CyberSecurity L&M Service Specialist

Arche Consulting Sp. z o.o.

Warszawa

On-site

PLN 180,000 - 260,000

Full time

27 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Arche Consulting Sp. z o.o. is seeking a security monitoring engineer to develop and maintain logging standards, optimise SIEM platforms, and integrate logs for enterprise threat detection. You will design correlation rules, build use cases, and support SOC teams with incident handling and dashboards.

The role requires advanced security knowledge, multiple certifications, and hands-on experience with Splunk and security automation. A global IT services focus underpins this opportunity.

Qualifications

  • 3+ certifications are required: CISSP, CCSP, GPEN, Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, TOGAF 9 Certified.
  • Knowledge of Secure SDLC and system security architecture.
  • Knowledge of Windows and Linux security.
  • Knowledge of network security architecture and telemetry analysis.
  • Experience in offensive and defensive security, penetration testing, red teaming and threat hunting.
  • Knowledge of MITRE ATT&CK and MITRE D3FEND.
  • Experience with security monitoring, incident response and vulnerability analysis.
  • Experience with correlation searches and detection engineering.
  • Experience with Infrastructure as Code, CI/CD and Azure DevOps.
  • Experience in security automation and Splunk SOAR playbooks.
  • Experience in HLD, LLD and technical security documentation.
  • Experience in security policies, procedures, risk assessment and technical reporting.
  • Experience with MSSP and cybersecurity vendor evaluation.
  • Experience in developing cybersecurity roadmaps and security standards.

Responsibilities

  • Develop and maintain Logging & Monitoring standards.
  • Maintain and optimise security monitoring platforms.
  • Analyse, normalise and integrate logs into SIEM.
  • Create and optimise correlation and detection rules based on MITRE ATT&CK.
  • Develop security monitoring use cases.
  • Design and implement security controls and SIEM integrations.
  • Configure, maintain and improve security of systems and services.
  • Perform incident and forensic analysis.
  • Configure and optimise SIEM components.
  • Create dashboards, KPI reports and security alerts.
  • Support SOC teams and incident handlers.
  • Contribute to monitoring architecture design.
  • Assess and develop security monitoring solutions.
  • Maintain technical documentation, procedures and playbooks.
  • Review and continuously improve monitoring policies and detection capabilities.

Skills

Security monitoring
Incident response
Threat hunting
MITRE ATT&CK
Splunk
Detection engineering
Automation

Education

CISSP
CCSP
GPEN
Splunk Enterprise Certified Admin
Splunk Enterprise Security Certified Admin
TOGAF 9 Certified

Tools

Cribl Stream
Splunk Enterprise
Splunk Enterprise Security
Splunk SOAR
Splunk UBA

Job description

Our client is a global IT services and consulting company specializing in digital transformation, cloud, cybersecurity, and managed services for enterprise clients.

Responsibilities

develop and maintain Logging & Monitoring standards,

maintain and optimise security monitoring platforms,

analyse, normalise and integrate logs into SIEM,

create and optimise correlation and detection rules based on MITRE ATT&CK,

develop security monitoring use cases,

design and implement security controls and SIEM integrations,

configure, maintain and improve security of systems and services,

perform incident and forensic analysis,

configure and optimise SIEM components,

create dashboards, KPI reports and security alerts,

support SOC teams and incident handlers,

contribute to monitoring architecture design,

assess and develop security monitoring solutions,

maintain technical documentation, procedures and playbooks,

review and continuously improve monitoring policies and detection capabilities,

Requirements

min. 3 certifications: CISSP, CCSP, GPEN, Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, TOGAF 9 Certified,

knowledge of Secure SDLC and system security architecture,

knowledge of Windows and Linux security,

knowledge of network security architecture and telemetry analysis,

experience in offensive and defensive security, penetration testing, red teaming and threat hunting,

knowledge of MITRE ATT&CK and MITRE D3FEND,

experience with security monitoring, incident response and vulnerability analysis,

experience with Cribl Stream, Splunk Enterprise, Splunk Enterprise Security, Splunk SOAR and Splunk UBA,

experience with correlation searches and detection engineering,

experience with Infrastructure as Code, CI/CD and Azure DevOps,

experience in security automation and Splunk SOAR playbooks,

experience in HLD, LLD and technical security documentation,

experience in security policies, procedures, risk assessment and technical reporting,

experience with MSSP and cybersecurity vendor evaluation,

experience in developing cybersecurity roadmaps and security standards.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

CyberSecurity Specialist
CyberSecurity Specialist

SEIDOR • Warszawa

On-site
PLN 180,000 - 260,000
CyberSecurity Service & L&M Specialist
CyberSecurity Service & L&M Specialist

Aricoma • Warszawa

On-site
PLN 110,000 - 165,000
On-site in Warsaw
HO relocation possibility
CyberSecurity Logging & Monitoring Service Specialist
CyberSecurity Logging & Monitoring Service Specialist

Altherias • Warszawa

Hybrid
PLN 150,000 - 210,000
CyberSecurity L&M Service Specialist (Warsaw, 80% remote) – Frontex
CyberSecurity L&M Service Specialist (Warsaw, 80% remote) – Frontex

TheWhiteam • Warszawa

Hybrid
PLN 180,000 - 240,000
CyberSecurity L&M Service Specialist (Warsaw, 80% remote) – Frontex at The Whiteam
CyberSecurity L&M Service Specialist (Warsaw, 80% remote) – Frontex at The Whiteam

The Whiteam • Warszawa

Hybrid
PLN 180,000 - 240,000
CyberSecurity L&M Service Specialist (Warsaw, 80% remote) – Frontex
CyberSecurity L&M Service Specialist (Warsaw, 80% remote) – Frontex

Twtspain • Warszawa

Hybrid
PLN 200,000 - 320,000
CyberSecurity Logging & Monitoring (L&M) Service Specialist
CyberSecurity Logging & Monitoring (L&M) Service Specialist

TechTree • Warszawa

On-site
PLN 240,000 - 360,000
Senior Cybersecurity L&M & SIEM Specialist
Senior Cybersecurity L&M & SIEM Specialist

Qualco Group • Warszawa

On-site
PLN 180,000 - 260,000
CyberSecurity L&M Service Specialist
CyberSecurity L&M Service Specialist

Quento • Warszawa

On-site
PLN 90,000 - 130,000
Cyber Security Engineer
Cyber Security Engineer

Interact Software • Poland

On-site
PLN 120,000 - 180,000