т1 иннотех

Стажер по информационной безопасности

Внедрять средства защиты информации в облачную инфраструктуру заказчиков компании и их сопровождение (администрирование, мониторинг работоспособности, управление ими, их конфигурирование);

т1 иннотех · На сервисе с: 01.10.26 11:47

Зарплата не указанаРоссияМоскваГибрид
Обязанности:
  • Внедрять средства защиты информации в облачную инфраструктуру заказчиков компании и их сопровождение (администрирование, мониторинг работоспособности, управление ими, их конфигурирование);
  • Пилотировать средства защиты информации совместно с архитекторами;
  • Управлять уязвимостями в информационной инфраструктуре совместно с ИТ-подразделением;
  • Осуществлять мониторинг информационной безопасности информационной инфраструктуры;
  • Принимать участие в проектировании систем информационной безопасности информационной инфраструктуры;
  • Принимать участие в проектировании систем информационной безопасности облачной информационной инфраструктуры для заказчиков;
  • Планировать задачи направления ИБ и контролировать сроки их выполнения;
  • Разрабатывать, актуализировать и вести внутреннюю нормативную и техническую документацию (регламенты, инструкции, политики);
  • Осуществлять сбор, систематизацию и анализ требований законодательства РФ, регуляторов (ФСТЭК, ФСБ, Роскомнадзор) и профильных стандартов ИБ.
Требования:
  • Образование Высшее / Неполное высшее (студенты от 3 курса и выше по специальности «Информационная безопасность»)
  • Понимание базовых принципов защиты информации, сетевых технологий и моделей безопасности (OSI, TCP/IP).
  • Знание структуры российского законодательства в области ИБ (понятия персональных данных, коммерческой тайны).
  • Умение работать с текстом, грамотность, внимательность к деталям при работе с документами.
  • Знания и навыки (желательные): Общее представление о требованиях регуляторов и стандартах: ФЗ-187 (КИИ), ФЗ-152 (ИСПДн), Требования к ГИС (Приказы ФСТЭК No 117 и 17), ГОСТ Р 57580, PCI DSS, ISO/IEC 27001.
  • Представление о целях, этапах и порядке проведения аттестации объектов информатизации (Приказ ФСТЭК России No 77).
  • Базовое понимание архитектуры облачных сервисов (IaaS, PaaS, SaaS).
  • Аналитический склад ума, способность работать с большими объемами нормативной и технической документации. Усидчивость, системность, высокая ответственность.
  • Желание развиваться в ИБ и проектировании систем защиты информации.
    Знание иностранного языка : Английский язык на уровне чтения технической документации (A2/B1).
  • Знание стека: Теоретические знания средств защиты информации (FW, IDS/IPS, WAF, VPN, VM, антивирусная защита) и принципов разграничения доступа (RBAC/ABAC).
  • Профессиональные навыки: Навыки разработки текстовых материалов (регламентов, инструкций, методичек или профильных курсовых работ). Навыки анализа ИТ-инфраструктуры

Похожие вакансии Кибербезопасность

Сайты компаний
V

Senior Cyber-Security Operations Analyst, Product AppSec

veeamНа сервисе с: 03.10.26 21:11
Зарплата не указанаСША

Veeam is the Data and AI Trust Company, specializing in helping organizations ensure their data and AI are fully understood, secured, and resilient to enable the acceleration of safe AI at scale. As the market leader in both data resilience and data security posture management, Veeam is built for the convergence of identity, data, security, and AI risk. Headquartered in Seattle with offices in more than 30 countries, Veeam protects over 550,000 customers worldwide, who trust Veeam to keep their businesses running. Join us as we go fearlessly forward together, growing, learning, and making a real impact for some of the world’s biggest brands.

#LI-REMOTE #LI-JC2

About the Role

We're looking for a Senior Cyber Security Operations Analyst to design, build, and scale secure enterprise development and QA environments across Azure-based software delivery ecosystems. You'll enhance Azure DevOps platform capabilities, improve CI/CD pipeline architecture, and integrate security throughout the software development lifecycle. This role works closely with Engineering, QA, Release Engineering, Platform Engineering, and Product Security teams to improve build reliability, deployment consistency, and operational efficiency. 

