both technical and business perspectives.
- Development of consulting skills such as problem structuring, stakeholder management, and presentation skills.
- Direct experience with diverse client environments and security challenges.
- A clear path to a Manager role within 2–3 years, contingent on demonstrated competencies.
- Opportunity to co-develop new service offerings and contribute to the growth of the practice
Why you’ll enjoy working here
Professional growth
that matches your ambitions and pace. Gain in months the kind of experience that can take years to build elsewhere.
- Fair pay with no gaps. We are among the few companies in the Czech Republic certified for
Equal Pay.
- A flexible benefits programme with
55,000 points
35 days of paid time off
, including three well-being days and two additional days off at the end of the year.
- An opportunity to give back to the community with one paid
volunteering day
every year.
- The chance to
work from one of PwC’s international offices
(available from the Senior Associate level).
- We support your learning and development journey: Benefit from
training and certifications
A buddy programme,
regular feedback, and access to a coach who can support your professional development and career path.
- Extensive
well-being support
An ultrabook and an iPhone
with unlimited data.
- Social events and Away Days .
Check us out on: Cyber & Privacy | Czech Republic
At PwC, we help clients solve today’s and tomorrow’s challenges across audit, consulting, tax, legal, technology, and data. We create an environment where people can learn, grow, and build a career in their own way. We believe the best results come from diverse experiences and perspectives. That’s why we foster an inclusive culture where everyone can be themselves, build on their strengths, and contribute to work that makes a real impact.
Interested in joining us? We’d love to hear from you and tell you more about this opportunity.
Ochrana osobních údajů pro žadatele o zaměstnání / Privacy Statement for Recruitment Applicants .
#LI-EK1
Not included in the source posting: what you'll do, qualifications, benefits.
Skills
Who can apply
The employer didn't state any visa, work authorization, citizenship or clearance requirements in this posting. Confirm with the employer before applying.
Read automatically from the employer's posting text. Always confirm with the employer — requirements can change after a job is published.