Cybersecurity Specialist (m/f/n)
We are looking for an experienced Cybersecurity Specialist (m/f/n) to join our client's team carrying out a project for one of the EU institutions located in Warsaw.
IMPORTANT: Please note that this position requires you to hold a security clearance at the “RESTREINT UE/EU RESTRICTED” level.
Typical tasks and responsibilities:
User & Solution Support: Provide cybersecurity support to users/customers and ensure sound operation of integrated security solutions.
System Configuration & Maintenance: Securely configure, maintain, and upgrade systems, services, products, and infrastructure.
Controls & Monitoring: Implement, monitor, and assure the performance of cybersecurity controls and procedures.
Documentation & Reporting: Document and report on security status, configurations, and update operational procedures.
IT Collaboration: Work closely with IT personnel on security actions and interact with network/system teams to develop solutions.
Vulnerability & Patch Management: Apply and manage technical patches to address vulnerabilities.
Architecture & Tech Support: Assist in designing, implementing, and supporting security technologies (access, filtering, email, AV, DLP, cloud, mobile).
Audits & Reviews: Actively participate in information security reviews and audits.
Incident Response & Monitoring: Monitor security systems, respond to events/alerts, and troubleshoot infrastructure faults or problems.
Tool Evaluation: Evaluate and recommend secure configurations and security tools for continuous improvement.
Change Management: Implement security changes according to ICT change management procedures.
Requirements Engineering: Identify, translate, and negotiate high-level security requirements with technical and non-technical stakeholders.
Service Continuity: Ensure service continuity for managed components according to defined SLAs.
Technical knowledge:
Security Fundamentals: Operating systems (OS) & computer network security, security controls, and both offensive & defensive security practices.
Vulnerabilities & Testing: Deep understanding of system vulnerabilities, threats, exploit mechanisms, penetration testing, remediation techniques, and risk analysis methodologies.
Standards & Frameworks: Strong knowledge of ISO 27000 family, SANS CIS critical security controls, and OWASP standards.
Protocols & IAM: Good knowledge of network protocols (SMTP, NTP, DNS, LDAP, DHCP, PKI/CA) and practical management of security within Identity and Access Management (IAM) solutions.
Development & Testing: Knowledge of SDLC (systems development life cycle), secure coding practices, and practical experience in designing and performing security tests.
Professional Experience: Hands-on experience in ICT as an Information Security Administrator or Specialist.
Professional skills:
Stakeholder Communication: Documenting, reporting, presenting, and communicating effectively with diverse stakeholders.
Security Integration & Config: Integrating cybersecurity solutions and configuring them in line with organizational security policies.
Assessment & Coding: Assessing security/performance of solutions, and developing/testing secure code and scripts.
Troubleshooting & Problem Solving: Identifying and resolving complex cybersecurity-related issues with an analytical mind, sharp attention to detail, and rapid learning.
Specific requirements:
Higher education.
At least 5 years of experience in this or a similar position.
At least 8 years of experience working in the IT industry.
Experience in PKI operations.
Experiance in the operations and maintenance of security monitoring platforms (Splunk, Sentinel, Darktrace).
Experience in operations of risk -based vulnerability management services (with Tenable) including penetration testing coordination.
Experience in deploying and managing PAM platforms.
Experience in application security testing with CheckMarx SAST and DAST.
Experience in implementation controls aligned with Zero Trust Architecture.
At least 3 certification among:
GCED (GIAC Certified Enterprise Defender) or equivalent.
GPPA (GIAC Certified Perimeter Protection Analyst) or equivalent.
GCCWN (GIAC Certified Windows Security Administrator) or equivalent.
GCUX (GIAC Certified UNIX Security Administrator) or equivalent.
GCCC (GIAC Certified Critical Controls) or equivalent.
SSCP (ISC)2 Certified Systems Security Practitioner) or equivalent.
CCSP (ISC2 Certified Cloud Security Professional) or equivalent.
CISSP (Certified Information Systems Security Professional) or equivalent.
CSSLP (ISC2 Certified Secure Software Lifecycle Professional) or equivalent.
GSEC (GIAC Certified Security Essentials) or equivalent.
ECSA (EC-Council Certified Security Analyst) or equivalent.
SCPO (SABSA Certified Security Operations & Service Management Practitioner) or equivalent.
ECSA (EC-Council Certified Security Analyst) or equivalent.
Note: each equivalent alternative means certification recognized internationally
Offer:
Rate: 550 - 600 EUR/MD net + VAT.
Contract: B2B cooperation with SHIMI.
Delivery mode: hybrid work: 50% on-site service provision (office in Warsaw)/50% remote.
Long‑term engagement: 230 MD/12 months with up to 3 possible extensions.
Benefits: Multisport card and private medical care.