CyberSecurity L&M Service Specialist (K/M)

160 - 250 PLN/ godz.B2B
SeniorFull-time·B2B
#422876·Dodano 15 dni temu·1
Źródło: justjoin.it
Aplikuj teraz

Tech Stack / Keywords

CybersecuritySplunk EnterpriseSplunk ESSplunk SOARSplunk UBACriblSIEMMITRE ATT&CKDetection EngineeringThreat hunting

Firma i stanowisko

Fabrity S.A. is a dynamically developing technology company specializing in software engineering, generative artificial intelligence, and industrial Internet of Things (IoT). The company creates complex solutions that help enterprises automate processes, increase operational efficiency, and make key decisions through effective data analysis. Fabrity supports organizations in digital transformation using leading platforms like ServiceNow, Microsoft Power Platform, and its proprietary low-code product Fastive. They work for clients across various industries including pharmaceuticals, healthcare, financial services, manufacturing, automotive, and retail, serving notable brands such as ABB, Bayer, Carrefour, PKO BP, Dormakaba, Sanofi, Toyota Bank, Frontex, Liebherr, Pepsico, and Saint-Gobain.

Wymagania

  • Minimum 5 years of experience in Cybersecurity Monitoring, SIEM Engineering, or Detection Engineering.
  • Very good knowledge of Splunk Enterprise, Splunk Enterprise Security, Splunk SOAR, Splunk UBA, and Cribl Stream.
  • Experience creating and tuning correlation rules and SIEM use cases.
  • Practical knowledge of the MITRE ATT&CK and MITRE D3FEND frameworks.
  • Experience designing security monitoring architectures.
  • Strong knowledge of Windows and Linux security.
  • Knowledge of network security, network traffic analysis, and security telemetry.
  • Experience in log analysis, threat detection, and threat hunting.
  • Familiarity with SecOps processes and security incident handling.
  • Experience creating technical documentation, including HLD and LLD.
  • Ability to automate security processes using scripting.
  • Experience with Infrastructure as Code (IaC) and CI/CD solutions.
  • Knowledge of Azure DevOps.
  • Ability to design and maintain playbooks in Splunk SOAR.
  • Experience managing and integrating enterprise security solutions.
  • Ability to assess cyber risk, vulnerabilities, and threats.
  • Very good command of the English language (B2).

Nice to have:

  • Experience in large international organizations or EU institutions.
  • Experience in Digital Forensics and Incident Response.
  • Knowledge of Red Teaming methodologies and penetration testing.
  • Experience cooperating with MSSP providers.
  • Experience in preparing business cases for cybersecurity initiatives.
  • Participation in defining Cyber Security development strategies.
  • Certifications in Splunk, Security Operations, or Cyber Security (e.g., CISSP, CCSP, GIAC GPEN, Splunk Certified Admin, TOGAF 9).

Obowiązki

  • Maintain and develop security monitoring platforms, primarily Splunk and Cribl.
  • Analyze, normalize, and integrate log sources with the SIEM platform.
  • Design and develop correlation rules and use cases based on the MITRE ATT&CK framework.
  • Create and optimize correlation searches in Splunk Enterprise Security.
  • Configure and maintain components of SIEM, SOAR, and monitoring tools.
  • Develop technical designs (HLD, LLD) and architectural documentation.
  • Collaborate with system owners to implement new log sources and monitoring mechanisms.
  • Define security monitoring policies and translate them into practical detection rules.
  • Design dashboards, reports, and KPIs for cybersecurity.
  • Participate in designing security monitoring architecture.
  • Implement and develop SecOps procedures and security control mechanisms.
  • Support security incident analysis and forensic investigations.
  • Analyze security audit results and implement corrective actions.
  • Create playbooks and automate security processes within the SOAR environment.
  • Collaborate with security teams, administrators, and business stakeholders.

Benefity

  • Benefits within a cafeteria system.
  • Cooperation based on a B2B contract.
  • Hybrid work model with presence in the client's office in Warsaw 1 day per week.
  • Opportunity to engage in a project impacting client business development.
  • Service provision for a prestigious public institution.
Elastyczne godziny

Inne informacje

Data protection clause details the processing of personal data by Fabrity S.A. and its associated entity, including rights to access, rectify, and delete data according to GDPR. Data is processed for recruitment and cooperation purposes with specified retention periods. Contact information for the Data Protection Officer and complaint procedures with the relevant authority are provided. Consent withdrawal is possible without affecting prior processing. Data will not be transferred to third countries or international organizations.

Fabrity S.A.

Fabrity S.A.

32 aktywne oferty

Zobacz wszystkie oferty
Aplikuj teraz