Overview
Company
Profile match
Impact
Conditions
Benefits
Hiring process
Similar jobs
SHIMI is a Polish recruitment, IT body leasing, and HR outsourcing agency headquartered in Warsaw. The company provides talent acquisition and staff augmentation services across several core areas, including IT & Engineering, SSC/BPO (Shared Service Centers/Business Process Outsourcing), Finance, and Sales. Its service models include permanent placement recruitment, IT body leasing/contracting, and full HR and payroll administration for client organizations operating in Poland and across the EU.

Currently, for one of our Partners, we are looking for an experiencedCyberSecurity L&M Service Specialist (m/f/n) to support a long-term project delivered for an organization of the European Union based in Warsaw.

Requirements:

  • At least 10 years of professional experience in IT
  • A minimum of 8 years of experience in a similar position
  • High degree diploma in IT (bachelor or engineer)
  • Personal Security Clearance at EU Confidential level is required

At least 3 certifications among (or equivalent recognized internationally):

  • CISSP or an equivalent certification
  • CCSP or an equivalent certification
  • GIAC Penetration Tester (GPEN) or an equivalent certification
  • Splunk Enterprise Certified Admin
  • Splunk Enterprise Security Certified Admin
  • At least TOGAF 9 Certified

Knowledge and skills:

  • Knowledge of the Systems Development Life Cycle, with a strong understanding ofSecure SDLC practices and the integration of security controls throughout the software development phases
  • Knowledge of OS-level security architecture, including configuration auditing, access controls, and security event log analysis for Windows and Linux platforms
  • Knowledge of network security architecture, including secure protocols, network segmentation, and the analysis of network traffic and telemetry logs
  • Knowledge of enterprise security controls, including the design, implementation, and tactical understanding of what security telemetry to monitor and how to detect anomalies effectively
  • Knowledge of offensive security practices, including penetration testing methodologies, red teaming operations, and understanding of real-world adversarial tactics and techniques
  • Knowledge of defensive security practices, including security monitoring, incident triage, threat hunting, and the engineering of detection rules to systematically neutralize threat actors
  • Knowledge of system security vulnerabilities, emerging cyber threats, and exploit mechanisms utilized by threat actors
  • Knowledge of MITRE ATT&CK and MITRE D3FEND frameworks, with a proven ability to map offensive adversary TTPs to defensive countermeasures to optimize security architecture.
  • Proficient in providing technical support for the implementation and configuration of diverse security controls across the enterprise security ecosystem.
  • Proficient in authoring and testing secure scripts to automate security workflows, detection logic, and infrastructure management
  • Proficient in identifying and troubleshooting cybersecurity monitoring-related issues to ensure system integrity and minimize operational impact
  • Experience in theadministration, lifecycle management, and integration of enterprise security platforms, specifically focusing on data ingestion pipelines via Cribl Stream, and the architecture of Splunk Enterprise, Splunk Enterprise Security, Splunk SOAR, and Splunk UBA ecosystems
  • Experience in developing, testing, and fine-tuning correlation searches within Splunk Enterprise Security, utilizing MITRE ATT&CK and D3FEND frameworks to map threat behaviors and optimize detection logic
  • Experience in utilizing Infrastructure as Code (IaC) methodologies and CI/CD automation tools, specifically Azure DevOps, to deploy, configure, and manage security controls, Splunk Enterprise, Splunk Enterprise Security, and Cribl Stream infrastructure
  • Proficiency in building and maintaining automated playbooks within Splunk SOAR
  • Experience in designing tailored security monitoring capabilities, including the creation of High-Level Designs (HLD), Low-Level Designs (LLD), and technical blueprints as core architecture documentation
  • Proficiency in technical report writing, with the ability to translate complex security metrics and incidents into actionable executive insights
  • Experience in drafting security procedures and policies, with an emphasis on information protection and data privacy
  • Experience in authoring comprehensive business cases to justify and launch new cybersecurity initiatives and technology deployments
  • Experience in supporting the evaluation and selection of Managed Security Service Providers (MSSPs) and cybersecurity technology vendors through technical validation and capability mapping
  • Experience in defining and developing strategic roadmaps for cybersecurity capabilities, coupled with the ability to effectively present and justify these roadmaps to executive sponsors and key stakeholders to secure funding and alignment

Typical tasks and responsibilities:

