We are seeking an experienced Security Engineer to join our team. You will be responsible for real-time monitoring and analysis of security events implementation and optimization of SIEM solutions threat intelligence analysis incident response development and collaboration with various teams to improve organizational security posture. This role requires a strong background in cybersecurity hands-on experience with SIEM tools and excellent analytical and communication skills.
Key Responsibilities:
- Real-time monitoring and analysis
- Continuously monitor security alerts and events from multiple security tools and systems within the SOC.
- Analyze security incidents to assess severity and potential impact on the organization.
- Use advanced analytics and threat detection techniques to identify anomalies and suspicious activities.
- SIEM implementation and optimization
- Lead the deployment and configuration of Security Information and Event Management (SIEM) solutions.
- Fine-tune SIEM rules and alerts to reduce false positives and improve detection capabilities.
- Regularly review and update SIEM configurations to adapt to evolving threats and organizational changes.
- Threat intelligence analysis
- Collect analyze and disseminate threat intelligence from open-source commercial and internal sources.
- Correlate threat intelligence with security events to provide context and enhance incident response.
- Stay current with the latest threat trends vulnerabilities and attack vectors relevant to the organization.
- Incident response development
- Develop and maintain comprehensive incident response playbooks for various types of security incidents.
- Conduct tabletop exercises and simulations to test and refine incident response plans.
- Coordinate with cross-functional teams during incidents to ensure effective containment and remediation.
- Collaboration and security posture improvement
- Work closely with IT network and application teams to identify security gaps and recommend improvements.
- Participate in security assessments audits and vulnerability management processes.
- Share insights and findings with stakeholders to promote security awareness.
- Reporting and presentation
- Prepare detailed reports on security incidents.
- Present findings and trends to management and other stakeholders highlighting areas for improvement.
Qualifications :
Education: Bachelors degree in Computer Science Information Security or a related field or comparable job experience.
- Experience: At least 5 years of experience in SOC/SIEM and cybersecurity.
- Technical Skills:
- Strong knowledge in analyzing security events and threats.
- Experience with common SIEM tools (e.g. Splunk ArcSight QRadar).
- Familiarity with Threat Intelligence platforms and techniques.
- Understanding of network security firewalls IDS/IPS and other security technologies.
- Soft Skills:
- Strong analytical and problem-solving abilities.
- Team player with excellent communication skills.
Additional Information :
Hybrid work model 3 days per week from the office (Warsaw Lublin or Pozna).
Remote Work :
No
Employment Type :
Full-time