CyberSecurity L&M Service Specialist
ARCHE consulting · Warsaw, Poland
No Polish requiredPosted yesterday
Apply directly with the employer or job board. Applications are never handled here.
Lokalizacja WARSZAWA Polska mazowieckie - About the employer
Our client is a global IT services and consulting company specializing in digital transformation, cloud, cybersecurity, and managed services for enterprise clients.
Responsibilities
- develop and maintain Logging & Monitoring standards,
- maintain and optimise security monitoring platforms,
- analyse, normalise and integrate logs into SIEM,
- create and optimise correlation and detection rules based on MITRE ATT&CK,
- develop security monitoring use cases,
- design and implement security controls and SIEM integrations,
- configure, maintain and improve security of systems and services,
- perform incident and forensic analysis,
- configure and optimise SIEM components,
- create dashboards, KPI reports and security alerts,
- support SOC teams and incident handlers,
- contribute to monitoring architecture design,
- assess and develop security monitoring solutions,
- maintain technical documentation, procedures and playbooks,
- review and continuously improve monitoring policies and detection capabilities,
Requirements
- min. 3 certifications: CISSP, CCSP, GPEN, Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, TOGAF 9 Certified,
- knowledge of Secure SDLC and system security architecture,
- knowledge of Windows and Linux security,
- knowledge of network security architecture and telemetry analysis,
- experience in offensive and defensive security, penetration testing, red teaming and threat hunting,
- knowledge of MITRE ATT&CK and MITRE D3FEND,
- experience with security monitoring, incident response and vulnerability analysis,
- experience with Cribl Stream, Splunk Enterprise, Splunk Enterprise Security, Splunk SOAR and Splunk UBA,
- experience with correlation searches and detection engineering,
- experience with Infrastructure as Code, CI/CD and Azure DevOps,
- experience in security automation and Splunk SOAR playbooks,
- experience in HLD, LLD and technical security documentation,
- experience in security policies, procedures, risk assessment and technical reporting,
- experience with MSSP and cybersecurity vendor evaluation,
- experience in developing cybersecurity roadmaps and security standards.
Benefits
- B2B contract,
- long-term cooperation.
Apply directly with the employer or job board. Applications are never handled here.
Keep looking
1,000+ English-friendly jobs in Warsaw
Every one checked for language requirements, updated daily.