Due to the fact that this position will deal with highly sensitive data and will support federal customers, we are only considering US citizens at this time. Security clearance is not required, but there is a slight chance it maybe requested in the future 

What You’ll Do

  • Design, implement, and enhance Azure DevOps platform capabilities, including reusable CI/CD templates, pipeline standards, and developer enablement tooling
  • Build and optimize secure CI/CD pipelines supporting multiple product lines, integrating security scanning, secrets management, artifact validation, and policy enforcement
  • Build and support scalable development and QA environments, improving provisioning, configuration management, and deployment automation
  • Implement and maintain infrastructure-as-code solutions using Terraform, Ansible, and PowerShell across Azure cloud environments
  • Partner with Product Security and Infrastructure teams to embed secure-by-design principles into SDLC workflows and support vulnerability remediation initiatives
  • Monitor CI/CD platform health and troubleshoot pipeline failures, deployment issues, and environment-related problems
  • Mentor junior engineers and promote DevSecOps best practices across Engineering, QA, Security, and Infrastructure teams 

Technologies You’ll Work With

  • CI/CD platforms: Azure DevOps, GitHub Actions, Jenkins
  • IaC and automation: Terraform, Ansible, PowerShell, Python, Bash
  • Containerization: Docker, Kubernetes
  • Cloud: Azure (primary), with familiarity across AWS or GCP
  • Security tooling: SAST, SCA, secrets management, artifact repositories
  • Agentic AI and modern automation approaches

What You’ll Bring

  • 8+ years of experience in DevSecOps, DevOps, Platform Engineering, or Build Engineering
  • Strong hands-on experience with Azure DevOps, CI/CD pipeline engineering, and build and release automation
  • Experience with Terraform, Docker, Kubernetes, Git, PowerShell, Python, and Bash
  • Solid understanding of DevSecOps practices, IaC, Secure SDLC, and cloud security
  • Experience with software supply chain security frameworks (SLSA, NIST SSDF, OWASP SCVS)
  • Bachelor's degree in Computer Science, Engineering, or equivalent experience 

Bonus Skills

  • Experience implementing agentic AI engineering and development solutions
  • Relevant certifications such as Azure DevOps Engineer Expert, CDP, GCSA, CCSP, CKS, or HashiCorp Terraform Associate
  • Experience in regulated or compliance-driven environments
  • Familiarity with policy enforcement workflows, artifact repositories, and secrets management platforms 

What you'll get

  • Unlimited paid time off, 12 paid holidays including 4 global VeeaMe Days for self-care and 24 paid volunteer hours annually through Veeam Cares
  • Paid parental leave: 8 weeks for all parents, 16 weeks for birthing parents
  • Medical, dental, and vision coverage starting on your first day
  • Mental health support, therapy sessions, and digital wellness tools via our Employee Assistance Program
  • 401(k) retirement plan with company matching contributions
  • Fertility, adoption, and surrogacy support through Maven, plus paid volunteer time
  • AirVet: 24/7 virtual veterinary care at no cost
  • Legal services, identity protection, and supplemental health insurance options
  • Tax-advantaged spending accounts for healthcare, dependent care, and commuting
  • Opportunities to learn and grow through on-demand libraries (LinkedIn Learning, O’Reilly), mentoring, workshops, and learning events like our annual Global Day of Learning

Compensation Transparency

Veeam is committed to pay transparency and equitable compensation. For this role, the compensation range below reflects the expected total target compensation (TTC), inclusive of base pay and a competitive performance-based bonus. For roles with a commission plan, the compensation range represents On Target Earnings (OTE), which includes base salary plus variable commission. When determining compensation, Veeam takes into consideration factors such as experience, education, skills, and geographic zone. Offers are typically made below the midpoint of the range.

In addition to compensation, Veeam provides a comprehensive benefits package, including health coverage, retirement plans, and unlimited time off.

U.S. Geographic Zones & Compensation Ranges (TTC / OTE)
Zone 1: San Francisco Bay Area, New York City Boroughs
$174,960—$324,960 USD
Zone 2: Washington, California (excluding San Francisco Bay Area)
$160,380—$297,880 USD
Zone 3: Texas, Illinois, North Carolina, Colorado, Massachusetts, Pennsylvania, Virginia, Oregon, Nevada, Hawaii, New York (excluding NYC boroughs); Sales roles located in Georgia, Ohio, and Arizona
$145,800—$270,800 USD
Zone 4: All other US locations
$126,846—$235,596 USD

Veeam Software is an equal opportunity employer and does not tolerate discrimination in any form on the basis of race, color, religion, gender, age, national origin, citizenship, disability, veteran status or any other classification protected by federal, state or local law. All your information will be kept confidential.

Personal data collected during the recruitment process will be processed in accordance with our Recruiting Privacy Notice, which explains how your information is collected, used, and handled in connection with hiring activities. By applying for this position, you consent to this processing. 

By submitting your application, you confirm that the information provided, including any supporting documents, is complete and accurate to the best of your knowledge. Any misrepresentation, omission, or falsification may result in disqualification from consideration or, if discovered after employment begins, termination of employment.

