IT Security Incident Response Specialist
In Cyclad, we work with top international companies to help them strengthen their technology capabilities and deliver secure, innovative solutions that support critical business operations. We are currently looking for an experienced IT Security Incident Response Specialist to join a Hybrid project within the transportation and infrastructure sector. In this role, you will be responsible for monitoring security systems, responding to cybersecurity incidents, and supporting the continuous improvement of the organization's security posture.
Project information:
Type of project: Manufacturing / Industry
Office Location: Warsaw, Poland
Work mode: Hybrid onsite presence 12 days per month
Budget: 70-90 PLN net/h - B2B
Project length: 20.07.2026 – 31.12.2026
Only candidates with citizenship in the European Union and residence in Poland
Start date: ASAP (depending on candidate’s availability)
Project scope:
Monitor and supervise security systems, including SIEM platforms, firewalls, IDS/IPS solutions, and other security monitoring tools used to detect suspicious activities within the IT infrastructure
Identify, classify, and investigate security incidents to determine their root causes and potential impact
Respond to cybersecurity incidents and coordinate incident management activities across relevant teams
Implement corrective actions following incident investigations and recommend improvements to the security infrastructure
Prepare detailed reports regarding detected incidents, investigation findings, and remediation activities
Develop, maintain, and update incident response procedures and security playbooks
Participate in the development and testing of Disaster Recovery Plans (DRP) and Business Continuity Plans (BCP)
Support and participate in internal and external security audits
Collaborate with infrastructure, system administration, and development teams to ensure effective incident resolution
Contribute to continuous improvement initiatives related to cybersecurity operations and incident response processes
Competence demands:
Strong commercial experience in IT Security Operations, Incident Response, or Cybersecurity
Fluent Polish language skills, both written and spoken (minimum C2 level)
Strong knowledge of cybersecurity threats and attack techniques, including phishing, ransomware, DDoS, APTs, SQL Injection, and Cross-Site Scripting (XSS)
Experience in malware detection and analysis using tools such as VirusTotal, Sandbox environments, or equivalent solutions
Hands-on experience with SIEM platforms and security event monitoring
Practical experience using network monitoring and traffic analysis tools such as Wireshark and tcpdump
Strong incident management skills covering the full lifecycle from detection through resolution
Experience performing root cause analysis and security risk assessments following incidents
Ability to prioritize incidents based on severity, business impact, and urgency
Experience collaborating with system administrators, infrastructure teams, and developers in complex IT environments
Strong analytical thinking and problem-solving skills
Ability to work independently and take ownership of security incidents
High attention to detail and commitment to security best practices
Industry certifications such as GCIH, CISSP, CEH, CompTIA Security+, or equivalent cybersecurity training will be considered an advantage
We offer:
Hybrid working model (Warsaw)
Full-time job agreement based on b2b
Opportunity to work within a critical infrastructure environment
Exposure to advanced cybersecurity technologies and incident response processes
Private medical care with dental care (covering 70% of costs)
Multisport card (also for an accompanying person )
Life insurance