CyberSecurity L&M Service Specialist (m/f/n)
Brak informacji o wynagrodzeniu
SeniorFull-time·B2B
#413086·Dodano 2 dni temu·0
Źródło: justjoin.itTech Stack / Keywords
SDLCOS-level security architectureNetwork Security ArchitectureMITRE ATT&CK and MITRE D3FEND frameworks
Firma i stanowisko
Role supporting a long-term project delivered for an organization of the European Union based in Warsaw.
Wymagania
- At least 10 years of professional IT experience
- Minimum 8 years in a similar cybersecurity position
- Bachelor's or engineer degree in IT
- Personal Security Clearance at EU Confidential level required
- At least 3 internationally recognized certifications among: CISSP, CCSP, GIAC Penetration Tester (GPEN), Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, TOGAF 9 Certified
- Knowledge of Systems Development Life Cycle (SDLC) with secure SDLC practices
- Expertise in OS-level security architecture for Windows and Linux platforms
- Expertise in network security architecture including secure protocols and network segmentation
- Knowledge of enterprise security controls, security telemetry monitoring, and anomaly detection
- Knowledge of offensive security practices including penetration testing and red teaming
- Knowledge of defensive security practices including monitoring, incident triage, and threat hunting
- Understanding of system security vulnerabilities and emerging cyber threats
- Knowledge of MITRE ATT&CK and MITRE D3FEND frameworks with ability to map offensive TTPs to defensive measures
- Experience providing technical support for implementation and configuration of security controls
- Skill in authoring and testing secure automation scripts
- Ability to troubleshoot cybersecurity monitoring issues
- Experience administering and integrating enterprise security platforms such as Splunk Enterprise, Splunk Enterprise Security, Splunk SOAR, and Splunk UBA
- Experience developing and fine-tuning correlation searches within Splunk
- Experience with Infrastructure as Code and CI/CD tools (e.g., Azure DevOps) for security platform deployment
- Proficiency in building and maintaining automated playbooks in Splunk SOAR
- Experience designing tailored security monitoring capabilities with HLD, LLD, and technical blueprints
- Strong technical report writing skills translating security metrics into executive insights
- Experience drafting security policies emphasizing information protection and data privacy
- Experience authoring business cases for cybersecurity initiatives
- Experience supporting evaluation and selection of Managed Security Service Providers and cybersecurity vendors
- Experience defining strategic cybersecurity roadmaps and presenting to executive sponsors
Obowiązki
- Drive development and maintenance of Logging & Monitoring standards
- Maintain monitoring platforms with regular health checks and license management
- Analyze logs to identify valuable data, normalize them, and create correlation rules based on the MITRE ATT&CK framework
- Support security monitoring use-case engineering
- Design security events collection and integrate log sources into SIEM solutions
- Translate security monitoring policy into monitoring rules
- Integrate and ensure operation of cybersecurity solutions
- Securely configure and maintain systems, services, and products
- Implement cybersecurity procedures and controls
- Monitor performance of implemented cybersecurity controls
- Evaluate security audit results and implement remediation controls
- Provide forensic analysis for information security incidents
- Draft security plans and Security Operating procedures (SecOps)
- Implement operational-level security policy controls
- Assess risks, threats, and consequences
- Contribute to the definition of security standards
- Provide expert support to incident handlers
- Configure SIEM components for optimal performance
- Improve correlation rules for efficient incident detection
- Identify required logs and complementary devices for monitoring
- Elaborate detection and correlation rules
- Regularly review and improve monitoring policy
- Define dashboards and reports for KPIs
- Produce qualified reports and alerts for SOC customers
- Design overall monitoring architecture with customers and security operations engineering team
- Assess security event detection solutions
- Maintain technical documentation, including playbooks and processes related to SIEM ecosystem support
Benefity
- B2B contract signed with Shimi
- Long-term cooperation
- Hybrid working model: 20% office in Warsaw, 80% remote
- Co-financing of private medical and sports packages
- Work in a multinational environment
- Candidate must be EU citizen working from Poland
Opieka zdrowotna
Karta sportowa
Inne informacje
Candidate must be an EU citizen and must work from Poland. Personal Security Clearance at EU Confidential level is required.
SHIMI sp. z o.o.
64 aktywne oferty