лига цифровой экономики

Эксперт по ASOC платформе

О проекте: мы создаем ASOC платформу, которая позволит командам разработки ПО получать единую картину реальных угроз безопасности и нейтрализовывать их.

лига цифровой экономики · На сервисе с: 29.09.26 16:12

Зарплата не указанаРоссияМоскваГибрид

О проекте: мы создаем ASOC платформу, которая позволит командам разработки ПО получать единую картину реальных угроз безопасности и нейтрализовывать их.

Твои задачи:

  • Проектировать архитектуру ASOC платформы - собирать, приоритезировать данные со сканеров SAST, DAST, SCA, secret detection.
  • Разрабатывать и развивать модули платформы - от интеграции со сканерами до логики автоматического триажа.
  • Автоматизировать рутину - писать скрипты и пайплайны, которые заменяют ручной разбор алертов на воспроизводимые процессы.
  • Встраивать инструменты безопасности в CI/CD внутренних и внешних команд разработчиков.
  • Проводить аудит зрелости процессов разработки ПО.
  • Готовить процессы и доказательную базу к сертификации по ГОСТ Р 56939-2024, BSIMM, SAMM так, чтобы результатом была успешная сертификация разрабатываемого ПО по требованиям безопасности информации.
Ждем от тебя:
  • Опыт пилотирования и внедрения нескольких решений из списка: SAST, DAST, SCA/OSA, ASOC/ASPM, API Security, Container Security.
  • Понимание архитектуры DevSecOps-процессов: как инструменты встраиваются в CI/CD, как управлять ложными срабатываниями, как строить метрики зрелости (MTTR, coverage, density of defects).
  • Знание российских и международных стандартов безопасности и умение их применять для улучшения процессов (ГОСТ Р 56939-2024, BSIMM, SAMM).
  • Высшее образование в сфере ИБ или ИТ.
Что мы обеспечим:
  • Официальное трудоустройство по ТК РФ.
  • Корпоративную технику для комфортной работы.
  • ДМС со стоматологией.
  • Участие в деятельности профессиональных сообществ.
  • Собственная корпоративная библиотека.
  • Возможность получать квалификацию за счёт компании.
  • Зимняя «витаминизация»: бесплатно фрукты в офисах.
  • Профессиональная текущая команда, готова делиться экспертизой.
  • Яркие корпоративы и нескучные тимбилдинги!
Эта вакансия также есть на:Habr Career

Похожие вакансии Кибербезопасность

Сайты компаний
T

Cybersecurity Teaching Experts

tripletenНа сервисе с: 03.10.26 20:10
Зарплата не указанаБразилияУдалёнка
Description

TripleTen is a service that empowers people, regardless of their prior experience, to embark on the exciting and challenging journey of mastering tech professions. Our bootcamps focus on training students in Data Analytics, Data Science, Web Development, Quality Assurance (QA) Engineering, and UX/UI Design — in an accessible and practical way, supporting them until they successfully thrive in a new career.


🚀 Our mission is to ensure that every student has the opportunity to successfully master a new profession, find their purpose, and become a valuable member of the tech industry.


What is our goal? We are continuously looking for experienced Cybersecurity professionals who want to support and guide our students on their path to becoming professional developers. This is a full-time teaching role with an expectation of 40 hours per week. The schedule can be flexible, but you must be consistently available to support students throughout their learning journey.

How to apply? Apply here. We review applications on a rolling basis, and candidates whose profiles align with the role will be invited to complete a digital interview, and complete a short technical test task.


If a vacancy is available, we will assign it to you right away; otherwise, we will keep your profile and completed task on file for future opportunities.


📌 Please submit your CV in English.

