CyberSecurity L&M Service Specialist

Qualco Group

Warszawa

On-site

PLN 180,000 - 260,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Quento Technologies S.A. seeks a highly motivated CyberSecurity L&M Service Specialist to design, implement, and optimize enterprise security monitoring and SIEM capabilities. You will analyze logs, develop detection rules, and onboard new log sources while aligning with MITRE ATT&CK and regulatory requirements.

The role emphasizes hands-on configuration of Splunk products, scripting, IaC, and CI/CD practices within an on-site Poland environment. Strong English skills (B2+) are required.

Qualifications

  • Bachelor’s degree in Information Technology, Computer Science, Engineering, or a related field.
  • Minimum 10 years of IT experience with at least 8 years in the relevant field.
  • At least three internationally recognized certifications (e.g., CISSP, CCSP, GIAC, Splunk Admin/Security, TOGAF).
  • Strong knowledge of Secure SDLC and security controls throughout the software lifecycle.

Responsibilities

  • Design, develop, maintain, and improve enterprise security monitoring, logging, and SIEM capabilities.
  • Administer and optimize monitoring platforms through health checks and capacity planning.
  • Analyze, normalize, and correlate security logs using MITRE ATT&CK to enhance threat detection.
  • Design and maintain SIEM use cases, detection rules, and alerting mechanisms.
  • Lead onboarding/integration of new log sources and cybersecurity solutions into SIEM.
  • Translate policies into technical detection rules and monitoring procedures.
  • Ensure resilience of cybersecurity systems and tooling.
  • Develop security dashboards, KPIs, and incident response playbooks.
  • Contribute to architecture evolution of security monitoring systems.

Skills

Security monitoring
SIEM
MITRE ATT&CK
Threat detection
Security analytics
Scripting
Infra as Code
CI/CD
English (B2+)

Education

Bachelor’s degree in IT/CS/Engineering

Tools

Splunk Enterprise
Splunk Enterprise Security
Splunk SOAR
Splunk UBA
Cribl Stream
Azure DevOps

Job description

At Quento, the ICT arm of the Qualco Group, we deliver comprehensive and innovative solutions across AI, Digital Engineering, Cloud, and Cybersecurity, helping businesses accelerate digital transformation. With a presence in Greece, Luxembourg, and Belgium, and backed by the expertise of the Qualco Group, we combine deep technical knowledge with strategic partnerships to support business growth.

At Quento Technologies S.A., we empower our people to innovate and lead in delivering transformative ICT solutions to our clients worldwide. Quento Technologies seeks a highly motivated CyberSecurity L&M Service Specialist

Responsibilities:

  • Design, develop, maintain, and continuously improve enterprise security monitoring, logging, and SIEM capabilities.

  • Administer and optimize monitoring platforms through health checks, performance tuning, capacity planning, and license utilization management.

  • Analyze, normalize, and correlate security logs and events, leveraging frameworks such as MITRE ATT&CK to enhance threat detection.

  • Design, implement, and maintain security monitoring use cases, correlation rules, detection content, and alerting mechanisms.

  • Lead the onboarding and integration of new log sources, security events, and cybersecurity solutions into the SIEM ecosystem.

  • Translate security monitoring policies and requirements into technical detection rules, operational controls, and monitoring procedures.

  • Securely configure, maintain, upgrade, and support cybersecurity systems, services, and products to ensure their resilience and effectiveness.

  • Implement, monitor, and continuously improve cybersecurity controls, procedures, and technical safeguards across the IT environment.

  • Evaluate security assessments, audit findings, vulnerabilities, and risks, prioritizing and implementing appropriate remediation measures.

  • Perform forensic investigations, provide expert support during security incidents, and contribute to incident response and threat analysis activities.

  • Define and maintain security dashboards, KPIs, reports, playbooks, technical documentation, and operational procedures supporting security operations.

  • Contribute to the design and evolution of security monitoring architectures, working closely with system owners and security operations teams to assess security event detection solutions and support the development of monitoring capabilities.

  • Ensuring that all activities and duties are carried out in full compliance with regulatory requirements and supporting the continued implementation of the Group Anti-Bribery and Corruption Policy.

  • Bachelor’s degree in Information Technology, Computer Science, Engineering, or a related field.

  • Minimum 10 years of IT experience, including at least 8 years in the relevant field.

  • At least three (3) internationally recognized certifications are required from the following: CISSP, CCSP, GIAC Penetration Tester (GPEN), Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, and TOGAF 9 Certified (or equivalent certification recognized)

  • Strong knowledge of Secure SDLC principles and the integration of security controls throughout the software development lifecycle.

