2 дня назад
CyberSecurity L&M Service Specialist
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
CyberSecurity L&M Service Specialist (SIEM/Splunk): Designing, operating, and continuously improving enterprise security monitoring, logging, and SIEM capabilities with an accent on threat detection engineering, security telemetry, and resilient cybersecurity controls. Focus on integrating Splunk and Cribl platforms, developing MITRE ATT&CK-aligned detection logic and playbooks, and performing forensic investigations and incident response.
Location: Warsaw, Poland; hybrid workplace, with the role also described as an onsite opportunity in Poland.
Company
Quento is the ICT arm of the , delivering solutions across AI, digital engineering, cloud, and cybersecurity to support digital transformation.
What you will do
- Design, develop, maintain, and improve enterprise security monitoring, logging, and SIEM capabilities.
- Administer and optimize monitoring platforms, including health checks, performance tuning, capacity planning, and license utilization.
- Analyze and correlate security logs and events, develop detection content and correlation rules, and onboard new log sources and cybersecurity solutions.
- Configure, maintain, and improve cybersecurity systems, controls, dashboards, KPIs, reports, playbooks, and operational documentation.
- Evaluate vulnerabilities, risks, audits, and security assessments, implementing appropriate remediation measures.
- Conduct forensic investigations and provide expert support during security incidents, threat analysis, and incident response activities.
Requirements
- Bachelor’s degree in information technology, computer science, engineering, or a related field.
- At least 10 years of IT experience, including 8 years in a relevant cybersecurity field.
- At least three internationally recognized certifications from the listed CISSP, CCSP, GIAC, Splunk, or TOGAF certifications, or recognized equivalents.
- Expertise in enterprise security controls, security telemetry, anomaly detection, threat detection engineering, penetration testing, red teaming, threat hunting, incident response, and detection use-case development.
- Hands-on administration and integration experience with Splunk Enterprise, Splunk Enterprise Security, Splunk SOAR, Splunk UBA, and Cribl Stream.
- Strong knowledge of Windows, Linux, network security, Secure SDLC, MITRE ATT&CK, MITRE D3FEND, scripting, automation, IaC, CI/CD, and Azure DevOps.
- Very good English, minimum B2 level, is required.
- Eligibility to obtain an EU Personal Security Clearance is required at a later stage.
Culture & Benefits
- Hybrid workplace with an onsite opportunity in Poland.
- Opportunity to work on transformative ICT solutions across AI, digital engineering, cloud, and cybersecurity.
- Inclusive hiring practices focused on ability and behavior.
- Application materials must be submitted in English.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
7 дней назад
Presales Engineer (Cybersecurity)
2 дня назад
Vulnerability & Patch Management (Senior) Consultant (Cybersecurity)
2 дня назад
Vulnerability & Patch Management (Associate) Manager (Cybersecurity)
2 дня назад
Vulnerability & Patch Management (Associate) Manager (Cybersecurity)
2 дня назад
Vulnerability & Patch Management Senior Consultant (Cybersecurity)
3 дня назад