How to apply for Information Security Consultant (SOC IR L3)

Eurofins

About Eurofins

Eurofins is a global leader in analytical testing services, with a mission to promote safer, healthier, and more sustainable environments. With over 900 laboratories in 50+ countries, they support industries from food and pharma to environmental testing. Working here means contributing to meaningful science that impacts everyday life, while being part of a diverse and innovative team.

About the role

As an Information Security Consultant (SOC IR L3), you will be a senior member of the Incident Response team, leading the investigation and resolution of complex cybersecurity incidents. You'll analyse and correlate security events from multiple sources like SIEM, IDS, EDR, and firewalls, conduct digital forensics, and provide expert guidance throughout the incident response lifecycle. This role is critical to protecting Eurofins' global operations and enhancing their security posture.

A typical day

A typical day might involve triaging alerts from the SIEM, conducting deeper investigations using EDR and forensic tools, and collaborating with IT teams to contain and remediate threats. You'll also spend time documenting incidents, updating playbooks, and occasionally participating in after-hours incident calls. The role is remote, so you'll primarily work from home, with occasional travel for team meetings or critical incidents.

Who Eurofins is looking for

  • 5+ years of experience in SOC, incident response, or digital forensics, with at least 2 years at L2/L3 level.
  • Hands-on expertise with SIEM (e.g., Splunk, QRadar), EDR (e.g., CrowdStrike, Carbon Black), IDS/IPS, firewalls, and antivirus solutions.
  • Strong knowledge of incident response frameworks (NIST, SANS) and experience leading investigations from detection to remediation.
  • Proficiency in forensic tools (e.g., EnCase, FTK, Volatility) and scripting for automation (Python, PowerShell).
  • Excellent communication skills and ability to work remotely with distributed teams; fluency in English (Polish is a plus).

Tips for this application

  • Highlight specific incidents you've led end-to-end, detailing the tools used (SIEM, EDR, etc.) and the outcome. Quantify impact where possible (e.g., 'reduced containment time by 30%').
  • Emphasize your experience with digital forensics and incident response lifecycle, as this is a core requirement. Mention any certifications like GCFA, GCIH, or GCFE.
  • Since the role is remote within Poland, explicitly state your location and willingness to travel occasionally. Mention your ability to work flexible hours for critical incidents.
  • Research Eurofins' recent security initiatives or press releases and reference them in your application to show genuine interest in the company's mission.
  • Tailor your resume to include keywords from the job description (SIEM, IDS, EDR, antivirus, firewall, proxy, digital forensics) to pass ATS scans.

What to cover in your cover letter

["Your hands-on experience in leading complex incident investigations and the specific tools you've mastered (e.g., Splunk, CrowdStrike, EnCase).", "How you've contributed to improving SOC procedures or playbooks in previous roles, aligning with Eurofins' focus on continuous development.", 'Your ability to work remotely and collaborate effectively with security and IT teams across different time zones.', "Your motivation to work in a mission-driven company focused on safety, health, and sustainability, and how your skills can help protect Eurofins' global operations."]

Draft a cover letter

Research before applying

  • Explore Eurofins' website, particularly their security and compliance pages, to understand their global footprint and the industries they serve.
  • Look up recent news about Eurofins, such as acquisitions or security incidents, to understand their current challenges and priorities.
  • Research the typical cyber threats facing analytical testing and life sciences companies (e.g., IP theft, ransomware) to tailor your responses.
  • Check LinkedIn profiles of current Eurofins SOC team members to understand their backgrounds and potential interview panel.

Likely interview topics

Based on the job description, expect questions about:

  • Walk us through a complex security incident you led from detection to resolution. What tools did you use and what was the outcome?
  • How do you correlate events from multiple sources like SIEM, EDR, and firewalls to identify a true positive? Provide a specific example.
  • Describe your experience with digital forensics. What tools and methodologies do you prefer and why?
  • How do you stay updated with the latest threats and attack techniques? What sources do you rely on?
  • Given the remote nature of this role, how do you ensure effective collaboration and communication during high-pressure incidents?
Practise interview questions

Common mistakes to avoid

  • Being vague about your incident response experience—interviewers will expect specific examples with tools and outcomes.
  • Underestimating the importance of digital forensics; if you lack hands-on experience, don't overstate it as it will be probed deeply.
  • Ignoring the remote aspect: failing to demonstrate how you stay productive and collaborative in a remote environment could raise concerns.

Deadline

No deadline is listed. Roles without a deadline usually close once the employer has enough candidates, so apply soon if you are interested.