CyberSecurity Logging & Monitoring Service Specialist

C&D Talent Advisory WROCŁAW 2026-08-23

Hiring via TechTree

This is a role that TechTree is recruiting for on behalf of one of its clients.

TechTree is an AI-driven recruitment platform working with high-growth companies.

When you apply, TechTree's AI Agent matches you not just to this role, but to other relevant opportunities across its network, so one application can unlock multiple roles.

CyberSecurity Logging & Monitoring (L&M) Service Specialist | Warsaw

TechTree's client is hiring a CyberSecurity Logging & Monitoring Service Specialist for a long-term security programme supporting a major EU agency in Warsaw.

This is a senior, hands-on opportunity combining SIEM engineering, security architecture, detection engineering, threat hunting, and offensive security within a highly regulated environment.

  • Location: Warsaw, Poland
  • Work model: On-site engagement
  • Employment: Contract
  • Contract duration: Initial 12 months, extendable up to 48 months
  • Estimated compensation: PLN 174,000–300,000 annually
  • Level: Mid-Senior,
  • Travel: None expected

What you'll do

  • Administer and architect Splunk Enterprise, Splunk ES, Splunk SOAR, Splunk UBA, and Cribl Stream
  • Design and maintain enterprise logging and monitoring architecture
  • Produce HLD/LLD documentation, security policies, and procedures
  • Build and improve detection rules and threat-hunting capabilities
  • Map security coverage against MITRE ATT&CK and D3FEND
  • Use penetration testing and red-team findings to strengthen blue-team detection
  • Support incident triage and security monitoring operations
  • Deploy and manage security infrastructure through Azure DevOps, CI/CD, and Infrastructure-as-Code
  • Prepare business cases and MSSP/vendor evaluations
  • Present security roadmaps and recommendations to senior stakeholders

What we're looking for

  • 10+ years of overall IT experience
  • 8+ years in security monitoring, SIEM, or a closely related role
  • Deep hands-on expertise with Splunk and Cribl Stream
  • Strong detection engineering, threat hunting, and incident-triage experience
  • Experience across both offensive and defensive security
  • Knowledge of MITRE ATT&CK and D3FEND
  • Experience producing security architecture documentation
  • Bachelor's degree or higher
  • English at B2+ level
  • At least 3 of the following certifications or recognised equivalents: CISSP, CCSP, GPEN, Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, TOGAF 9 Certified
  • Eligibility to obtain and hold CONFIDENTIEL UE / EU CONFIDENTIAL security clearance from day one
  • Ability to work in Warsaw

Strong advantages

  • Azure DevOps experience
  • Infrastructure-as-Code for security platforms
  • Business-case development
  • MSSP and vendor evaluations
  • Executive-level security communication

If this sounds like a fit, we'd love to hear from you. Apply today!