  • Strong understanding of Windows, Linux, and network security architectures, including access controls, configuration auditing, security logging, network segmentation, secure protocols, and traffic analysis.

  • Expertise in enterprise security controls, security telemetry, anomaly detection, security monitoring, and threat detection engineering.

  • Strong knowledge of offensive and defensive security practices, including penetration testing, red teaming, incident triage, threat hunting, incident response, and detection use-case development.

  • Strong understanding of cybersecurity threats, vulnerabilities, exploit mechanisms, and adversarial tactics, with hands‑on application of MITRE ATT&CK and MITRE D3FEND frameworks.

  • Proficiency in scripting, automation, troubleshooting, and the implementation and configuration of enterprise security controls and cybersecurity monitoring solutions.

  • Hands‑on experience administering, integrating, and optimizing Splunk Enterprise, Splunk Enterprise Security, Splunk SOAR, Splunk UBA, and Cribl Stream platforms, including data ingestion pipelines and lifecycle management.

  • Experience developing, testing, and fine‑tuning SIEM correlation rules, detection logic, automated playbooks, and security orchestration workflows, leveraging MITRE ATT&CK and D3FEND methodologies.

  • Experience applying Infrastructure as Code (IaC) and CI/CD practices using Azure DevOps to deploy, configure, and manage security platforms and monitoring infrastructure.

  • Experience designing and implementing security monitoring capabilities and architectures, including High‑Level Designs (HLDs), Low‑Level Designs (LLDs), technical blueprints, security monitoring use cases, and supporting technical documentation.

  • Strong technical writing and communication skills, including the development of technical reports, security policies and procedures, business cases, cybersecurity roadmaps, executive presentations, and the evaluation of cybersecurity technologies, MSSPs, and strategic security initiatives.

  • Very good command of English (minimum B2 level).

  • Eligibility to obtain an EU Personal Security Clearance, at a later stage is required.

This role is an onsite opportunity Poland.

Your race, gender identity and expression, age ethnicity or disability make no difference in Quento we want to attract, develop, promote, and retain the best people based only on their ability and behavior.

Disclaimer: Quento collects and processes personal data in accordance with the EU General Data Protection Regulation (GDPR). We are bound to use the information provided within your job application for recruitment purposes only and not to share these with any third parties. For more details on the processing of your personal data during the Recruitment procedure, please be informed in theRecruitment Notice, before the submission of your application.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

CyberSecurity L&M Service Specialist
CyberSecurity L&M Service Specialist

Quento • Warszawa

On-site
PLN 90,000 - 130,000
Senior Cybersecurity L&M & SIEM Specialist
Senior Cybersecurity L&M & SIEM Specialist

Qualco Group • Warszawa

On-site
PLN 180,000 - 260,000
CyberSecurity Specialist
CyberSecurity Specialist

SEIDOR • Warszawa

On-site
PLN 180,000 - 260,000
CyberSecurity Logging & Monitoring Service Specialist
CyberSecurity Logging & Monitoring Service Specialist

Altherias • Warszawa

Hybrid
PLN 150,000 - 210,000
SIEM & Security Monitoring Specialist
SIEM & Security Monitoring Specialist

Quento • Warszawa

On-site
PLN 90,000 - 130,000
CyberSecurity L&M Service Specialist (Warsaw, 80% remote) – Frontex at The Whiteam
CyberSecurity L&M Service Specialist (Warsaw, 80% remote) – Frontex at The Whiteam

The Whiteam • Warszawa

Hybrid
PLN 180,000 - 240,000
CyberSecurity Logging & Monitoring (L&M) Service Specialist
CyberSecurity Logging & Monitoring (L&M) Service Specialist

TechTree • Warszawa

On-site
PLN 240,000 - 360,000
CyberSecurity L&M Service Specialist (Warsaw, 80% remote) – Frontex
CyberSecurity L&M Service Specialist (Warsaw, 80% remote) – Frontex

Twtspain • Warszawa

Hybrid
PLN 200,000 - 320,000
CyberSecurity L&M Service Specialist (Warsaw, 80% remote) – Frontex
CyberSecurity L&M Service Specialist (Warsaw, 80% remote) – Frontex

TheWhiteam • Warszawa

Hybrid
PLN 180,000 - 240,000
CyberSecurity Service & L&M Specialist
CyberSecurity Service & L&M Specialist

Aricoma • Warszawa

On-site
PLN 110,000 - 165,000
On-site in Warsaw
HO relocation possibility