ABOUT THE JOB
We are a large company with a start-up spirit. We organize ourselves into expert knowledge Units that collaborate with each other.
That's why we are looking for curious individuals who are motivated by challenges and eager to grow personally and professionally, to join our team and make a positive impact on the world through technology.
ARE YOU UP FOR THE CHALLENGE?
We want you to be a part of our team, from Warsaw, as a CyberSecurity L&M Service Specialist.
WHAT WILL YOU DO IN YOUR DAY-TO-DAY?
- Logging and monitoring: Develop and maintain standards, policies, dashboards, KPIs, reports, and monitoring architectures.
- SIEM engineering: Integrate log sources, normalize valuable security data, optimize SIEM components and licensing, and perform regular platform health checks.
- Detection engineering: Design, test, and improve monitoring use cases and correlation rules aligned with MITRE ATT&CK.
- Security operations: Integrate, configure, secure, maintain, and upgrade cybersecurity systems while implementing and monitoring operational controls.
- Risk and incident response: Assess risks and threats, remediate audit findings, provide forensic analysis, and support incident handlers.
- New-system onboarding: Identify required logs and artifacts, recommend complementary monitoring tools, and develop relevant detection rules.
- Reporting and documentation: Deliver actionable SOC reports and alerts, track remediation actions, and maintain security plans, procedures, technical documentation, and playbooks.
- Stakeholder collaboration: Coordinate monitoring design and improvements with customers, system owners, and security operations engineering teams.
WHAT DO WE EXPECT FROM YOU?
The consultant must demonstrate experience in:
- 6+ years of experience
- Certifications: At least three internationally recognized certifications—subject to Contracting Authority approval—from CISSP, CCSP, GPEN, Splunk Enterprise Admin, Splunk Enterprise Security Admin, TOGAF 9, or equivalent credentials.
- Security expertise: Secure SDLC; Windows/Linux and network security; enterprise controls and telemetry; penetration testing and red teaming; defensive monitoring, incident triage, threat hunting, and detection engineering; vulnerabilities, emerging threats, and exploit techniques.
- Frameworks and automation: Practical knowledge of MITRE ATT&CK and D3FEND; secure scripting; troubleshooting; Infrastructure as Code and CI/CD using Azure DevOps.
- Security platforms: Administration, integration, and lifecycle management of Cribl Stream, Splunk Enterprise, Enterprise Security, SOAR, and UBA—including data ingestion, correlation-search tuning, and automated playbooks.
- Architecture and documentation: Design of security-monitoring capabilities supported by HLDs, LLDs, technical blueprints, reports, policies, procedures, and business cases.
- Strategy and stakeholder management: MSSP and vendor evaluation, cybersecurity roadmap development, executive presentations, funding justification, and stakeholder alignment.
Will you join us in humanizing technology?