CyberSecurity Logging & Monitoring (L&M) Service Specialist
Brak informacji o wynagrodzeniu
MidFull-time
#416512·Dodano dziś·0
Źródło: justjoin.itTech Stack / Keywords
8+ years in a similar security monitoring / SIEM
Firma i stanowisko
The position supports the security operations of a major EU Justice & Home Affairs agency in Warsaw. It is a hands-on role focusing on SIEM engineering, security architecture, and offensive and defensive security practices.
Wymagania
- 10+ years of overall IT experience, including 8+ years in a similar security monitoring / SIEM role
- Deep hands-on expertise administering Splunk (Enterprise, ES, SOAR, UBA) and Cribl Stream
- Strong grounding in offensive (pentesting, red teaming) and defensive (threat hunting, detection engineering, incident triage) security, fluent in MITRE ATT&CK and D3FEND
- Experience with Infrastructure-as-Code and CI/CD, specifically Azure DevOps, for deploying and managing security infrastructure
- Ability to author HLD/LLD architecture documentation, security policies/procedures, business cases, and MSSP/vendor evaluations
- Bachelor's degree or higher
- English proficiency at B2+ level
- At least 3 of the following certifications (or equivalents): CISSP, CCSP, GIAC Penetration Tester (GPEN), Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, TOGAF 9 Certified
- Willingness and eligibility to obtain and hold a CONFIDENTIEL UE/EU CONFIDENTIAL personal security clearance from day one
Obowiązki
- Administer and architect Splunk Enterprise, Splunk ES, Splunk SOAR, Splunk UBA, and Cribl Stream for data routing and pipeline management
- Design and maintain logging & monitoring architecture, including producing HLD/LLD documentation, security policies, and procedures
- Hunt threats and engineer detections, triaging incidents and mapping coverage against MITRE ATT&CK and D3FEND
- Apply offensive security skills (pentesting, red teaming) to validate and improve detection and response capability
- Deploy and manage security controls and Splunk/Cribl infrastructure as code using CI/CD pipelines (Azure DevOps)
- Produce business cases and conduct vendor/MSSP evaluations; present security roadmaps to executive stakeholders
Inne informacje
Willingness and eligibility to obtain and hold a CONFIDENTIEL UE/EU CONFIDENTIAL personal security clearance from day one. Location: Warsaw, Poland - on-site at client's HQ (approx. 20% on client premises / 80% off-site). Long-term contract initially for 12 months with possibility of up to 3 annual renewals. No travel foreseen.
Techtree
24 aktywne oferty