Pracuj.pl Hybrydowo Mid

Security Operations Specialist

KEEPIT POLAND SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ

⚲ Kraków, Stare Miasto

16 000–19 000 zł brutto / mies.

Wymagania

  • SIEM solutions
  • Security Operations
  • IT security

Opis stanowiska

Nasze wymagania:
IT security background (security related education or experience)
2+ years experience working in a Security Operations Cetner
Has a strong interest in emerging threats and technologies within cybersecurity.
Experience working with incident response and SIEM solutions
Experience developing detection logic
Experience working in Linux environments
Speaks and writes English

O projekcie:
In the role of a Security Operations Specialist, your primary responsibility is to ensure a prompt response to incidents. In addition, you will be responsible for developing new detection logic for our SIEM and, more broadly, helping promote a strong security culture across the company. You will work closely with engineering, product, operations, and internal penetrations teams.
All specialists contribute to the development of detection logic for our systems through a internally developed, structured workflow aligned with standard procedures and a detection-as-code framework.
Clear and accurate documentation of detection logic and playbooks is a critical part of our work. Applicants are therefore expected to have well-defined skills in documenting their work.

Zakres obowiązków:
Incident detection, analysis, and response
SIEM detection engineering and alert tuning
Linux system hardening and security monitoring
Network traffic analysis and security monitoring
Security documentation, playbooks, and procedures
Threat modelling
Risk management
Automation and scripting (CI/CD workflows)
Endpoint security (EDR/XDR)

Oferujemy:
Official employment – Umowa o pracę contract
4 additional working days of vacation leave per full calendar year
3 days of internal sick leave without a doctor`s note
Health and Life Insurance
Employee Capital Plan (PPK)
Multisport card compensation
Coverage of professional training sessions, meetups, etc.
English-speaking club with native speakers
Polish language classes
Internet and Glasses reimbursement
Cosy office in Krakow city centre (Długa, 72) with beverages, fruit, and cookies
Winter and summer parties, events, team-buildings

🔍 Dekoder Ogłoszenia

🔴
Has a strong interest in emerging threats and technologies within cybersecurity.
Oczekuje się, że kandydat będzie samodzielnie śledził nowinki i rozwijał się w obszarze cyberbezpieczeństwa, często poza godzinami pracy.
🔴
helping promote a strong security culture across the company.
Może oznaczać szkolenie innych działów lub edukowanie pracowników w zakresie bezpieczeństwa, co wykracza poza typowe obowiązki specjalisty ds. operacji bezpieczeństwa.
🟡
All specialists contribute to the development of detection logic for our systems through a internally developed, structured workflow aligned with standard procedures and a detection-as-code framework.
Choć brzmi to nowocześnie, może oznaczać, że będziesz musiał nauczyć się i pracować z wewnętrznym, specyficznym dla firmy narzędziem lub procesem, który nie jest standardem rynkowym.
🔴
Risk management
Może oznaczać odpowiedzialność za identyfikację i ocenę ryzyka, co jest szerszym zakresem niż tylko reagowanie na incydenty.
🔴
Automation and scripting (CI/CD workflow)
Oczekuje się, że będziesz automatyzował zadania i potencjalnie integrował je z procesami CI/CD, co może wymagać umiejętności programistycznych lub DevOps.