W

СISO ЕАптека

Объединённая компания Wildberries и Russ — это международная технологическая компания, образованная в результате слияния двух лидеров рынка — IT-компании Wildberries и оператора наружной рекламы Russ.

wildberries · На сервисе с: 02.10.26 11:02

Зарплата не указанаРоссияМосква

Объединённая компания Wildberries и Russ — это международная технологическая компания, образованная в результате слияния двух лидеров рынка — IT-компании Wildberries и оператора наружной рекламы Russ.

Вместе с масштабным развитием IT направления Wildberries и Russ развивает информационную безопасность. Мы решаем сложные и разнообразные задачи: от повышения защищенности каждого сервиса до развития безопасности в рамках всей нашей инфраструктуры.

RWB запускает масштабную инициативу в ЕАПТЕКЕ. Мы ищем сильного лидера для роли CISO — опытного человека с инженерным бэкграундом для руководства информационной безопасностью ЕАПТЕКА. Это ключевая роль в реализации стратегической инициативы, включая внедрение Указа Президента РФ № 250 и обеспечение соответствия требованиям Wildberries и регуляторов.

Ваша миссия:
Выстроить эффективную ИБ функцию ЕАПТЕКА, обеспечить соответствие требованиям RWB, регуляторов и безопасность бизнеса в условиях современного ландшафта угроз.

Обязанности

  • Реализация Указа Президента РФ №250 и обеспечение регуляторного соответствия;
  • Участие в разработке и внедрении стратегии ИБ ЕАПТЕКА;
  • Управление внутренней командой и координация с core-командами ИБ RWB;
  • Обеспечение прозрачной и понятной отчетности для руководства ЕАПТЕКА и ИБ RWB;
  • Выстраивание процессов защиты под ключ с учетом лучших практик.

Требования

  • У вас есть опыт работы с безопасностью на уровне бизнес-процессов, продуктов и IT-инфраструктуры;
  • У вас есть навыки взаимодействия с бизнесом и IT-командами для эффективного внедрения решений;
  • Обладаете знаниями современных технологий разработки, включая CI/CD, контейнеризацию и оркестрацию;
  • У вас есть понимание актуальных угроз и умений оценивать риски, опыт безопасной разработки;
  • Имеете навыки моделирования угроз и анализа рисков в современных IT-системах.

Условия

  • Обучение и развитие: языковые клубы, собственный корпоративный университет, программы развития управленческих навыков и многое другое;
  • Благополучие сотрудников: корпоративный пакет ДМС со стоматологией, корпоративный спорт, консультации психолога и дополнительные возможности аккредитованной IT-компании;
  • Множество сообществ: клуб спикеров, футбола, йоги, шахмат и т.д.;
  • Забота о семьях: создаем условия, в которых легко сочетать карьеру и заботу о близких – от гибкого подхода до масштабных проектов для детей сотрудников;
  • Скидки и партнерские программы: на обучение, страхование, покупки и многое другое;
  • Комфортная рабочая среда: бесплатное питание в офисе, современные офисы рядом с метро, корпоративная техника и портал для сотрудников.

Похожие вакансии Кибербезопасность

Сайты компаний
andersen

Head of Cybersecurity Solutions & Integration

andersenНа сервисе с: 03.10.26 15:10
Зарплата не указанаКипрГерманияИспанияПортугалияЛюксембургЛатвияЛитваМексикаЭстонияВенгрияФинляндияФранцияАвстрияДанияИталия

The IT company Andersen invites a Head of Cybersecurity Solutions & Integration to join its team.

Andersen is a pre-IPO software development company providing a full cycle of services. For over 19 years, we have been helping enterprises and middle-sized firms worldwide transform their businesses by creating effective digital solutions using innovative technologies.

Today, we are working with organizations from various parts of the world, including North America, Western Europe, Israel, Australia, and the UAE. Our expertise covers FinTech, Healthcare, Retail, Telecom, Media & Entertainment, Logistics, Travel & Hospitality, eCommerce, and other industries.

