← Back to list

Job
Security Operations Analyst (SIEM Operations and Threat Detection)
Security Engineer
• Hybrid
• Full-time
•
Warsaw, Poland
Senior consultant role in a globally distributed Cyber Security Operations Center (CSOC), focused on improving threat detection and security operations. Remote, freelance full-time contract.
Responsibilities
- ▹Contribute to the development, implementation, validation, tuning and maintenance of security monitoring, analytics and detection capabilities across SIEM, EDR, cloud and other cybersecurity platforms
- ▹Support the operation, maintenance, optimization and continuous improvement of security monitoring and threat detection services
- ▹Participate in the onboarding, integration, testing and validation of security data sources, telemetry feeds and monitoring capabilities
- ▹Contribute to security content management, including use case lifecycle management, rule reviews, testing, tuning and content quality assurance
- ▹Collaborate with cyber threat intelligence, incident response and cybersecurity operations teams to translate operational and threat intelligence requirements into effective detection and monitoring capabilities
- ▹Under guidance, participate in cybersecurity architecture reviews of new or existing solutions and recommend improvements to monitoring and detection effectiveness
- ▹Contribute to the preparation and maintenance of cybersecurity operations metrics, dashboards, KPIs and service performance reports
- ▹Review, validate and assess the effectiveness of detections, monitoring configurations, operational processes and service deliverables
- ▹Gather and analyze operational feedback to identify opportunities for tuning, optimization, reducing false positives and improving detection quality
- ▹Contribute to quality assurance activities, including process reviews, control validation, service quality assessments and corrective actions
- ▹Support the development, review and maintenance of CSOC procedures, standards, documentation, knowledge base articles and operational guidance
- ▹Prepare and present technical reports, summaries, findings and recommendations to internal and external stakeholders
- ▹Take part in a rotating on-call shift schedule from Monday to Sunday: you are on standby outside standard working hours and only log in to resolve critical incidents if they arise
Requirements
- ▹5+ years of relevant experience in information technology, including triage of alerts and supporting security incidents
- ▹Proven experience administering a SIEM platform, preferably Splunk or Microsoft Sentinel
- ▹Experience with the usual SOC toolbox (e.g. SIEMs, EDRs) and the ability to autonomously perform technical analysis of security threats and collaborate with the Incident Response team
- ▹Deep knowledge of Microsoft Security tools (e.g. M365, Cloud App Security, Azure, Defender for Endpoint, Azure Security, Azure Sentinel and XDR)
- ▹Deep knowledge of cloud technologies (e.g. Azure, AWS and GCP)
- ▹Deep knowledge of SIEM tools such as Splunk, QRadar, ArcSight, MS Sentinel, ELK Stack
- ▹Knowledge of at least one EDR solution (MS Defender for Endpoint, CrowdStrike)
- ▹Knowledge of email security, network monitoring and incident response
- ▹Knowledge of Linux, Mac and Windows
Nice to have
- ▹Experience building SIEM architectures from initial design to implementation, including designing data ingestion pipelines for diverse log sources across cloud and on-prem environments
- ▹Proven knowledge of monitoring AWS environments (IaaS, SaaS, PaaS)
- ▹Knowledge of at least one general-purpose or shell scripting language (e.g. Ruby, Bash, PowerShell, Python)
- ▹Desirable certifications: MCSE, CCNA, Microsoft Azure (e.g. SC-200), GCIH, CEH, GCFA or any GIAC or similar certification
Soft skills
Excellent communication skillsCustomer-facing experience and oral communication skillsAbility to write documentation and reportsCreativity and ability to find innovative solutionsWillingness to learn on the jobConflict management and cooperation
What we offer
- ▹Remote position
- ▹Freelance, full-time contract
- ▹Training and career development
- ▹Multicultural team and international projects
About the company
Talan is an international consulting group that supports innovation and business transformation through technology. It has over 7,200 consultants in 21 countries and is headquartered in Paris.
Languages: Angol: C1
Similar jobs
Job
Security Operations Engineer
Capco
+3
💰 Salary: not specified
🏢 On-site
🗣️ EN

Job
Product Security Engineer (m/f/d)
Aras
Azure DevopsBicep
+7
💰 Salary: not specified
🏢 On-site
🗣️ EN

Job
Offensive Security Engineer, Penetration Testing
Pgcareers
+5
💰 Salary: not specified
🏢 On-site
WARSAW
🗣️ EN

Job
Cryptography Security Consultant
EY
Power BI
+2
💰 Salary: not specified
🏢 On-site
Łódź
🗣️ EN

Job
Information Security Analyst
Ajaia
Datadog
+1
$25,000–$32,000/yr
gross
🌍 Remote
🗣️ EN

Job
Security Engineer EDR
EY
Powershell
+2
💰 Salary: not specified
🏢 On-site
Rzeszów
🗣️ EN