  • Drive development, maintenance of Logging & Monitoring standards
  • Maintain monitoring platforms by running regular health checks and assure licence utilisation is optimal
  • Conduct analysis of provided logs to identify the most valuable ones, normalise them and create correlation rules. All of this in the context of the MITRE ATT@CK framework
  • Support security monitoring use-case engineering
  • Security events collection technical design. Integration of log sources into a SIEM solution.
  • Elaboration and translation of the security monitoring policy into monitoring rules
  • Integrate cybersecurity solutions and ensure their sound operation
  • Securely configure systems, services and/or products
  • Maintain and upgrade the security of systems, services and/or products
  • Implement cybersecurity procedures and controls
  • Monitor and assure the performance of the implemented cybersecurity controls
  • Evaluate results of security audits and tests, security findings, prioritises, plans, and implements remediation controls
  • Provide forensic analysis in response to information security incidents
  • Draft security plans
  • Draft Security Operating procedures (SecOps)
  • Implement (security policy) technical or operational controls at operational level including in products and systems
  • Evaluate risks, threats and consequences
  • Contribute to definition of security standards
  • Provide expert support to incident handlers
  • Configure the SIEM components for optimal performance
  • Improve correlation rules to ensure that the monitoring policy allows an efficient detection of potential incidents. For a new component to be monitored, this encompasses
  • Identifying the required logs/files/artefacts to collect from the monitored system and, if necessary, possible complementary devices to deploy
  • Elaborating the relevant detection and correlation rules
  • Reviewing and improving the monitoring policy on a regular basis
  • Define dashboards and reports for reporting on KPIs.
  • Produce qualified reports (including recommendations) or alerts to SOC customers and follow up on actions
  • Contribute to the design of the overall monitoring architecture, in close relationship with the customers/system owners, on the one hand, and the security operations engineering team, on the other hand, by performing the following tasks:
  • Assessment of security event detection solutions, development of solutions;
  • Produce and maintain accurate and up-to-date technical documentation, including processes and procedures (so-called playbook), related to use case engineering as well as support of SIEM ecosystem

Offer:

  • B2Bcontract signed with SHIMI
  • Long-term cooperation
  • Hybrid working model: 20% from the office in Warsaw, 80% remote
  • Benefits: Co-financing of private medical and sports packages
  • Work in a multinational environment
  • The candidate must be an EU citizen and must be working from Poland

Recommended for you based on this role

Similar stack
Same company
In your city
$64k – $70k per year • Remote • 4+ years exp • Warsaw
SQL
Databases
Snowflake
Apply
In office
SQL
Databases
Amazon Redshift
Apache Iceberg
MinIO
AI/ML
Airflow
dbt
Apply
In office
Python
Python
FastAPI
Databases
FAISS
PostgreSQL
AI/ML
Claude
Gemini
Langfuse
LangGraph
LLM
RAG
LangChain
DevOps
Azure
Bicep
Docker
Podman
Apply
$82k – $94k per year • Remote • 5+ years exp • Bachelor's Degree • Warsaw
C#
JavaScript
Node JS
TypeScript
C#
.NET
Frontend
Angular
Apply
In office • Master's Degree
Python
Databases
ElasticSearch
PostgreSQL
AI/ML
Haystack
LangChain
DevOps
AWS
Azure
CI/CD
Configuration Management
Docker
Grafana
Kubernetes
Prometheus
Terraform
Management
Confluence
Jira
Apply
DevOps Developer 4 days ago
Remote/Hybrid • 5+ years exp • Bachelor's Degree
Python
TypeScript
AI/ML
AI Agents
Claude
DevOps
AWS
CI/CD
Git
Terraform
Cybersecurity
SonarQube
Apply
In office • 5+ years exp • Bachelor's Degree
C#
JavaScript
TypeScript
C#
.NET
Frontend
Angular
Web Components
DevOps
OpenShift
Apply
Software Developer 12 days ago
In office
C#
C#
.NET
Apply
$61k – $72k per year • Remote • Full-Time • 3+ years exp • Warsaw
C#
Python
DevOps
CI/CD
Rest API
Apply
$116k – $118k per year • Remote • Internship • 5+ years exp • Warsaw
SQL
C#
C#
.NET
Analytics
Power BI
Apply
Career impact
Discover how this job can transform your career
Get a personal career forecast for this job - salary uplift, next-level role, skill boost and a 3-year financial impact, all calculated from your profile.
Personal salary uplift vs. your current pay
Your 3-year career trajectory
Skills you will level up in this role
3-year financial impact in dollars
Create free account
Free forever • Less than a minute • No credit card

Work setup

Location
Warsaw
Remote work
Remote/Hybrid

Compensation

Benefits
Hybrid work