– Building the cybersecurity integration practice.

– Establishing and developing vendor partnerships (Palo Alto Networks, Microsoft, etc.), driving partner tier progression, and ensuring certifications.

– Identifying and onboarding regional partners and distributors, analyzing their business models, and building a partner network.

– Prioritizing directions and forming a service portfolio across solution classes: NGFW, EDR/XDR, SIEM, IAM/PAM, Cloud Security.

– Working with clients and supporting pre-sales on integration opportunities.

– Owning the practice development roadmap.

– Managing the P&L of the direction: KPIs for revenue and costs, supporting pipeline and deals.

– Aligning integration offerings with MSSP practices.

– Experience in cybersecurity for at least 6 years, of which at least 2 years in leadership roles at a systems integrator, VAR, or vendor.

– Hands-on understanding of several security solution classes: NGFW, EDR/XDR, SIEM, IAM/PAM, Cloud Security.

– Established relationships with vendors and partners; experience managing partner programs.

– Strong commercial understanding: deal structuring, resale margins, services attach.

– Entrepreneurial mindset, drive, and motivation by challenge.

– English proficiency at Upper-Intermediate level or higher.

– Vendor certifications: Palo Alto PCNSE, Microsoft Security, etc.

  • Andersen cooperates with such businesses as Samsung, Johnson & Johnson, Ryanair, Europcar, TUI, Verivox, Shypple, etc..
  • We offer the opportunity to gain experience in developing business relationships with the world's largest brands, as well as large-scale projects using cutting-edge technologies.
  • Interesting and high-profile deals, negotiation practice, and communication with C-level people.
  • The most important thing that we value in our employees is a commitment to continuous learning. The company supports them in this and gives them access to the best educational platforms, seminars, and practices. In addition, for over 19 years, Andersen has assembled a huge knowledge base and established a robust resource management institution.
  • We have been strengthening our expertise since 2007. During this time, we have formed excellent teams with streamlined processes, where you can learn something new from your colleagues every day and enjoy your work.
  • We at Andersen have many different ways to grow. You can improve as a specialist or a manager, and all your activities will be decently rewarded.

Join us!

Сайты компаний
andersen

Security Architect

andersenНа сервисе с: 03.10.26 15:10
Зарплата не указанаАрменияПортугалияОАЭКатарАргентинаАвстрия

Andersen is hiring a Security Architect to design secure, scalable architectures and strengthen cybersecurity across international digital transformation projects.

Andersen is a pre-IPO software development company that provides a full cycle of services, following project management standards and best practices. For over 19 years, we have been helping enterprises and middle-sized firms transform their businesses by creating effective digital solutions using innovative technologies.

Immerse yourself in a global landscape as we collaborate with enterprises spanning North America, Western Europe, Israel, Australia, and the UAE. Our diverse expertise extends across FinTech, Healthcare, Retail, Telecom, Media & Entertainment, Logistics, Travel & Hospitality, eCommerce, and more.

