Unlock Full Resume Report

New offer - be the first one to apply!

September 3, 2026

Security Monitoring Platform Developer (Azure Developer)

Mid • On-site

184,320 - 230,400 PLN/yr

Warsaw, MZ, Poland

The Security Monitoring Platform Developer designs, implements, and maintains custom security automation applications within the CDC Cyber Security Monitoring (CSM) squad.

The role focuses on developing Azure-native application pipelines, integrating external security services, and enabling automated incident-handling workflows in Microsoft Sentinel and Azure Data Explorer (ADX). Key deliverables include CheckMail phishing-analysis automation, a MISP threat-intelligence connector, SQL-based data replication, and complex Sentinel incident orchestration. While the Platform Engineer maintains infrastructure and platform operations, the Developer builds the custom application layer that runs on top of it, as well as infrastructure components with larger code aspects.

Compensation

Minimum monthly gross compensation: 15,360 PLN. Final pay is determined based on experience, qualifications, scope of responsibility, and internal alignment. This position is eligible for variable pay components, such as performance-based bonuses, in accordance with the applicable employee group, role scope, and compensation structure.

Your Tasks & Responsibilities

  • Develop and maintain the CheckMail automation pipeline—an Azure-native application for automated analysis, enrichment, LLM-based classification, and escalation of user-reported phishing emails—including Function Apps (Python), Logic Apps, Service Bus integration, ADX data persistence, and Sentinel incident creation.
  • Implement and operate the MISP2Sentinel threat-intelligence connector—an Azure Function App (Python) using PyMISP and MISP-STIX libraries to periodically push IoCs from DCSO-hosted MISP to the Sentinel ThreatIntelligenceIndicator table via the Upload Indicators API.
  • Develop Azure Function Apps (Python) for SQL-based data replication, building and maintaining data pipelines between Azure SQL Database, ADX, and Sentinel to provide context data for detection and enrichment workflows.
  • Design and implement complex security incident-handling logic in Microsoft Sentinel, including multi-step enrichment workflows with VirusTotal, URLScan, and CrowdStrike Sandbox; Analytics Rules; Automation Rules; and Logic App-based orchestration for SOC triage and ServiceNow ticketing.
  • Integrate external security APIs and services into the SIEM platform, including enrichment providers, sandbox integrations, and threat-intelligence feeds, with error handling, retry logic, and Dead Letter Queue management.
  • Follow and contribute to the established IaC deployment process; deploy all application code and infrastructure via GitHub Actions, Terraform, and CSM GitHub repositories.
  • Ensure application reliability and observability through structured logging, health-monitoring integration, Application Insights instrumentation, and proactive alerting.
  • Support content handover and knowledge transfer; ensure developed components are documented, follow CSM naming conventions, and are integrated into the established RBAC and deployment model.
  • Collaborate with CSM analysts to translate detection and automation requirements into scalable, maintainable application code.

Key Working Relations

Internal

  • CSF & CDC teams
  • IT & Security Operations
  • Application / Development Teams

External

  • IT Security, SIEM & UEBA providers and partners
  • External SOC contractors

Qualifications & Competencies

  • Strong hands-on development experience in Python, including Azure Functions, asynchronous processing, and API integrations.
  • Experience with Azure PaaS services: Function Apps, Logic Apps, Service Bus, Key Vault, Event Hub, and Application Insights.
  • Solid understanding of REST APIs, JSON, and data-serialization formats, including STIX and MISP event format.
  • Experience with SQL databases and data-pipeline patterns; Azure SQL and ADX/KQL are strong advantages.
  • Understanding of Git-based workflows, infrastructure as code with Terraform, and CI/CD with GitHub Actions.
  • Experience in IT Security, SIEM, or a related field, including understanding of the security incident lifecycle, detection engineering, and threat-intelligence concepts.
  • Understanding of IT and enterprise systems, including business processes and data flows.
  • Ability to collaborate in global teams across time zones.
  • University degree or equivalent experience, preferably in Computer Science, Information Technology, or Cyber Security.
  • Excellent oral and written English communication skills; German is an advantage.

Benefits

  • Medical care above statutory requirements.
  • Flexible benefits supporting leisure and well-being/sports programs.
  • Life, accident, and disability insurance through group coverage.
  • Employer-supported pension plans with regular company contributions.
  • Home-office allowance to support hybrid or remote work.
  • Extra paid holidays.

Benefits may vary depending on country, role, and employment conditions.

Similar jobs you might like