Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
Arche Consulting Sp. z o.o. is seeking a security monitoring engineer to develop and maintain logging standards, optimise SIEM platforms, and integrate logs for enterprise threat detection. You will design correlation rules, build use cases, and support SOC teams with incident handling and dashboards.
The role requires advanced security knowledge, multiple certifications, and hands-on experience with Splunk and security automation. A global IT services focus underpins this opportunity.
Our client is a global IT services and consulting company specializing in digital transformation, cloud, cybersecurity, and managed services for enterprise clients.
develop and maintain Logging & Monitoring standards,
maintain and optimise security monitoring platforms,
analyse, normalise and integrate logs into SIEM,
create and optimise correlation and detection rules based on MITRE ATT&CK,
develop security monitoring use cases,
design and implement security controls and SIEM integrations,
configure, maintain and improve security of systems and services,
perform incident and forensic analysis,
configure and optimise SIEM components,
create dashboards, KPI reports and security alerts,
support SOC teams and incident handlers,
contribute to monitoring architecture design,
assess and develop security monitoring solutions,
maintain technical documentation, procedures and playbooks,
review and continuously improve monitoring policies and detection capabilities,
min. 3 certifications: CISSP, CCSP, GPEN, Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, TOGAF 9 Certified,
knowledge of Secure SDLC and system security architecture,
knowledge of Windows and Linux security,
knowledge of network security architecture and telemetry analysis,
experience in offensive and defensive security, penetration testing, red teaming and threat hunting,
knowledge of MITRE ATT&CK and MITRE D3FEND,
experience with security monitoring, incident response and vulnerability analysis,
experience with Cribl Stream, Splunk Enterprise, Splunk Enterprise Security, Splunk SOAR and Splunk UBA,
experience with correlation searches and detection engineering,
experience with Infrastructure as Code, CI/CD and Azure DevOps,
experience in security automation and Splunk SOAR playbooks,
experience in HLD, LLD and technical security documentation,
experience in security policies, procedures, risk assessment and technical reporting,
experience with MSSP and cybersecurity vendor evaluation,
experience in developing cybersecurity roadmaps and security standards.