Security Engineer
CyberSecurity L&M Service Specialist - European Union Agency
Warsaw
Apply on the employer's siteRole description
📢
CyberSecurity L&M Service Specialist
📍 Location: Onsite in Warsaw, Poland. Hybrid can be discussed.
🤝 Client: European Union Agency based in Warsaw, Poland
💼
About the job:
NTT DATA is currently looking for a CyberSecurity L&M Service Specialist for an EU agency in Warsaw.
This is a freelance / B2B contract with possibility for extensions for 3 more years.
💼
Your Tasks:
As a CyberSecurity L&M Service Specialist, these are the main tasks that you'll be responsible for:
- Maintain monitoring platforms by running regular health checks and assure licence utilisation is optimal
- Systems to be monitored Splunk with all available modules (UBA, Enterprise Security, SOAR, Cribl)
- Conduct analysis of provided logs to identify the most valuable ones, normalise them and create correlation rules. All of this in context of MITRE ATT@CK framework
- Engage with System Owners to assure that any new log source is onboarded to monitoring platform. Elaborate and translate the security monitoring policy into monitoring rules
- Review any new CyberSecurity regulation or audit findings in order to comply with same
- Develop, maintain and support security monitoring use-case engineering
- Contribute to the design of the overall monitoring architecture, in close relationship with the customers/system owners, on the one hand, and the security operations engineering team, on the other hand, by performing the assessment of security events detection solutions, development of solutions
🛠️
What You'll Bring:
✅
Technical Skills:
- Minimum 10 years of IT relevant professional experience (at least 8 years in a similar position)
- Knowledge of the Systems Development Life Cycle, with a strong understanding of Secure SDLC practices and the integration of security controls throughout the software development phases
- Knowledge of OS-level security architecture, including configuration auditing, access controls, and security event log analysis for Windows and Linux platforms
- Knowledge of network security architecture, including secure protocols, network segmentation, and the analysis of network traffic and telemetry logs
- Knowledge of enterprise security controls, including the design, implementation, and tactical understanding of what security telemetry to monitor and how to detect anomalies effectively
- Knowledge of offensive security practices, including penetration testing methodologies, red teaming operations, and understanding of real-world adversarial tactics and techniques
- Knowledge of defensive security practices, including security monitoring, incident triage, threat hunting, and the engineering of detection rules to systematically neutralize threat actors
- Knowledge of system security vulnerabilities, emerging cyber threats, and exploit mechanisms utilized by threat actors
- Knowledge of MITRE ATT&CK and MITRE D3FEND frameworks, with a proven ability to map offensive adversary TTPs to defensive countermeasures to optimize security architecture
- Proficient in providing technical support for the implementation and configuration of diverse security controls across the enterprise security ecosystem
- Proficient in authoring and testing secure scripts to automate security workflows, detection logic, and infrastructure management
- Proficient in identifying and troubleshooting cybersecurity monitoring related issues to ensure system integrity and minimize operational impact
- Experience in the administration, lifecycle management, and integration of enterprise security platforms, specifically focusing on data ingestion pipelines via Cribl Stream, and the architecture of Splunk Enterprise, Splunk Enterprise Security, Splunk SOAR, and Splunk UBA ecosystems
- Experience in developing, testing, and fine-tuning correlation searches within Splunk Enterprise Security, utilizing MITRE ATT&CK and D3FEND frameworks to map threat behaviours and optimize detection logic
- Experience in utilizing Infrastructure as Code (IaC) methodologies and CI/CD automation tools, specifically Azure DevOps, to deploy, configure, and manage security controls, Splunk Enterprise. Splunk Enterprise Security, and Cribl Stream infrastructure
- Proficiency in building and maintaining automated playbooks within Splunk SOAR
- Experience in designing tailored security monitoring capabilities, including the creation of High-Level Designs (HLD), Low-Level Designs (LLD), and technical blueprints as core architecture documentation
- Proficiency in technical report writing, with the ability to translate complex security metrics and incidents into actionable executive insights
- Experience in drafting security procedures and policies, with an emphasis on information protection and data privacy
- Experience in authoring comprehensive business cases to justify and launch new cybersecurity initiatives and technology deployments
- Experience in supporting the evaluation and selection of Managed Security Service Providers (MSSPs) and cybersecurity technology vendors through technical validation and capability mapping
- Experience in defining and developing strategic roadmaps for cybersecurity capabilities, coupled with the ability to effectively present and justify these roadmaps to executive sponsors and key stakeholders to secure funding and alignment
🎓
Education & Certifications:
-
Bachelor's degree
-
At least 3 certifications among:
1) CISSP or an equivalent certification
2) CCSP or an equivalent certification
3) GIAC Penetration Tester (GPEN) or an equivalent certification
4) Splunk Enterprise Certified Admin
5) Splunk Enterprise Security Certified Admin
6) At least TOGAF 9 Certified
or for any listed above, an equivalent alternative certification recognized internationally.
🗣️
Languages:
- English, Level B2 in Understanding, Speaking and Writing
🎁
What's in It for You?
- You will have the opportunity to work in an international and multi-cultural environment.
- You will be able to work for interesting projects managed by an EU Agency.
- Attractive compensation, tailored to your experience level.
✨
Ready to Join?
If you're excited to work in a role where you'll grow professionally and make an impact from day one - we'd love to hear from you!
🌍
Who We Are - NTT DATA
NTT DATA - a part of NTT Group - is a trusted global innovator of IT and business services headquartered in Tokyo. We help clients transform through consulting, industry solutions, business process services, IT modernization and managed services. NTT DATA enables clients, as well as society, to move confidently into the digital future. We are committed to our clients' long-term success and combine global reach with local client attention to serve them in over 50 countries. Visit us at nttdata.com.
This is a saved copy of a posting published elsewhere. Postings get taken down without notice — check the employer's site before applying. mentors.coach is not the hiring party.