What you will do
  • Host regular live Q&A sessions to help students unblock and progress confidently
  • Offer personalized support through 1:1 video calls to answer questions and guide assignments
  • Occasionally respond to student questions via direct messages
  • Lead live lessons on core program topics and industry-relevant skills
  • Share your professional insights and best practices to support the learning community
  • Review student projects and provide feedback based on program standards
  • Write clear, actionable feedback to help students improve and meet expectations
  • Support students in text by explaining concepts, troubleshooting code, and clarifying project or review questions


Requirements

We require at least 3 years of hands-on experience in cybersecurity, with knowledge in:

  • Networking & Architecture: Understanding of flat vs. segmented networks, DMZs, and blast radius reduction.
  • Authentication & Access Abuse: Ability to identify risks related to privileged access, RDP usage, and mass data exports.
  • Incident Analysis: Experience investigating failed logins, password resets, and administrative account creation using MITRE ATT&CK tactics.
  • Log Analysis: Ability to analyze logs and identify suspicious patterns.
  • Python Programming: Ability to develop scripts for log processing, occurrence counting, and extracting relevant information.
  • Ability to explain complex topics clearly to beginners.
  • Patience and empathy toward students who are new to cybersecurity.
  • Availability to dedicate between 12 and 20 hours per week to the project, with a flexible schedule that may occasionally include weekends.
  • B1 English level and strong Spanish proficiency.
  • Ability to answer beginner-level questions with patience and practical examples.


Nice to have:

  • Previous teaching experience.
  • Experience guiding beginners one-on-one with clear, step-by-step instruction.


What we can offer you
  • Training in mentoring and communication techniques.
  • The opportunity to teach while continuing your main job.
  • The chance to share knowledge and experience with developers within our community.
  • Cross-cultural collaboration experience through mentoring and webinar facilitation.
  • Remote collaboration with a schedule that is convenient for both you and the team. We do not focus on micromanagement.
  • A comfortable digital office environment. We use modern digital tools such as Miro, Notion, Zoom, and others to ensure smooth collaboration.
  • A diverse and close-knit team distributed across the U.S. and Latin America.


Сайты компаний
T

Cybersecurity Teaching Experts

tripletenНа сервисе с: 03.10.26 20:10
Зарплата не указанаСШАПеруLimaУдалёнка
Description

TripleTen is a service that empowers people, regardless of their prior experience, to embark on the exciting and challenging journey of mastering tech professions. Our bootcamps focus on training students in Data Analytics, Data Science, Web Development, Quality Assurance (QA) Engineering, and UX/UI Design — in an accessible and practical way, supporting them until they successfully thrive in a new career.


🚀 Our mission is to ensure that every student has the opportunity to successfully master a new profession, find their purpose, and become a valuable member of the tech industry.


What is our goal? We are continuously looking for experienced Cybersecurity professionals who want to support and guide our students on their path to becoming professional developers. This is a full-time teaching role with an expectation of 40 hours per week. The schedule can be flexible, but you must be consistently available to support students throughout their learning journey.

How to apply? Apply here. We review applications on a rolling basis, and candidates whose profiles align with the role will be invited to complete a digital interview, and complete a short technical test task.


If a vacancy is available, we will assign it to you right away; otherwise, we will keep your profile and completed task on file for future opportunities.


📌 Please submit your CV in English.

What you will do
  • Host regular live Q&A sessions to help students unblock and progress confidently
  • Offer personalized support through 1:1 video calls to answer questions and guide assignments
  • Occasionally respond to student questions via direct messages
  • Lead live lessons on core program topics and industry-relevant skills
  • Share your professional insights and best practices to support the learning community
  • Review student projects and provide feedback based on program standards
  • Write clear, actionable feedback to help students improve and meet expectations
  • Support students in text by explaining concepts, troubleshooting code, and clarifying project or review questions


Requirements

We require at least 3 years of hands-on experience in cybersecurity, with knowledge in:

  • Networking & Architecture: Understanding of flat vs. segmented networks, DMZs, and blast radius reduction.
  • Authentication & Access Abuse: Ability to identify risks related to privileged access, RDP usage, and mass data exports.
  • Incident Analysis: Experience investigating failed logins, password resets, and administrative account creation using MITRE ATT&CK tactics.
  • Log Analysis: Ability to analyze logs and identify suspicious patterns.
  • Python Programming: Ability to develop scripts for log processing, occurrence counting, and extracting relevant information.
  • Ability to explain complex topics clearly to beginners.
  • Patience and empathy toward students who are new to cybersecurity.
  • Availability to dedicate between 12 and 20 hours per week to the project, with a flexible schedule that may occasionally include weekends.
  • B1 English level and strong Spanish proficiency.
  • Ability to answer beginner-level questions with patience and practical examples.


Nice to have:

  • Previous teaching experience.
  • Experience guiding beginners one-on-one with clear, step-by-step instruction.