Сайты компаний
V

Staff AI Security Engineer

veeamНа сервисе с: 03.10.26 21:08
Зарплата не указанаСШАКанадаSan Jose

Veeam is the Data and AI Trust Company, specializing in helping organizations ensure their data and AI are fully understood, secured, and resilient to enable the acceleration of safe AI at scale. As the market leader in both data resilience and data security posture management, Veeam is built for the convergence of identity, data, security, and AI risk. Headquartered in Seattle with offices in more than 30 countries, Veeam protects over 550,000 customers worldwide, who trust Veeam to keep their businesses running. Join us as we go fearlessly forward together, growing, learning, and making a real impact for some of the world’s biggest brands.

About the Role

Veeam VDC Security Engineering builds and operates the security platform for a multi-cloud (Azure and AWS) SaaS serving regulated industries. This role sits in Platform Security and helps drive AI/LLM security as a discipline. You will help shape how VDC uses large language models safely (defensively, at scale) and how we use them offensively to find and fix real security defects faster than traditional programs allow.

What You’ll Do

  • Design and ship the data-handling controls (code, filters, and infrastructure guardrails) for VDC's internal AI tooling and the AI features in our product. Redact sensitive data from prompts, model context, logs, and outputs before any of it reaches a third-party model provider
  • Build and productionize an AI-enhanced vulnerability reduction capability that plugs into CI/CD, surfaces real defects with a low false-positive rate, and either recommends or applies remediation without eroding developer trust
  • Publish and evolve a self-serve secure-LLM-use pattern for other VDC engineering teams, including input filtering, output validation, provider-tier data classification, and threat-model shortcuts for teams adding AI features to their products
  • Threat-model internal AI tools for prompt injection, indirect prompt attack surfaces, model exfiltration, and agent-tool boundary weaknesses. Partner with the red team on findings, then build the fixes and guardrails with tool owners
  • Partner with Compliance to shape auditor-facing evidence for AI-assisted controls, including which evidence formats hold up when the collector was an LLM and where human review must gate disclosure
  • Contribute the AI-security lens to adjacent Security Engineering programs where LLMs touch the surface area: vulnerability management maturity, supply chain risk reduction, code owners routing, and compliance evidence collection
  • Set VDC's direction on emerging LLM security tools and internal AI-forward workflows: what to adopt, what to skip, and what to build in-house

Technologies You’ll Work With

  • Azure OpenAI Service and other Azure AI Foundry components
  • Anthropic Claude, OpenAI, and multi-provider LLM APIs used across VDC internal tools
  • Microsoft Presidio, custom redaction pipelines, or equivalent PII/secrets detection at the prompt boundary
  • Cycode (SAST / SCA / Secrets) and Wiz for signal fusion into AI-driven remediation
  • GitHub Actions and Azure DevOps for CI/CD integration of security-review LLM tooling
  • Python and Go for the AI security tooling stack; comfort reading PowerShell and TypeScript for integration points
  • Microsoft Sentinel and Log Analytics for the audit trail on AI-mediated security operations

What You’ll Bring

  • 10+ years across security and engineering, with recent focus on AI/ML systems in production (LLM deployments, model risk, or AI-driven security tooling)
  • Hands-on experience shipping controls (Code, infra or data gaurdrails) that operate on LLM inputs and outputs (redaction, filtering, output validation, prompt-injection defense)
  • Build and tune detection systems that catch PII and secrets (API keys, credentials, personal data) across large, messy datasets, knowing when a regex rule is good enough, when you need a trained classifier, and when only an LLM can catch it, and justifying that choice on cost, latency, and accuracy grounds
  • Track record of taking AI/security work from concept to production, including designing for developer trust and false-positive management
  • Strong cloud security fundamentals across Azure and AWS: RBAC, secret management, key handling, network egress controls
  • Turn ad-hoc "is this LLM use case safe?" questions into a reusable mechanism (a scoring rubric in PR templates, a lint rule, an approval gate) that teams run themselves, instead of a doc they read once or a person they ping
  • Comfort building and hardening security tooling in Python and Go
  • Familiarity with regulated-industry evidentiary expectations (SOC 2 Type 2, ISO 27001, FedRAMP, HITRUST) and how AI-generated evidence intersects with them
  • Hands-on experience with agentic AI development environments (Claude Code, Cursor, GitHub Copilot Enterprise) and their operational security implications
  • A demonstrable track record of shipping production code (a code portfolio, open-source contributions, or internal build history). This is a hands-on building role, not an advisory one

Bonus Skills

  • Familiarity with LLM attack techniques (prompt injection, indirect prompt attacks, tool-boundary abuse, model exfiltration) enough to threat-model and build defenses
  • Background in traditional AppSec or SAST that translates cleanly to LLM-augmented vulnerability finding
  • Contributions to open-source LLM safety or evaluation projects (Presidio, PromptFoo, Garak, etc.)
  • Prior work with Azure OpenAI Service enterprise data-handling controls and LLM governance patterns
  • Experience integrating security tooling into developer workflows without becoming a merge-blocking bottleneck

