Position:
Cybersecurity Specialist
Place of work:
Katowice/remotely
Working hours:
full time
Type of contract:
employment contract/B2B
Working system:
office/hybrid working
Level of experience:
mid/senior
Start date:
immediate start
Job description
We are an ICT provider for the healthcare sector and, as a key entity, are subject to the obligations arising from the NIS2 Directive and the Act on the National Cybersecurity System (uKSC). We are looking for a specialist to strengthen our newly formed CSIRT team and take on real, operational responsibility for the security of the protected healthcare environment and the organisations we serve — from incident monitoring and response, through vulnerability management, to identity, access and staff awareness-raising.
Job responsibilities:
You carry out some of your tasks as part of the CSIRT team, whilst others are carried out in collaboration with the team of system administrators and those responsible for compliance and data protection.
- SIEM/SOC — you maintain the SIEM as the backbone of the SOC — both in-house and as a service provided to client organisations: you connect and standardise log sources, create your own detection and correlation rules, and fine-tune automated responses (Active Response).
- Incident detection and response — you handle alerts from XDR-class agent-based host monitoring, analyse anomalies and carry out incident response in accordance with IR procedures (classification of events/incidents/faults, CIA analysis, intervention measures).
- Vulnerability management — you carry out regular scans using an authorised scanner, triage the results (CVE/CVSS/KEV), coordinate remediation with technical teams, and report on their status.
- Identity, access and secrets — you maintain MFA/2FA and a VPN, develop privileged account management (PAM) based on the least privilege model, and maintain a password repository: policies, service password rotation, roles and access auditing.
- Server and container security — you manage Linux servers and harden them in accordance with CIS guidelines, secure SSH access (keys, protection against dictionary attacks), automate repetitive tasks (e.g. CRON/Bash/Python) and secure container environments (Docker, LXC/LXD).
- Backups — you design and maintain backups of critical systems and their configurations using the 3-2-1 model, schedule and monitor tasks, carry out regular recovery tests, protect backups from the effects of ransomware, and manage their encryption and retention in accordance with business continuity policies.
- Network — you are responsible for network segmentation (including OT, backup/DC, corporate and medical networks, VoIP/PBX, and management) and iptables/nftables rules, and you support device monitoring via SNMP.
- Cryptographic posture — you manage the lifecycle of TLS/SSL certificates and the internal PKI/CA, enforce secure protocols and cipher suites on services (web, email, VPN, SSH), oversee key management (rotation, secure storage, access control) and the encryption of data at rest and in transit, as well as detect and eliminate weak cryptography.
- Email — securing the email system: anti-spam, password policy enforcement and optimisation.
- Security awareness — you design and run phishing campaigns and simulations (using your own scenarios, a test environment and data minimisation), analyse their effectiveness and train staff.
- Compliance and documentation — you help to develop security policies and procedures, as well as ISMS documentation (playbooks, logs, reports), in accordance with NIS2/uKSC and ISO 27001.
Requirements
At least 3 years’ experience in the field of IT cybersecurity.
- Excellent knowledge of Linux systems: administration, hardening in accordance with CIS guidelines, secure SSH configuration and automation.
- The practical implementation and maintenance of SIEM and agent-based XDR — from onboarding and log standardisation, through detection rules and correlation, to dashboards and response procedures.
- Experience in vulnerability management: scanning using an authorised scanner, triaging results, knowledge of CVE/CVSS/KEV, and coordinating remediation.
- Knowledge of networking concepts to the extent required for security and segmentation: TCP/IP, VLANs, network segmentation, routing, VPNs, iptables/nftables and SNMP.
- Cryptographic posture management, TLS/SSL certificates and PKI (lifecycle, renewal, revocation), protocol and cipher suite hardcoding, key management, and encryption of data at rest and in transit
- Experience in the field of identity and access management: MFA/2FA, privileged accounts (PAM) under the least privilege model, and password and secret management (password vault, rotation, policies, auditing).
- Maintaining backup systems: the 3-2-1 strategy, scheduling and monitoring tasks, recovery tests (RPO/RTO) and protecting backups against ransomware (non-modifiable/offline backups).
- Knowledge of containerisation in the context of security (Docker, LXC/LXD).
- Practical knowledge of the NIS2/uKSC and ISO 27001 requirements, and the ability to document these accurately (IR procedures, playbooks, ISMS, logs).
- Experience in running phishing campaigns and simulations, as well as security training.
- Readiness to respond to critical incidents outside standard working hours (on an ad hoc basis, in accordance with the arrangements agreed within the CSIRT team).
Nice to have:
- Knowledge of Microsoft service security issues, in particular Active Directory/LDAPS.
- Knowledge of network monitoring / NDR, including traffic collection architecture (SPAN/TAP) and anomaly analytics.
- Experience with industrial OT protocols.
We offer
- Stable employment with a company that has a well-established market position.
- Flexible employment arrangements and hybrid working.
- An advanced technology stack in the field of security.
- Short decision-making processes and a collaborative approach — you have a real say in the choice of tools and the direction of security measures.
- Support from an experienced team of administrators and close collaboration within the CSIRT team and with those responsible for compliance.
- Opportunities to develop your skills and gain certifications.
- The chance to gain experience in the regulated, demanding healthcare sector.
- Unlimited access to coffee, a friendly atmosphere and a modern office – and, most importantly, no parking problems!
Benefits
- Funding for sports activities
- Opportunity to work remotely
- Fruit
- Team-building events
- A computer for personal use
- No dress code
- Coffee / tea
- Water
- Staff car park
Further information
Please submit your application, including your CV, via the form below.
We reserve the right to contact selected candidates only.
Apply
Fields marked are required.