Technology Specialist - CDO (Cyber Defense and Operations)
Kraków, PL, 31-864
⚠️ We'll shut down after Aug 1st - try foo🦍 for all jobs in tech ⚠️
Digital & Technology Team (D&T) is an integral division of HEINEKEN Global Shared Services Center. We are committed to making Heineken the most connected brewery. That includes digitalizing and integrating our processes, ensuring best-in-class technology, and embedding a data-driven culture. By joining us you will work in one of the most dynamic and innovative teams and have a direct impact on building the future of Heineken!
Would you like to meet the Team, see our office and much more? Visit our website: Heineken (heineken-dt.pl)
The role Technology Specialist CDO is part of the Cyber Defense and Operations Tribe, Global Threat Response Product Team, responsible for delivering valuable product increments each sprint and building a cyber resilient organization by acting as a first line of defense against cyber-attacks and by educating the global organization on how to act and respond to security incidents to limit the business impact.
The CDO Tribe capabilities are aligned with the NIST frameworks and are grouped into Defensive Capabilities as Monitoring, Detection, Vulnerability Mng, Threath Intelligence; Offensive Capabilities as Incident Response, Penetration Testing; Threat Hunting Capabilities.
Your responsibilities would include:
- being the first responders to high-priority incidents, analyzing threats, doing investigations, and triage
- coordination/alignment of broader SOC Analysts team and associated activity, with emphasis on real-time proactive monitoring and incident response activity
- providing remote incident response activities and advice to support HEINEKEN operating companies during and immediately after security incidents
- identifying and investigating threats, responding promptly, and supporting security measures set by management
- creating and maturing operational security processes, procedures and SOPs for incident response
- carrying out in-depth investigations on Security events, raising incidents and supporting the Incident Management process
- occasionally being on-call to respond to incidents that arise outside of business hours (part of HOST duty)
- service management – operationally overseeing and coordinating third parties involved in incident response and security monitoring.
You are a good match if you have:
- 5+ years working experience in security operations center of international companies and with SIEM solutions
- Bachelor's degree or equivalent experience
- passion for security and enjoys solving problems
- understanding the Agile mindset and having basic knowledge of working in a Scrum Team. You show end-to-end ownership on work that you do
- excellent knowledge of English, written and verbal
- experience with outsourced managed services, using ITIL processes
- certifications such as CEH, CIR, CISM, CISA, CGEDIT, any of the OWASP or similar.
Technical experience:
- operational experience with SIEM (Azure Sentinel)– Log Management, Vulnerability scanning and IPS/IDS technologies
- operational experience with the Microsoft security stack (Defender)
- Kusto query language knowledge (KQL)
- industry standard security frameworks for information systems (NIST, ISO 27001/2, CSA, COBIT)
- familiarity with scripting programming, e.g., Bash, PowerShell, Python
- the Cyber Kill Chain & MITRE ATT&CK framework
- security solutions (SSL, Remote Access, IPSEC, Reverse Proxy, IDS/IPS, Firewall, Multi Factor Authentication)
- knowledge of :
- penetration testing, Malware engineering
- offensive security specialist (e.g pen tester, ethical hacker, etc.)
- sysadmin skills (Linux/MAC/Windows)
- network admin skills
- network security administrator
- enabling services (e.g NTP, SMTP, patching, Antivirus)
- server infrastructure (VMWare ESXi, storage, Azure, AWS)
- cryptography knowledge (basic algorithm knowledge)
- DB knowledge
- authentication protocol knowledge.
Soft Skills:
- being able to translate technical language into a story that can be understood, and cohesively present it back to different stakeholders with a clear message
- providing clear, concise and easily consumable communication with key technical and non-technical stakeholders
- able to work in a complex and highly externalized environment
- interested in continuous self-development through training and learning on the job. Being curious about new developments and technologies; educating yourself
- critical thinking and contextual analysis abilities
- investigative and analytical problem solving skills
- teamwork, can-do mentality
- strong time management skills and willing to go above and beyond where required
- working in a highly dynamic environment, whit high pressure situations
- ability to take decisive action based on available information in a timely manner
- ability to research and characterize security threats to include identification and classification of threat indicators
- strong time management skills and willing to go above and beyond where required
- be passionate about mentoring and coaching junior resources, sharing knowledge.
At HEINEKEN Kraków, we take integrity and ethical conduct seriously. If someone has concerns about a possible violation of legal regulations indicated in Polish Whistleblowing Act or our Code of Business Conduct, we encourage them to speak up. Cases can be reported to global team or locally (in line with the local HGSS Whistleblowing procedure) by selecting proper option in this tool or by communicating it on hotline.
#LI-AK1 #LI-HYBRIDWe offer:
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Agile Antivirus AWS Azure Bash CEH CISA CISM COBIT Cryptography Cyber defense Cyber Kill Chain Firewalls IDS Incident response IPS ISO 27001 ITIL Linux Malware MITRE ATT&CK Monitoring Network security NIST NIST Frameworks Offensive security OWASP Pentesting PowerShell Python Scripting Scrum Sentinel SIEM SMTP SOC VMware Windows
Perks/benefits: Career development Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.