CyberSecurity Logging & Monitoring (L&M) Service Specialist
The opportunity
We're hiring a CyberSecurity Logging & Monitoring (L&M) Service Specialist for a long-term, on-site engagement supporting the security operations of a major EU Justice & Home Affairs agency in Warsaw. This is a deep, hands-on role at the intersection of SIEM engineering, security architecture, and both offensive and defensive security practice.
The role
You'll own the logging & monitoring stack end-to-end - administering and architecting Splunk (Enterprise, ES, SOAR, UBA) and Cribl Stream, hardening detection coverage, and translating security requirements into concrete architecture and policy. You'll work closely with the wider security team, bridging red-team findings and blue-team operations, and will be expected to communicate technical roadmaps to non-technical stakeholders and executives.
What you'll do
Administer and architect Splunk Enterprise, Splunk ES, Splunk SOAR and Splunk UBA, plus Cribl Stream for data routing and pipeline management
Design and maintain logging & monitoring architecture, producing HLD/LLD documentation, security policies and procedures
Hunt threats and engineer detections, triaging incidents and mapping coverage against MITRE ATT&CK and D3FEND
Apply offensive security skills (pentesting, red teaming) to validate and improve detection and response capability
Deploy and manage security controls and Splunk/Cribl infrastructure as code, using CI/CD pipelines (Azure DevOps)
Produce business cases and vendor/MSSP evaluations, and present security roadmaps to executive stakeholders
What you bring
10+ years of overall IT experience, including 8+ years in a similar security monitoring / SIEM role
Deep hands-on expertise administering Splunk (Enterprise, ES, SOAR, UBA) and Cribl Stream
Strong grounding in both offensive (pentesting, red teaming) and defensive (threat hunting, detection engineering, incident triage) security, fluent in MITRE ATT&CK and D3FEND
Comfortable with Infrastructure-as-Code and CI/CD, specifically Azure DevOps, for deploying and managing security infrastructure
Ability to author HLD/LLD architecture documentation, security policies/procedures, business cases, and MSSP/vendor evaluations
Bachelor's degree or higher; English proficiency at B2+ level
At least 3 of the following certifications (or recognised equivalents): CISSP, CCSP, GIAC Penetration Tester (GPEN), Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, TOGAF 9 Certified
Willingness and eligibility to obtain and hold a CONFIDENTIEL UE/EU CONFIDENTIAL personal security clearance from day one
Logistics
Location: Warsaw, Poland - on-site at the client's HQ (approx. 20% on client premises / 80% off-site)
Engagement: long-term contract, initial 12-month term with the possibility of up to 3 annual renewals (up to 48 months total)
Start date: as early as October 2026
Travel: none foreseen
Clearance: CONFIDENTIEL UE/EU CONFIDENTIAL required from day one of assignment