Senior Cyber Security Resilience Specialist
Tech Stack / Keywords
Firma i stanowisko
SIX is recruiting a Senior Cyber Security Resilience Specialist focused on improving and operating Cyber Security Resilience services such as File Integrity Monitoring (FIM), Secure Configuration Baselines (SCB), and Vulnerability Management (VM). The role includes working with infrastructure, platform, engineering, risk, and compliance teams to ensure effective and compliant cyber resilience capabilities in a regulated industry.
Wymagania
- 5+ years experience in Cyber Security, Infrastructure Security, or Security Engineering
- Hands-on experience with Vulnerability Management, Secure Configuration Baselines (CIS Benchmarks), File Integrity Monitoring
- Strong understanding of Windows and Linux security, Cloud security principles, security monitoring and detection engineering, security automation and orchestration
- Experience with enterprise-scale security control implementation and governance
- Experience in regulated industries such as Banking or Financial Services
- Knowledge of FINMA, DORA, NIST CSF, ISO 27001, CIS Controls or similar frameworks
- Experience integrating security platforms through APIs and automation
- Exposure to SIEM, Cortex XSOAR, Elastic Stack, and threat detection engineering
- Ability to translate complex technical issues into business-relevant insights
- Self-driven, independent operator with strong ownership mindset
- Excellent stakeholder management and influencing skills
- Ability to lead initiatives across multiple teams and organizational boundaries
- Continuous improvement mindset focused on automation and operational excellence
- English fluency (mandatory)
Nice to have:
- German language skills (strong advantage)
Obowiązki
- Contribute to continuous improvement of Cyber Security Resilience services: File Integrity Monitoring (FIM), Secure Configuration Baselines (SCB), Vulnerability Management (VM)
- Define operational standards, processes, and KPI improvements for resilience controls
- Drive adoption of cybersecurity best practices and regulatory requirements
- Ensure alignment of resilience controls with evolving threat landscapes and business needs
- Provide subject matter expertise for FIM, SCB, and Vulnerability Management platforms and processes
- Lead deployment, optimization, and enhancement of security monitoring capabilities
- Drive continuous improvement to enhance data quality, monitoring coverage, and risk visibility
- Support platform lifecycle management including upgrades and onboarding of new assets
- Analyze vulnerability trends, exposure levels, and remediation effectiveness
- Engage with technology teams to prioritize and drive remediation activities
- Develop and maintain risk-based vulnerability management methodologies
- Produce executive and technical reports for senior stakeholders
- Contribute to SCB implementation and governance based on CIS Benchmarks and best practices
- Assess baseline compliance across infrastructure and application environments
- Partner with engineering teams to improve configuration compliance posture
- Define and maintain FIM monitoring strategies, policies, and alerting thresholds
- Conduct advanced analysis of integrity monitoring events to identify security risks
- Drive enhancements to monitoring coverage and detection capabilities
- Act as primary technical contact for internal and external audits including FINMA, DORA, Internal Audit, External Regulatory Reviews
- Ensure continuous audit readiness with evidence management and control validation
- Interpret regulatory requirements into technical and operational controls
- Support risk assessments and control effectiveness reviews
Benefity
- Hybrid work model allowing up to 40% working from home
- Private medical care and life insurance
- Meal, transportation, and electricity allowance
- Sport card
- Cinema tickets and Benefit System points
- Up to 20 days working from abroad / Day for U
- Access to technical and language learning platforms
Inne informacje
Informujemy, że administratorem danych jest SIX z siedzibą w Warszawie, ul. Przyokopowa 26 (dalej jako "administrator"). Masz prawo do żądania dostępu do swoich danych osobowych, ich sprostowania, usunięcia lub ograniczenia przetwarzania, prawo do wniesienia sprzeciwu wobec przetwarzania, a także prawo do przenoszenia danych oraz wniesienia skargi do organu nadzorczego. Dane osobowe przetwarzane będą w celu realizacji procesu rekrutacji. Podanie danych w zakresie wynikającym z ustawy z dnia 26 czerwca 1974 r. Kodeks pracy jest obowiązkowe. W pozostałym zakresie podanie danych jest dobrowolne. Odmowa podania danych obowiązkowych może skutkować brakiem możliwości przeprowadzenia procesu rekrutacji. Administrator przetwarza dane obowiązkowe na podstawie ciążącego na nim obowiązku prawnego, zaś w zakresie danych dodatkowych podstawą przetwarzania jest zgoda. Dane osobowe będą przetwarzane do czasu zakończenia postępowania rekrutacyjnego i przez okres możliwości dochodzenia ewentualnych roszczeń, a w przypadku wyrażenia zgody na udział w przyszłych postępowaniach rekrutacyjnych - do czasu wycofania tej zgody. Zgoda na przetwarzanie danych osobowych może zostać wycofana w dowolnym momencie. Odbiorcą danych jest serwis Rocket Jobs oraz inne podmioty, którym powierzyliśmy przetwarzanie danych w związku z rekrutacją.
SIX
11 aktywnych ofert