At Bayer we’re visionaries, driven to solve the world’s toughest challenges and striving for a world where ,Health for all, Hunger for none’ is no longer a dream, but a real possibility. We’re doing it with energy, curiosity and sheer dedication, always learning from unique perspectives of those around us, expanding our thinking, growing our capabilities and redefining ‘impossible’. There are so many reasons to join us. If you’re hungry to build a varied and meaningful career in a community of brilliant and diverse minds to make a real difference, there’s only one choice.
Security Monitoring Platform Developer (Azure Developer)
For Digital Hub Warsaw, we are looking for:
Security Monitoring Platform Developer (Azure Developer)
(Title stated in the contract: Cyber Security Engineer)
The Security Monitoring Platform Developer designs, implements, and maintains custom security automation applications within the CDC Cyber Security Monitoring (CSM) squad.
The role focuses on developing Azure-native application pipelines (Azure Functions, Logic Apps, Service Bus), integrating external security services, and enabling automated incident handling workflows in Microsoft Sentinel and Azure Data Explorer (ADX). Key deliverables include the CheckMail phishing analysis automation, MISP threat intelligence connector, SQL-based data replication, and complex Sentinel incident orchestration. This role is distinct from the Platform Engineer role: while the Engineer maintains infrastructure and platform operations, the Developer builds the custom application layer that runs on top of it as well as infrastructure components with larger code aspects.
At Bayer, we are committed to transparency, equal pay for equal work or work of equal value, and objective reward practices in line with EU and local regulations. The minimum monthly gross compensation for this role is 15 360 PLN, with final pay determined based on objective factors such as experience, qualifications, scope of responsibility, and internal alignment. This position is eligible for variable pay components, such as performance based bonuses, awarded in accordance with the applicable employee group, role scope, and compensation structure.
Your Tasks & Responsibilities:
- Develop and maintain the Checkmail automation pipeline- an Azure-native application for automated analysis, enrichment, LLM-based classification, and escalation of user-reported phishing emails, including Function Apps (Python), Logic Apps, Service Bus integration, ADX data persistence, and Sentinel incident creation
- Implement and operate the MISP2Sentinel threat intelligence connector- Azure Function App (Python) using PyMISP and MISP-STIX libraries to periodically push IoCs from DCSO-hosted MISP to the Sentinel Threat IntelligenceIndicator table via Upload Indicators API
- Develop Azure Function Apps (Python) for SQL-based data replication- building and maintaining data pipelines between Azure SQL Database, ADX, and Sentinel to provide context data for detection and enrichment workflows
- Design and implement complex security incident handling logic in Microsoft Sentinel- including multi-step enrichment workflows (VirusTotal, URLScan, CrowdStrike Sandbox), Analytics Rules, Automation Rules, and Logic App-based orchestration for SOC triage and ServiceNow ticketing
- Integrate external security APIs and services into the SIEM platform- including enrichment providers, sandbox integrations, and threat intelligence feeds, with proper error handling, retry logic, and Dead Letter Queue management
- Follow and contribute to the established IaaC deployment process- all application code and infrastructure deployed via GitHub Actions, Terraform, and the CSM GitHub repositories
- Ensure application reliability and observability- implement structured logging, health monitoring integration, Application Insights instrumentation, and proactive alerting for all developed components
- Support content handover and knowledge transfer- ensure all developed components are documented, follow CSM naming conventions, and are integrated into the established RBAC and deployment model
- Collaborate with CSM analysts to translate detection and automation requirements into scalable, maintainable application code.
Key working relations
Internal
- CSF & CDC teams
- IT & Security Operations
- Application / Development Teams
External
- IT Security, SIEM & UEBA providers and partners
- External SOC contractors
Qualifications & Competencies (education, skills, experience):
- Strong hands-on development experience in Python, including Azure Functions, async processing, and API integrations
- Experience with Azure PaaS services: Function Apps, Logic Apps, Service Bus, Key Vault, Event Hub, Application Insights
- Solid understanding of REST APIs, JSON, and data serialization formats (STIX, MISP event format)
- Experience with SQL databases and data pipeline patterns (Azure SQL, ADX/KQL is a strong plus)
- Understanding of Git-based workflows, IaaC (Terraform), and CI/CD (GitHub Actions)
- Experience in IT Security, SIEM, or related field- understanding of security incident lifecycle, detection engineering, and threat intelligence concepts
- Understanding of IT and enterprise systems including business processes and data flows
- Collaboration skills and ability to work in global teams across time zones
- University degree or equal experience, preferably in Computer Science, Information Technology, or Cyber Security
- Excellent oral and written communication skills (English required, German is a plus)
In addition, Bayer offers a competitive and holistic benefits package, including:
- Medical care above statutory requirements
- Flexible benefits supporting leisure, and well being/sports programs
- Life, accident, and disability insurance through group coverage
- Employer supported pension plans with regular company contributions
- Home office allowance to support hybrid or remote work
- Extra Paid Holidays
Benefits may vary depending on country, role, and employment conditions.
You feel you do not meet all criteria we are looking for? That doesn't mean you aren't the right fit for the role. Apply with confidence, we value potential over perfection.
WORK LOCATION: WARSAW AL.JEROZOLIMSKIE 158
Bayer welcomes applications from all individuals, regardless of race, national origin, gender, age, physical characteristics, social origin, disability, union membership, religion, family status, pregnancy, sexual orientation, gender identity, gender expression or any unlawful criterion under applicable law. We are committed to treating all applicants fairly and avoiding discrimination.
Bayer is committed to providing access and reasonable accommodations in its application process for individuals with disabilities and encourages applicants with disabilities to request any needed accommodation(s) using the contact information below.
Bayer offers the possibility of working in a hybrid model. We know how important work-life balance is, so our employees can work from home, from the office or combine both work environments. The possibilities of using the hybrid model are each time discussed with the manager.
Bayer respects and applies the Whistleblower Act in Poland.
Location:
Warsaw
Division:
CSF
Reference Code:
877177