 

#LI-SO2

What you'll get

  • Unlimited paid time off, 12 paid holidays including 4 global VeeaMe Days for self-care and 24 paid volunteer hours annually through Veeam Cares
  • Paid parental leave: 8 weeks for all parents, 16 weeks for birthing parents
  • Medical, dental, and vision coverage starting on your first day
  • Mental health support, therapy sessions, and digital wellness tools via our Employee Assistance Program
  • 401(k) retirement plan with company matching contributions
  • Fertility, adoption, and surrogacy support through Maven, plus paid volunteer time
  • AirVet: 24/7 virtual veterinary care at no cost
  • Legal services, identity protection, and supplemental health insurance options
  • Tax-advantaged spending accounts for healthcare, dependent care, and commuting
  • Opportunities to learn and grow through on-demand libraries (LinkedIn Learning, O’Reilly), mentoring, workshops, and learning events like our annual Global Day of Learning

Pay Transparency

Veeam is committed to pay transparency and equitable compensation. For this role, the compensation range below reflects the expected total target compensation (TTC), inclusive of base pay and a competitive performance-based bonus. For roles with a commission plan, the compensation range represents On Target Earnings (OTE), which includes base salary plus variable commission. When determining compensation, Veeam takes into consideration factors such as experience, education, skills, and geographic zone. Offers are typically made below the midpoint of the range.

In addition to compensation, Veeam provides a comprehensive benefits package, including health coverage, retirement plans, and unlimited time off.

Compensation Range (TTC / OTE)
$289,320—$537,360 USD

Veeam Software is an equal opportunity employer and does not tolerate discrimination in any form on the basis of race, color, religion, gender, age, national origin, citizenship, disability, veteran status or any other classification protected by federal, state or local law. All your information will be kept confidential.

Personal data collected during the recruitment process will be processed in accordance with our Recruiting Privacy Notice, which explains how your information is collected, used, and handled in connection with hiring activities. By applying for this position, you consent to this processing. 

By submitting your application, you confirm that the information provided, including any supporting documents, is complete and accurate to the best of your knowledge. Any misrepresentation, omission, or falsification may result in disqualification from consideration or, if discovered after employment begins, termination of employment.

hh.ru
Аквариус. Бэк-офис
Зарплата не указанаРоссияМоскваОфис

ПК «Аквариус» – ведущий российский разработчик, производитель и поставщик компьютерной техники и ИТ-решений для государственных и корпоративных заказчиков. В 2021 «Аквариус» стал 4-м в рейтинге CNews Analytics среди крупнейших российских IT-разработчиков.

Компания основана в 1989 году и сегодня располагает собственным производством международного уровня мощностью более 800 тыс. устройств в год и сетью сервисного обслуживания в 135 городах России.

Наша Компания активно развивается и растет, именно поэтому для нас так важно привлекать в свою команду только лучших - с высоким уровнем профессионализма и вовлеченности!

Добраться можно на корп. транспорте от м. улица 1905 г., Народное ополчение и м. Крылатское, есть бесплатная парковка.

Инженер по защите информации от утечки по техническим каналам

Основные задачи:

  • Выполнение работ, связанных с проведением аттестационных испытаний, контролем защищённости информации, обрабатываемой на объектах информатизации, предусматривающих:

  • Проведение оценки защищенности от утечки по техническим каналам;

  • Подготовку отчетных материалов по результатам работ.

Требования:

  • Высшее образование по направлению деятельности/подготовки (специальности) в области информационной безопасности или иное высшее в соответствии с действующими профессиональными стандартами в области защиты информации;

  • Знание требований нормативно-методических документов в области защиты информации от утечки по техническим каналам;

  • Опыт работы в указанной области;

  • Владение соответствующими средствами инструментального контроля защищенности информации;

  • Готовность к периодическим командировкам.

Мы предлагаем Вам:

  • Стать частью крупной стабильной компании разработчике и производителе компьютерной техники и IT‑решений, успешно развивающейся на российском рынке уже более 30-ти лет;
  • Возможность профессионального роста и развития;
  • ДМС после испытательного периода;
  • Грамотная система адаптации;
  • Возможность обучаться за счет компании (повышение квалификации);
  • Развитая корпоративная культура;
  • Оформление в соответствии с ТК РФ;
  • Удобный корпоративный транспорт (8-15 мин. от метро ул. 1905 г., народное ополчение и м. Крылатское), бесплатная парковка возле офиса.
  • График работы 5/2 с с 9.00 - 18.00, работа из офиса.
  • Ждем Ваше резюме! В отклике просим указывать релевантный опыт и финансовые ожидания.

HireSeeker собирает вакансии со всех площадок и присылает только релевантные. Бесплатно.