Techtree
Techtree
New

CyberSecurity Logging & Monitoring (L&M) Service Specialist

Brak informacji o wynagrodzeniu
MidFull-time
#416512·Dodano dziś·0
Źródło: justjoin.it
Aplikuj teraz

Tech Stack / Keywords

8+ years in a similar security monitoring / SIEM

Firma i stanowisko

The position supports the security operations of a major EU Justice & Home Affairs agency in Warsaw. It is a hands-on role focusing on SIEM engineering, security architecture, and offensive and defensive security practices.

Wymagania

  • 10+ years of overall IT experience, including 8+ years in a similar security monitoring / SIEM role
  • Deep hands-on expertise administering Splunk (Enterprise, ES, SOAR, UBA) and Cribl Stream
  • Strong grounding in offensive (pentesting, red teaming) and defensive (threat hunting, detection engineering, incident triage) security, fluent in MITRE ATT&CK and D3FEND
  • Experience with Infrastructure-as-Code and CI/CD, specifically Azure DevOps, for deploying and managing security infrastructure
  • Ability to author HLD/LLD architecture documentation, security policies/procedures, business cases, and MSSP/vendor evaluations
  • Bachelor's degree or higher
  • English proficiency at B2+ level
  • At least 3 of the following certifications (or equivalents): CISSP, CCSP, GIAC Penetration Tester (GPEN), Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, TOGAF 9 Certified
  • Willingness and eligibility to obtain and hold a CONFIDENTIEL UE/EU CONFIDENTIAL personal security clearance from day one

Obowiązki

  • Administer and architect Splunk Enterprise, Splunk ES, Splunk SOAR, Splunk UBA, and Cribl Stream for data routing and pipeline management
  • Design and maintain logging & monitoring architecture, including producing HLD/LLD documentation, security policies, and procedures
  • Hunt threats and engineer detections, triaging incidents and mapping coverage against MITRE ATT&CK and D3FEND
  • Apply offensive security skills (pentesting, red teaming) to validate and improve detection and response capability
  • Deploy and manage security controls and Splunk/Cribl infrastructure as code using CI/CD pipelines (Azure DevOps)
  • Produce business cases and conduct vendor/MSSP evaluations; present security roadmaps to executive stakeholders

Inne informacje

Willingness and eligibility to obtain and hold a CONFIDENTIEL UE/EU CONFIDENTIAL personal security clearance from day one. Location: Warsaw, Poland - on-site at client's HQ (approx. 20% on client premises / 80% off-site). Long-term contract initially for 12 months with possibility of up to 3 annual renewals. No travel foreseen.

Techtree

Techtree

24 aktywne oferty

Zobacz wszystkie oferty
Aplikuj teraz