CyberSecurity L&M Service Specialist (Warsaw, 80% remote) – Frontex
The White Team Capon Bridge, West Virginia, United States
IT Services and IT Consulting · 201-500 employees
About the role
The specialist will manage logging and monitoring solutions, including Splunk and Cribl, while designing and implementing enterprise security controls. They are responsible for threat hunting, incident triage, and mapping offensive tactics to defensive countermeasures using MITRE frameworks.
What they look for
Requirements
Candidates must have at least 10 years of relevant IT experience and hold a minimum of three professional certifications such as CISSP, CCSP, or Splunk Enterprise Certified Admin. A valid EU Confidential security clearance is required from the first day of the assignment.
Full description
CyberSecurity L&M Service Specialist (Warsaw, 80% remote) – Frontex
Profile: CyberSecurity L&M Service Specialist (Logging and Monitoring, Splunk and Cribl solutions, SecOps, Threat Modelling).
Place of performance: On-site service provision - Frontex Headquarters – 20% on-site + 80% remote.
Duration of the mission: 48 months.
Security Clearance: Is required (valid from the first day of assignment) - CONFIDENTIEL UE/EU CONFIDENTIAL.
Minimum level of education: Level 6.
Minimum English language skills: B2.
Minimum IT relevant experience: 10 years (8 years in relevant roles).
Award Criteria: 50% Price / 50% Quality.
Minimum required scoring for interview: 70%.
Travel expenses: Not foreseen.
Rate: Flexible. The rate offered depends on the candidate’s level, in accordance with the European public grading system. Further details are available upon discussion.
· NWH: 230days x4 years.
Required technical certificates:
At least 3 certifications are required among:
· CISSP or an equivalent certification.
· CCSP or an equivalent certification.
· GIAC Penetration Tester (GPEN) or an equivalent certification.
· Splunk Enterprise Certified Admin.
· Splunk Enterprise Security Certified Admin.
· At least TOGAF 9 Certified.
· Note: each equivalent alternative means certification recognized internationally (subject and scope to acceptance by Frontex as a valid credential).
Knowledge and Skills
· Knowledge of the Systems Development Life Cycle, with a strong understanding of Secure SDLC practices and the integration of security controls throughout the software development phases.
· Knowledge of OS-level security architecture, including configuration auditing, access controls, and security event log analysis for Windows and Linux platforms.
· Knowledge of network security architecture, including secure protocols, network segmentation, and the analysis of network traffic and telemetry logs.
· Knowledge of enterprise security controls, including the design, implementation, and tactical understanding of what security telemetry to monitor and how to detect anomalies effectively.
· Knowledge of offensive security practices, including penetration testing methodologies, red teaming operations, and understanding of real-world adversarial tactics and techniques.
· Knowledge of defensive security practices, including security monitoring, incident triage, threat hunting, and the engineering of detection rules to systematically neutralize threat actors.
· Knowledge of system security vulnerabilities, emerging cyber threats, and exploit mechanisms utilized by threat actors.
· Knowledge of MITRE ATT&CK and MITRE D3FEND frameworks, with a proven ability to map offensive adversary TTPs to defensive countermeasures to optimize security architecture.
· Proficient in providing technical support for the implementation and configuration of diverse security controls across the enterprise security ecosystem.
· Proficient in authoring and testing secure scripts to automate security workflows, detection logic, and infrastructure management.
· Proficient in identifying and troubleshooting cybersecurity monitoring related issues to ensure system integrity and minimize operational impact.
· Experience in the administration, lifecycle management, and integration of enterprise security platforms, specifically focusing on data ingestion pipelines via Cribl Stream, and the architecture of Splunk Enterprise, Splunk Enterprise Security, Splunk SOAR, and Splunk UBA ecosystems
· Experience in developing, testing, and fine-tuning correlation searches within Splunk Enterprise Security, utilizing MITRE ATT&CK and D3FEND frameworks to map threat behaviors and optimize detection logic.
· Experience in utilizing Infrastructure as Code (IaC) methodologies and CI/CD automation tools, specifically Azure DevOps, to deploy, configure, and manage security controls, Splunk Enterprise. Splunk Enterprise Security, and Cribl Stream infrastructure.
· Proficiency in building and maintaining automated playbooks within Splunk SOAR.
· Experience in designing tailored security monitoring capabilities, including the creation of High-Level Designs (HLD), Low-Level Designs (LLD), and technical blueprints as core architecture documentation.
