3 дня назад
CyberSecurity L&M Service Specialist
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
CyberSecurity L&M Service Specialist (SIEM/Splunk): Designing, administering, and improving enterprise security monitoring, logging, and SIEM capabilities with an accent on Splunk platforms, threat detection engineering, and cybersecurity controls. Focus on integrating log sources, developing MITRE ATT&CK- and D3FEND-aligned detection use cases, conducting forensic investigations, and supporting incident response.
Location: Onsite in Poland, Warsaw
Company
Quento is the ICT arm of the , delivering AI, digital engineering, cloud, and cybersecurity solutions for business transformation.
What you will do
- Design, develop, administer, and continuously improve enterprise security monitoring, logging, and SIEM capabilities.
- Optimize monitoring platforms through health checks, performance tuning, capacity planning, and license management.
- Analyze and correlate security events, onboard new log sources, and develop detection rules, use cases, dashboards, KPIs, and alerting mechanisms.
- Configure, maintain, upgrade, and integrate cybersecurity systems, including security orchestration and automation workflows.
- Evaluate vulnerabilities, audit findings, and security risks, implementing appropriate remediation measures.
- Conduct forensic investigations and provide expert support for incident response and threat analysis.
Requirements
- Bachelor’s degree in information technology, computer science, engineering, or a related field.
- At least 10 years of IT experience, including 8 years in a relevant cybersecurity field.
- At least three internationally recognized certifications are required, including certifications such as CISSP, CCSP, GPEN, Splunk Enterprise Security, Splunk Enterprise Administration, or TOGAF 9.
- Expertise in enterprise security controls, security telemetry, anomaly detection, threat detection engineering, penetration testing, red teaming, threat hunting, incident response, and incident triage.
- Hands-on experience with Splunk Enterprise, Splunk Enterprise Security, Splunk SOAR, Splunk UBA, and Cribl Stream, including data ingestion and lifecycle management.
- Very good command of English at minimum B2 level and eligibility to obtain an EU Personal Security Clearance are required.
Nice to have
- Experience with Secure SDLC, Windows and Linux security, network security architectures, scripting, automation, and troubleshooting.
- Experience with Infrastructure as Code and CI/CD using Azure DevOps.
- Experience designing security monitoring architectures, HLDs, LLDs, technical blueprints, policies, procedures, roadmaps, and executive presentations.
Culture & Benefits
- Onsite work opportunity in Poland.
- Work in an ICT organization supporting clients worldwide.
- Equal-opportunity environment focused on ability and behavior.
- Applications must include a CV submitted in English.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
4 дня назад
Security Operations Specialist
2 дня назад
Senior Consulting Systems Engineer – NOC/SOC, SIEM/SOAR (MSSP & Service Provider) EMEA
5 дней назад
Security Engineer Expert (Cybersecurity)
3 дня назад
Senior Consultant in Cybersecurity
1 день назад
Senior Detection & Response Engineer (Cybersecurity)
2 дня назад