Unlock Full Resume Report

New offer - be the first one to apply!

September 4, 2026

CyberSecurity Logging & Monitoring (L&M) Service Specialist

Senior • On-site

Warsaw, Poland

The opportunity

We’re hiring a CyberSecurity Logging & Monitoring (L&M) Service Specialist for a long-term, on-site engagement supporting security operations. This is a deep, hands-on role at the intersection of SIEM engineering, security architecture, and both offensive and defensive security practice.

The role

You’ll own the logging and monitoring stack end-to-end—administering and architecting Splunk Enterprise, ES, SOAR, UBA, and Cribl Stream; hardening detection coverage; and translating security requirements into concrete architecture and policy. You’ll work closely with the wider security team, bridging red-team findings and blue-team operations, and will be expected to communicate technical roadmaps to non-technical stakeholders and executives.

What you’ll do

  • Administer and architect Splunk Enterprise, Splunk ES, Splunk SOAR, Splunk UBA, and Cribl Stream for data routing and pipeline management
  • Design and maintain logging and monitoring architecture, producing HLD/LLD documentation, security policies, and procedures
  • Hunt threats and engineer detections, triaging incidents and mapping coverage against MITRE ATT&CK and D3FEND
  • Apply offensive security skills, including pentesting and red teaming, to validate and improve detection and response capability
  • Deploy and manage security controls and Splunk/Cribl infrastructure as code using CI/CD pipelines in Azure DevOps
  • Produce business cases and vendor/MSSP evaluations, and present security roadmaps to executive stakeholders

What you bring

  • 10+ years of overall IT experience, including 8+ years in a similar security monitoring/SIEM role
  • Deep hands-on expertise administering Splunk Enterprise, ES, SOAR, UBA, and Cribl Stream
  • Strong grounding in offensive security—pentesting and red teaming—and defensive security—threat hunting, detection engineering, and incident triage
  • Fluency in MITRE ATT&CK and D3FEND
  • Infrastructure-as-Code and CI/CD experience, specifically Azure DevOps, for deploying and managing security infrastructure
  • Ability to author HLD/LLD architecture documentation, security policies and procedures, business cases, and MSSP/vendor evaluations
  • Bachelor’s degree or higher
  • English proficiency at B2+ level
  • At least 3 of the following certifications, or recognized equivalents: CISSP, CCSP, GIAC Penetration Tester (GPEN), Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, TOGAF 9 Certified
  • Willingness and eligibility to obtain and hold CONFIDENTIEL UE/EU CONFIDENTIAL personal security clearance from day one

Logistics

  • On-site at the client’s HQ, with approximately 20% of time on client premises and 80% off-site
  • Long-term contract with an initial 12-month term and the possibility of up to 3 annual renewals, for up to 48 months total
  • Start date: as early as October 2026
  • Travel: none foreseen
  • CONFIDENTIEL UE/EU CONFIDENTIAL clearance required from day one of assignment

Similar jobs you might like