What we can offer you
  • Training in mentoring and communication techniques.
  • The opportunity to teach while continuing your main job.
  • The chance to share knowledge and experience with developers within our community.
  • Cross-cultural collaboration experience through mentoring and webinar facilitation.
  • Remote collaboration with a schedule that is convenient for both you and the team. We do not focus on micromanagement.
  • A comfortable digital office environment. We use modern digital tools such as Miro, Notion, Zoom, and others to ensure smooth collaboration.
  • A diverse and close-knit team distributed across the U.S. and Latin America.


Сайты компаний
T

Application Security Engineer

tripletenНа сервисе с: 03.10.26 19:50
Зарплата не указанаНе указана странаЛокация не указанаУдалёнка
Description

Nebius Academy (powered by TripleTen) provides assessments and training for tech companies and aspiring professionals worldwide, helping companies & individuals transform their lives through career development and acquiring the new skills needed as a tech professional.

Our focus on data science, machine learning, and generative AI helps tech-forward companies level up their employees' skills and drive innovation.

We are looking for an Application Security Engineer to own product security end to end — from threat modelling and secure design reviews to vulnerability management and security controls embedded into CI/CD.

You will work closely with product and platform teams to make security part of the engineering process, building secure defaults and helping prevent vulnerabilities from reaching production without slowing development down.

What you will do
  • Own application and product security end to end, from design reviews and threat modelling to vulnerability remediation and follow-up.
  • Partner with product and platform teams to embed security into the development lifecycle rather than treat it as a final review step.
  • Build and improve security controls in CI/CD, including SAST, dependency, secrets, container, and IaC scanning.
  • Review application designs and code where security risk is meaningful, and turn recurring findings into secure defaults, shared libraries, lint rules, and CI gates.
  • Drive vulnerability management across application code and cloud posture, including triage, risk-based prioritisation, remediation timelines, and external pentest findings.
  • Strengthen security in multitenant B2B systems, including tenant isolation, authentication, authorization, RBAC / ABAC, and access controls.
  • Work on cloud and Kubernetes security across AWS environments, including IAM, secrets management, network boundaries, and workload hardening.
  • Help translate GDPR, SOC 2, and ISO 27001 requirements into practical engineering controls and system properties.
  • Develop and support a security champions programme to help engineering teams adopt secure practices in their day-to-day work.
  • Address security risks specific to AI and LLM-powered features, including prompt injection, data leakage, and untrusted model output.
Requirements
  • 5+ years of engineering experience, including at least 2 years focused on Application Security or Product Security.
  • Strong software engineering background with the ability to read, review, and write production code; Python experience is highly preferred.
  • Deep practical knowledge of web application security, including OWASP Top 10, ASVS, authentication and session management, OAuth2 / OIDC / SAML, and authorization issues such as IDOR and broken access control.
  • Experience securing multitenant or B2B SaaS products, including tenant isolation, RBAC / ABAC, and access control models.
  • Hands-on experience embedding security into CI/CD, including SAST, SCA, secrets scanning, container scanning, and IaC scanning.
  • Strong experience with threat modelling, secure design reviews, and secure code reviews in collaboration with product and engineering teams.
  • Experience managing vulnerabilities based on risk, criticality, and exploitability, including remediation prioritisation and escalation when needed.
  • Working knowledge of AWS and Kubernetes security, including IAM, secrets management, network boundaries, and workload hardening.
  • Strong communication skills and the ability to explain security risks clearly to engineers, product managers, and auditors.
  • Fluent Russian and English at B2 level or above.

Nice to have:

  • Experience building a DevSecOps practice from scratch.
  • Experience running or participating in a Security Champions programme.
  • Hands-on penetration testing experience.
  • Experience securing LLM-powered or AI products.
  • Experience with SOC 2 or ISO 27001 from an engineering perspective.
  • Knowledge of software supply chain security, including SBOMs, SLSA, image signing, or similar practices.
What we can offer you
  • A supportive and proactive work environment.
  • Competitive compensation: 4000-6000 EUR Gross per month
  • Fully remote and full-time collaboration.
  • Modern digital tools for seamless collaboration.
  • Tangible results measured by student success.

HireSeeker собирает вакансии со всех площадок и присылает только релевантные. Бесплатно.