Cybersecurity Specialist (m/f/n)
⚲ Warszawa
9 870 - 10 920 EUR netto (B2B)
Wymagania
- CheckMarx SAST
- CheckMarx DAST
- Public Key Infrastructure
- Splunk
- Sentinel
- Darktrace
- Tenable
- Privileged Access Management
Opis stanowiska
We are looking for an experienced Cybersecurity Specialist (m/f/n) to join our client's team carrying out a project for one of the EU institutions located in Warsaw.
IMPORTANT: Please note that this position requires you to hold a security clearance at the “RESTREINT UE/EU RESTRICTED” level.
Typical tasks and responsibilities:
• User & Solution Support: Provide cybersecurity support to users/customers and ensure sound operation of integrated security solutions.
• System Configuration & Maintenance: Securely configure, maintain, and upgrade systems, services, products, and infrastructure.
• Controls & Monitoring: Implement, monitor, and assure the performance of cybersecurity controls and procedures.
• Documentation & Reporting: Document and report on security status, configurations, and update operational procedures.
• IT Collaboration: Work closely with IT personnel on security actions and interact with network/system teams to develop solutions.
• Vulnerability & Patch Management: Apply and manage technical patches to address vulnerabilities.
• Architecture & Tech Support: Assist in designing, implementing, and supporting security technologies (access, filtering, email, AV, DLP, cloud, mobile).
• Audits & Reviews: Actively participate in information security reviews and audits.
• Incident Response & Monitoring: Monitor security systems, respond to events/alerts, and troubleshoot infrastructure faults or problems.
• Tool Evaluation: Evaluate and recommend secure configurations and security tools for continuous improvement.
• Change Management: Implement security changes according to ICT change management procedures.
• Requirements Engineering: Identify, translate, and negotiate high-level security requirements with technical and non-technical stakeholders.
• Service Continuity: Ensure service continuity for managed components according to defined SLAs.
Technical knowledge:
• Security Fundamentals: Operating systems (OS) & computer network security, security controls, and both offensive & defensive security practices.
• Vulnerabilities & Testing: Deep understanding of system vulnerabilities, threats, exploit mechanisms, penetration testing, remediation techniques, and risk analysis methodologies.
• Standards & Frameworks: Strong knowledge of ISO 27000 family, SANS CIS critical security controls, and OWASP standards.
• Protocols & IAM: Good knowledge of network protocols (SMTP, NTP, DNS, LDAP, DHCP, PKI/CA) and practical management of security within Identity and Access Management (IAM) solutions.
• Development & Testing: Knowledge of SDLC (systems development life cycle), secure coding practices, and practical experience in designing and performing security tests.
• Professional Experience: Hands-on experience in ICT as an Information Security Administrator or Specialist.
Professional skills:
• Stakeholder Communication: Documenting, reporting, presenting, and communicating effectively with diverse stakeholders.
• Security Integration & Config: Integrating cybersecurity solutions and configuring them in line with organizational security policies.
• Assessment & Coding: Assessing security/performance of solutions, and developing/testing secure code and scripts.
• Troubleshooting & Problem Solving: Identifying and resolving complex cybersecurity-related issues with an analytical mind, sharp attention to detail, and rapid learning.
Specific requirements:
• Higher education.
• At least 5 years of experience in this or a similar position.
• At least 8 years of experience working in the IT industry.
• Experience in PKI operations.
• Experiance in the operations and maintenance of security monitoring platforms (Splunk, Sentinel, Darktrace).
• Experience in operations of risk -based vulnerability management services (with Tenable) including penetration testing coordination.
• Experience in deploying and managing PAM platforms.
• Experience in application security testing with CheckMarx SAST and DAST.
• Experience in implementation controls aligned with Zero Trust Architecture.
At least 3 certification among:
• GCED (GIAC Certified Enterprise Defender) or equivalent.
• GPPA (GIAC Certified Perimeter Protection Analyst) or equivalent.
• GCCWN (GIAC Certified Windows Security Administrator) or equivalent.
• GCUX (GIAC Certified UNIX Security Administrator) or equivalent.
• GCCC (GIAC Certified Critical Controls) or equivalent.
• SSCP (ISC)2 Certified Systems Security Practitioner) or equivalent.
• CCSP (ISC2 Certified Cloud Security Professional) or equivalent.
• CISSP (Certified Information Systems Security Professional) or equivalent.
• CSSLP (ISC2 Certified Secure Software Lifecycle Professional) or equivalent.
• GSEC (GIAC Certified Security Essentials) or equivalent.
• ECSA (EC-Council Certified Security Analyst) or equivalent.
• SCPO (SABSA Certified Security Operations & Service Management Practitioner) or equivalent.
• ECSA (EC-Council Certified Security Analyst) or equivalent.
Note: each equivalent alternative means certification recognized internationally
Offer:
• Rate: 550 - 600 EUR/MD net + VAT.
• Contract: B2B cooperation with SHIMI.
• Delivery mode: hybrid work: 50% on-site service provision (office in Warsaw)/50% remote.
• Long‑term engagement: 230 MD/12 months with up to 3 possible extensions.
• Benefits: Multisport card and private medical care.
IMPORTANT: Please note that this position requires you to hold a security clearance at the “RESTREINT UE/EU RESTRICTED” level.
Typical tasks and responsibilities:
• User & Solution Support: Provide cybersecurity support to users/customers and ensure sound operation of integrated security solutions.