· Proficiency in technical report writing, with the ability to translate complex security metrics and incidents into actionable executive insights.
· Experience in drafting security procedures and policies, with an emphasis on information protection and data privacy.
· Experience in authoring comprehensive business cases to justify and launch new cybersecurity initiatives and technology deployments.
· Experience in supporting the evaluation and selection of Managed Security Service Providers (MSSPs) and cybersecurity technology vendors through technical validation and capability mapping.
· Experience in defining and developing strategic roadmaps for cybersecurity capabilities, coupled with the ability to effectively present and justify these roadmaps to executive sponsors and key stakeholders to secure funding and alignment.
Tasks and Responsibilities
· Knowledge of the Systems Development Life Cycle, with a strong understanding of Secure SDLC practices and the integration of security controls throughout the software development phases.
· Knowledge of OS-level security architecture, including configuration auditing, access controls, and security event log analysis for Windows and Linux platforms.
· Knowledge of network security architecture, including secure protocols, network segmentation, and the analysis of network traffic and telemetry logs.
· Knowledge of enterprise security controls, including the design, implementation, and tactical understanding of what security telemetry to monitor and how to detect anomalies effectively.
· Knowledge of offensive security practices, including penetration testing methodologies, red teaming operations, and understanding of real-world adversarial tactics and techniques.
· Knowledge of defensive security practices, including security monitoring, incident triage, threat hunting, and the engineering of detection rules to systematically neutralize threat actors.
· Knowledge of system security vulnerabilities, emerging cyber threats, and exploit mechanisms utilized by threat actors.
· Knowledge of MITRE ATT&CK and MITRE D3FEND frameworks, with a proven ability to map offensive adversary TTPs to defensive countermeasures to optimize security architecture.
· Proficient in providing technical support for the implementation and configuration of diverse security controls across the enterprise security ecosystem.
· Proficient in authoring and testing secure scripts to automate security workflows, detection logic, and infrastructure management.
· Proficient in identifying and troubleshooting cybersecurity monitoring related issues to ensure system integrity and minimize operational impact.
· Experience in the administration, lifecycle management, and integration of enterprise security platforms, specifically focusing on data ingestion pipelines via Cribl Stream, and the architecture of Splunk Enterprise, Splunk Enterprise Security, Splunk SOAR, and Splunk UBA ecosystems.
· Experience in developing, testing, and fine-tuning correlation searches within Splunk Enterprise Security, utilizing MITRE ATT&CK and D3FEND frameworks to map threat behaviors and optimize detection logic.
· Experience in utilizing Infrastructure as Code (IaC) methodologies and CI/CD automation tools, specifically Azure DevOps, to deploy, configure, and manage security controls, Splunk Enterprise. Splunk Enterprise Security, and Cribl Stream infrastructure.
· Proficiency in building and maintaining automated playbooks within Splunk SOAR.
· Experience in designing tailored security monitoring capabilities, including the creation of High-Level Designs (HLD), Low-Level Designs (LLD), and technical blueprints as core architecture documentation.
· Proficiency in technical report writing, with the ability to translate complex security metrics and incidents into actionable executive insights.
· Experience in drafting security procedures and policies, with an emphasis on information protection and data privacy.
· Experience in authoring comprehensive business cases to justify and launch new cybersecurity initiatives and technology deployments.
· Experience in supporting the evaluation and selection of Managed Security Service Providers (MSSPs) and cybersecurity technology vendors through technical validation and capability mapping.
· Experience in defining and developing strategic roadmaps for cybersecurity capabilities, coupled with the ability to effectively present and justify these roadmaps to executive sponsors and key stakeholders to secure funding and alignment.
Similar roles
-
Cybersecurity Project Manager
Sopra Steria Singapore, Singapore
-
Application Security Engineer
Moniepoint Nigeria
-
Senior Security Engineer
Auctane Madrid, Community of Madrid, Spain · €75K–€83K/yr
-
Cybersecurity Co-Founder / CSO (100 % remote) (m/f/d)
EWOR GmbH Bradford, England, United Kingdom
-
IT Security Engineer
Sword Services Greece S.A. Athens, Attica, Greece
-
Cybersecurity Co-Founder / Head of Engineering (100 % remote) (m/f/d)
EWOR GmbH Karlsruhe, Baden-Württemberg, Germany