IT Security Incident Response Specialist

Open 29d posting dated 2 weeks ago

In Cyclad, we work with top international companies to help them strengthen their technology capabilities and deliver secure, innovative solutions that support critical business operations. We are currently looking for an experienced IT Security Incident Response Specialist to join a Hybrid project within the transportation and infrastructure sector. In this role, you will be responsible for monitoring security systems, responding to cybersecurity incidents, and supporting the continuous improvement of the organization's security posture.

Project information:

  • Type of project: Manufacturing / Industry

  • Office Location: Warsaw, Poland

  • Work mode: Hybrid onsite presence 12 days per month

  • Budget: 70-90 PLN net/h - B2B

  • Project length: 20.07.2026 – 31.12.2026

  • Only candidates with citizenship in the European Union and residence in Poland

  • Start date: ASAP (depending on candidate’s availability)

Project scope:

  • Monitor and supervise security systems, including SIEM platforms, firewalls, IDS/IPS solutions, and other security monitoring tools used to detect suspicious activities within the IT infrastructure

  • Identify, classify, and investigate security incidents to determine their root causes and potential impact

  • Respond to cybersecurity incidents and coordinate incident management activities across relevant teams

  • Implement corrective actions following incident investigations and recommend improvements to the security infrastructure

  • Prepare detailed reports regarding detected incidents, investigation findings, and remediation activities

  • Develop, maintain, and update incident response procedures and security playbooks

  • Participate in the development and testing of Disaster Recovery Plans (DRP) and Business Continuity Plans (BCP)

  • Support and participate in internal and external security audits

  • Collaborate with infrastructure, system administration, and development teams to ensure effective incident resolution

  • Contribute to continuous improvement initiatives related to cybersecurity operations and incident response processes

Competence demands:

  • Strong commercial experience in IT Security Operations, Incident Response, or Cybersecurity

  • Fluent Polish language skills, both written and spoken (minimum C2 level)

  • Strong knowledge of cybersecurity threats and attack techniques, including phishing, ransomware, DDoS, APTs, SQL Injection, and Cross-Site Scripting (XSS)

  • Experience in malware detection and analysis using tools such as VirusTotal, Sandbox environments, or equivalent solutions

  • Hands-on experience with SIEM platforms and security event monitoring

  • Practical experience using network monitoring and traffic analysis tools such as Wireshark and tcpdump

  • Strong incident management skills covering the full lifecycle from detection through resolution

  • Experience performing root cause analysis and security risk assessments following incidents

  • Ability to prioritize incidents based on severity, business impact, and urgency

  • Experience collaborating with system administrators, infrastructure teams, and developers in complex IT environments

  • Strong analytical thinking and problem-solving skills

  • Ability to work independently and take ownership of security incidents

  • High attention to detail and commitment to security best practices

  • Industry certifications such as GCIH, CISSP, CEH, CompTIA Security+, or equivalent cybersecurity training will be considered an advantage

We offer:

  • Hybrid working model (Warsaw)

  • Full-time job agreement based on b2b

  • Opportunity to work within a critical infrastructure environment

  • Exposure to advanced cybersecurity technologies and incident response processes

  • Private medical care with dental care (covering 70% of costs)

  • Multisport card (also for an accompanying person )

  • Life insurance