About The Position

This role is for a CyberSecurity L&M Service Specialist focusing on Logging and Monitoring, Splunk and Cribl solutions, SecOps, and Threat Modelling. The position requires 20% on-site service provision at Frontex Headquarters and allows for 80% remote work. The mission duration is 48 months. A CONFIDENTIEL UE/EU CONFIDENTIAL security clearance is mandatory from the first day of assignment. The minimum education level required is Level 6, with a minimum English language skill of B2. The role demands a minimum of 10 years of IT relevant experience, with at least 8 years in relevant roles. Award criteria are split 50% Price and 50% Quality, with a minimum required scoring of 70% for the interview. Travel expenses are not foreseen. The rate is flexible and depends on the candidate's level, aligning with the European public grading system.

Requirements

  • Minimum of 10 years of IT relevant experience (8 years in relevant roles).
  • Minimum level of education: Level 6.
  • Minimum English language skills: B2.
  • At least 3 certifications required among: CISSP or an equivalent certification, CCSP or an equivalent certification, GIAC Penetration Tester (GPEN) or an equivalent certification, Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, At least TOGAF 9 Certified.
  • Knowledge of the Systems Development Life Cycle, with a strong understanding of Secure SDLC practices and the integration of security controls throughout the software development phases.
  • Knowledge of OS-level security architecture, including configuration auditing, access controls, and security event log analysis for Windows and Linux platforms.
  • Knowledge of network security architecture, including secure protocols, network segmentation, and the analysis of network traffic and telemetry logs.
  • Knowledge of enterprise security controls, including the design, implementation, and tactical understanding of what security telemetry to monitor and how to detect anomalies effectively.
  • Knowledge of offensive security practices, including penetration testing methodologies, red teaming operations, and understanding of real-world adversarial tactics and techniques.
  • Knowledge of defensive security practices, including security monitoring, incident triage, threat hunting, and the engineering of detection rules to systematically neutralize threat actors.
  • Knowledge of system security vulnerabilities, emerging cyber threats, and exploit mechanisms utilized by threat actors.
  • Knowledge of MITRE ATT&CK and MITRE D3FEND frameworks, with a proven ability to map offensive adversary TTPs to defensive countermeasures to optimize security architecture.
  • Proficient in providing technical support for the implementation and configuration of diverse security controls across the enterprise security ecosystem.
  • Proficient in authoring and testing secure scripts to automate security workflows, detection logic, and infrastructure management.
  • Proficient in identifying and troubleshooting cybersecurity monitoring related issues to ensure system integrity and minimize operational impact.
  • Experience in the administration, lifecycle management, and integration of enterprise security platforms, specifically focusing on data ingestion pipelines via Cribl Stream, and the architecture of Splunk Enterprise, Splunk Enterprise Security, Splunk SOAR, and Splunk UBA ecosystems.
  • Experience in developing, testing, and fine-tuning correlation searches within Splunk Enterprise Security, utilizing MITRE ATT&CK and D3FEND frameworks to map threat behaviors and optimize detection logic.
  • Experience in utilizing Infrastructure as Code (IaC) methodologies and CI/CD automation tools, specifically Azure DevOps, to deploy, configure, and manage security controls, Splunk Enterprise, Splunk Enterprise Security, and Cribl Stream infrastructure.
  • Proficiency in building and maintaining automated playbooks within Splunk SOAR.
  • Experience in designing tailored security monitoring capabilities, including the creation of High-Level Designs (HLD), Low-Level Designs (LLD), and technical blueprints as core architecture documentation.
  • Proficiency in technical report writing, with the ability to translate complex security metrics and incidents into actionable executive insights.
  • Experience in drafting security procedures and policies, with an emphasis on information protection and data privacy.
  • Experience in authoring comprehensive business cases to justify and launch new cybersecurity initiatives and technology deployments.
  • Experience in supporting the evaluation and selection of Managed Security Service Providers (MSSPs) and cybersecurity technology vendors through technical validation and capability mapping.
  • Experience in defining and developing strategic roadmaps for cybersecurity capabilities, coupled with the ability to effectively present and justify these roadmaps to executive sponsors and key stakeholders to secure funding and alignment.

Responsibilities

  • Knowledge of the Systems Development Life Cycle, with a strong understanding of Secure SDLC practices and the integration of security controls throughout the software development phases.
  • Knowledge of OS-level security architecture, including configuration auditing, access controls, and security event log analysis for Windows and Linux platforms.
  • Knowledge of network security architecture, including secure protocols, network segmentation, and the analysis of network traffic and telemetry logs.
  • Knowledge of enterprise security controls, including the design, implementation, and tactical understanding of what security telemetry to monitor and how to detect anomalies effectively.
  • Knowledge of offensive security practices, including penetration testing methodologies, red teaming operations, and understanding of real-world adversarial tactics and techniques.
  • Knowledge of defensive security practices, including security monitoring, incident triage, threat hunting, and the engineering of detection rules to systematically neutralize threat actors.
  • Knowledge of system security vulnerabilities, emerging cyber threats, and exploit mechanisms utilized by threat actors.
  • Knowledge of MITRE ATT&CK and MITRE D3FEND frameworks, with a proven ability to map offensive adversary TTPs to defensive countermeasures to optimize security architecture.
  • Proficient in providing technical support for the implementation and configuration of diverse security controls across the enterprise security ecosystem.
  • Proficient in authoring and testing secure scripts to automate security workflows, detection logic, and infrastructure management.
  • Proficient in identifying and troubleshooting cybersecurity monitoring related issues to ensure system integrity and minimize operational impact.
  • Experience in the administration, lifecycle management, and integration of enterprise security platforms, specifically focusing on data ingestion pipelines via Cribl Stream, and the architecture of Splunk Enterprise, Splunk Enterprise Security, Splunk SOAR, and Splunk UBA ecosystems.
  • Experience in developing, testing, and fine-tuning correlation searches within Splunk Enterprise Security, utilizing MITRE ATT&CK and D3FEND frameworks to map threat behaviors and optimize detection logic.
  • Experience in utilizing Infrastructure as Code (IaC) methodologies and CI/CD automation tools, specifically Azure DevOps, to deploy, configure, and manage security controls, Splunk Enterprise, Splunk Enterprise Security, and Cribl Stream infrastructure.
  • Proficiency in building and maintaining automated playbooks within Splunk SOAR.
  • Experience in designing tailored security monitoring capabilities, including the creation of High-Level Designs (HLD), Low-Level Designs (LLD), and technical blueprints as core architecture documentation.
  • Proficiency in technical report writing, with the ability to translate complex security metrics and incidents into actionable executive insights.
  • Experience in drafting security procedures and policies, with an emphasis on information protection and data privacy.
  • Experience in authoring comprehensive business cases to justify and launch new cybersecurity initiatives and technology deployments.
  • Experience in supporting the evaluation and selection of Managed Security Service Providers (MSSPs) and cybersecurity technology vendors through technical validation and capability mapping.
  • Experience in defining and developing strategic roadmaps for cybersecurity capabilities, coupled with the ability to effectively present and justify these roadmaps to executive sponsors and key stakeholders to secure funding and alignment.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service