• System Configuration & Maintenance: Securely configure, maintain, and upgrade systems, services, products, and infrastructure.
• Controls & Monitoring: Implement, monitor, and assure the performance of cybersecurity controls and procedures.
• Documentation & Reporting: Document and report on security status, configurations, and update operational procedures.
• IT Collaboration: Work closely with IT personnel on security actions and interact with network/system teams to develop solutions.
• Vulnerability & Patch Management: Apply and manage technical patches to address vulnerabilities.
• Architecture & Tech Support: Assist in designing, implementing, and supporting security technologies (access, filtering, email, AV, DLP, cloud, mobile).
• Audits & Reviews: Actively participate in information security reviews and audits.
• Incident Response & Monitoring: Monitor security systems, respond to events/alerts, and troubleshoot infrastructure faults or problems.
• Tool Evaluation: Evaluate and recommend secure configurations and security tools for continuous improvement.
• Change Management: Implement security changes according to ICT change management procedures.
• Requirements Engineering: Identify, translate, and negotiate high-level security requirements with technical and non-technical stakeholders.
• Service Continuity: Ensure service continuity for managed components according to defined SLAs.
Technical knowledge:
• Security Fundamentals: Operating systems (OS) & computer network security, security controls, and both offensive & defensive security practices.
• Vulnerabilities & Testing: Deep understanding of system vulnerabilities, threats, exploit mechanisms, penetration testing, remediation techniques, and risk analysis methodologies.
• Standards & Frameworks: Strong knowledge of ISO 27000 family, SANS CIS critical security controls, and OWASP standards.
• Protocols & IAM: Good knowledge of network protocols (SMTP, NTP, DNS, LDAP, DHCP, PKI/CA) and practical management of security within Identity and Access Management (IAM) solutions.
• Development & Testing: Knowledge of SDLC (systems development life cycle), secure coding practices, and practical experience in designing and performing security tests.
• Professional Experience: Hands-on experience in ICT as an Information Security Administrator or Specialist.
Professional skills:
• Stakeholder Communication: Documenting, reporting, presenting, and communicating effectively with diverse stakeholders.
• Security Integration & Config: Integrating cybersecurity solutions and configuring them in line with organizational security policies.
• Assessment & Coding: Assessing security/performance of solutions, and developing/testing secure code and scripts.
• Troubleshooting & Problem Solving: Identifying and resolving complex cybersecurity-related issues with an analytical mind, sharp attention to detail, and rapid learning.
Specific requirements:
• Higher education.
• At least 5 years of experience in this or a similar position.
• At least 8 years of experience working in the IT industry.
• Experience in PKI operations.
• Experiance in the operations and maintenance of security monitoring platforms (Splunk, Sentinel, Darktrace).
• Experience in operations of risk -based vulnerability management services (with Tenable) including penetration testing coordination.
• Experience in deploying and managing PAM platforms.
• Experience in application security testing with CheckMarx SAST and DAST.
• Experience in implementation controls aligned with Zero Trust Architecture.
At least 3 certification among:
• GCED (GIAC Certified Enterprise Defender) or equivalent.
• GPPA (GIAC Certified Perimeter Protection Analyst) or equivalent.
• GCCWN (GIAC Certified Windows Security Administrator) or equivalent.
• GCUX (GIAC Certified UNIX Security Administrator) or equivalent.
• GCCC (GIAC Certified Critical Controls) or equivalent.
• SSCP (ISC)2 Certified Systems Security Practitioner) or equivalent.
• CCSP (ISC2 Certified Cloud Security Professional) or equivalent.
• CISSP (Certified Information Systems Security Professional) or equivalent.
• CSSLP (ISC2 Certified Secure Software Lifecycle Professional) or equivalent.
• GSEC (GIAC Certified Security Essentials) or equivalent.
• ECSA (EC-Council Certified Security Analyst) or equivalent.
• SCPO (SABSA Certified Security Operations & Service Management Practitioner) or equivalent.
• ECSA (EC-Council Certified Security Analyst) or equivalent.
Note: each equivalent alternative means certification recognized internationally
Offer:
• Rate: 550 - 600 EUR/MD net + VAT.
• Contract: B2B cooperation with SHIMI.
• Delivery mode: hybrid work: 50% on-site service provision (office in Warsaw)/50% remote.
• Long‑term engagement: 230 MD/12 months with up to 3 possible extensions.
• Benefits: Multisport card and private medical care.
🔍 Dekoder Ogłoszenia
🟡
experienced Cybersecurity Specialist
Poszukują kogoś, kto ma już na koncie projekty związane z bezpieczeństwem IT, a niekoniecznie kogoś z wieloletnim stażem na jednym stanowisku.
🟡
join our client's team carrying out a project for one of the EU institutions
Praca jest realizowana dla zewnętrznego klienta, a nie bezpośrednio dla instytucji UE, co może oznaczać pośrednictwo firmy rekrutacyjnej.
🟡
User & Solution Support
Może oznaczać zarówno pomoc techniczną dla użytkowników, jak i rozwiązywanie problemów z systemami bezpieczeństwa, co może być czasochłonne.
🟡
Assist in designing, implementing, and supporting security technologies
Rola może być bardziej wspierająca niż inicjująca, a zakres odpowiedzialności za projektowanie może być ograniczony.
🔴
Evaluate and recommend secure configuratio
Część zdania jest ucięta, co może sugerować niedbałość w tworzeniu ogłoszenia lub niepełny zakres odpowiedzialności.