Unlock Full Resume Report

New offer - be the first one to apply!

September 5, 2026

CyberSecurity L&M Service Specialist (m/f/n)

Senior • On-site

Warsaw, MZ, Poland

Requirements

  • At least 10 years of professional experience in IT
  • At least 8 years of experience in a similar position
  • Higher-education degree in IT (bachelor's or engineering)
  • Personal Security Clearance at EU Confidential level
  • At least 3 of the following certifications, or internationally recognized equivalents: CISSP, CCSP, GIAC Penetration Tester (GPEN), Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin
  • TOGAF 9 Certified

Knowledge and skills

  • Knowledge of the Systems Development Life Cycle, with a strong understanding of Secure SDLC practices and integration of security controls throughout software development phases
  • Knowledge of OS-level security architecture, including configuration auditing, access controls, and security event log analysis for Windows and Linux
  • Knowledge of network security architecture, including secure protocols, network segmentation, and analysis of network traffic and telemetry logs
  • Knowledge of enterprise security controls, including security telemetry design, monitoring, and anomaly detection
  • Knowledge of offensive security practices, including penetration testing, red teaming, and adversarial tactics and techniques
  • Knowledge of defensive security practices, including security monitoring, incident triage, threat hunting, and detection-rule engineering
  • Knowledge of system security vulnerabilities, emerging cyber threats, and exploit mechanisms
  • Knowledge of MITRE ATT&CK and MITRE D3FEND, with the ability to map adversary TTPs to defensive countermeasures
  • Ability to implement and configure enterprise security controls
  • Ability to author and test secure scripts for security workflow automation, detection logic, and infrastructure management
  • Ability to troubleshoot cybersecurity monitoring issues
  • Experience administering, managing lifecycles of, and integrating Cribl Stream, Splunk Enterprise, Splunk Enterprise Security, Splunk SOAR, and Splunk UBA
  • Experience developing, testing, and fine-tuning Splunk Enterprise Security correlation searches using MITRE ATT&CK and D3FEND
  • Experience using IaC and CI/CD automation, specifically Azure DevOps, to deploy, configure, and manage security controls and Splunk/Cribl infrastructure
  • Ability to build and maintain automated playbooks in Splunk SOAR
  • Experience designing security monitoring capabilities, including High-Level Designs, Low-Level Designs, and technical blueprints
  • Technical report-writing skills, including translating security metrics and incidents into executive insights
  • Experience drafting security procedures and policies focused on information protection and data privacy
  • Experience creating business cases for cybersecurity initiatives and technology deployments
  • Experience evaluating MSSPs and cybersecurity vendors through technical validation and capability mapping
  • Experience developing cybersecurity capability roadmaps and presenting them to executive sponsors and stakeholders

Typical tasks and responsibilities

  • Develop and maintain Logging & Monitoring standards
  • Maintain monitoring platforms through health checks and optimal licence utilization
  • Analyze logs, identify valuable data, normalize it, and create correlation rules in the context of MITRE ATT&CK
  • Support security monitoring use-case engineering
  • Design security event collection and integrate log sources into a SIEM solution
  • Translate security monitoring policy into monitoring rules
  • Integrate cybersecurity solutions and ensure reliable operation
  • Securely configure systems, services, and products
  • Maintain and upgrade the security of systems, services, and products
  • Implement cybersecurity procedures and controls
  • Monitor the performance of implemented cybersecurity controls
  • Evaluate audit and test results, prioritize findings, and plan and implement remediation controls
  • Perform forensic analysis in response to information-security incidents
  • Draft security plans and Security Operating Procedures (SecOps)
  • Implement technical and operational security controls in products and systems
  • Evaluate risks, threats, and consequences
  • Contribute to security standards definition
  • Provide expert support to incident handlers
  • Configure SIEM components for optimal performance
  • Improve correlation rules for efficient incident detection, including identifying required logs, files, and artefacts; defining complementary devices where needed; and developing detection and correlation rules
  • Regularly review and improve the monitoring policy
  • Define KPI dashboards and reports
  • Produce qualified reports, recommendations, and alerts for SOC customers; follow up on actions
  • Contribute to overall monitoring architecture design with customers, system owners, and the security operations engineering team
  • Assess and develop security event detection solutions
  • Produce and maintain technical documentation, processes, procedures, and playbooks related to use-case engineering and SIEM ecosystem support

Offer

  • B2B contract
  • Long-term cooperation
  • Hybrid working model: 20% from the Warsaw office and 80% remote

Benefits

  • Co-financing of private medical and sports packages
  • Work in a multinational environment
  • Candidate must be an EU citizen and work from Poland

Similar jobs you might like