  • Acting as the lead technical authority in client meetings discovery sessions: identify the client's security risks, maturity gaps and business drivers.
  • Designing security services where standard offerings do not fit.
  • Defining solution architecture, scope, delivery model and effort estimates for proposals.
  • Presenting and defending solutions to CISOs, CIOs and executive stakeholders.
  • Supporting Delivery Managers in RFP responses and complex bids.
  • Generating demand through direct engagement with security leaders: workshops, briefings, advisory sessions.
  • Feeding market and client insights back into the service portfolio and roadmap.
  • Contributing to thought leadership: white papers, webinars, industry events.
  • Experience in cybersecurity for 5+ years, of which 2+ years in a client-facing role: pre-sales, security architecture, security consulting.
  • Broad knowledge across security domains: security operations, offensive security, cloud security, identity, incident response, governance and compliance.
  • Excellent communication and presentation skills; able to build rapport with senior stakeholders quickly.
  • Working knowledge of regulatory frameworks: ISO 27001, NIST CSF, DORA, NIS2, PCI DSS.
  • Level of English – from Upper-Intermediate+ and above.
  • CISSP, CCSP, SABSA, Microsoft SC-100 or equivalent; Russian, Arabic; experience with financial services clients.
  • Andersen cooperates with such companies as Siemens, Johnson & Johnson, AstraZeneca, BNP Paribas, Allianz, Ryanair, TUI, Verivox, Media Markt, etc..
  • For the past four years, our company has been growing annually by 60–100%, and we constantly involve top-notch specialists in our team.
  • Andersen has mentoring and adaptation systems for new employees, and transparent performance review and assessment systems will allow you to determine your development path and plan your growth.
  • The most important thing that we value in our employees is a commitment to continuous learning. The company supports them in this and gives them access to the best educational platforms, seminars, and practices. In addition, for over 19 years, Andersen has assembled a huge knowledge base and established a robust resource management institution.
  • We have been strengthening our expertise since 2007. During this time, we have formed excellent teams with streamlined processes, where you can learn something new from your colleagues every day and enjoy your work.
  • We are a cool young team of like-minded people communicating informally.
  • You'll have a stable and competitive salary and an extensive benefits package.
  • At Andersen, we have many different ways to grow. You can improve as a specialist or a manager, and all your activities will be decently rewarded.

Join us!

Сайты компаний
andersen

DevSecOps Architect / Technical Lead

andersenНа сервисе с: 03.10.26 15:03
Зарплата не указанаАрменияПортугалияОАЭКатарАргентинаАвстрияГибрид

Andersen is hiring a DevSecOps Architect / Technical Lead for a project modernizing digital banking architecture and enhancing security, scalability, and platform reliability.

The customer is a financial services organization providing banking products and digital solutions for individual and business clients. The company operates through an established service network and online platforms and is part of a larger international financial group, supporting ongoing development of its services for a broad client base.

The project is focused on defining a structured architecture roadmap for a large-scale digital banking transformation program. It includes target-state architecture, platform modernization, API governance, security, data and analytics, system decoupling, and phased migration of business capabilities to reduce system dependencies and accelerate future digital development.

The role requires a one-week on-site onboarding with the client in Slovenia. Travel and accommodation expenses are fully covered by the company. Candidates must be able and willing to travel to Slovenia for the onboarding.

  • Translating the DevSecOps master plan into a practical implementation roadmap.
  • Defining reusable CI/CD, security and release-management standards.
  • Supporting the transition from Bitbucket/Jenkins to Azure Repos and Azure Pipelines.
  • Implementing security scanning and release gates in CI/CD pipelines.
  • Configuring security controls for AKS, container images, identities and secrets.
  • Establishing artifact signing, SBOM generation and secure promotion processes.
  • Integrating platform security events with the bank’s monitoring and SIEM solutions.
  • Defining vulnerability-management, audit-evidence and incident-response processes.
  • Providing technical leadership, recommendations and knowledge transfer to delivery teams.
  • Participating directly in configuration, integration and troubleshooting activities.
  • Experience in DevSecOps, cloud security or platform security for 5+ years.
  • Proven experience designing and driving DevSecOps processes, architecture, or engineering standards across multiple teams, not only implementing predefined solutions within a single project.
  • Experience translating high-level security or DevSecOps strategy into a practical technical roadmap, architecture decisions, standards, and implementation guidance.
  • Experience owning technical decisions and driving the adoption of DevSecOps practices across engineering teams.
  • Strong hands-on experience with Microsoft Azure.
  • Hands-on experience implementing security controls and gates across CI/CD, including several of the following: SAST, SCA, DAST, secret scanning, IaC scanning, and container scanning.
  • Practical experience with Kubernetes and container security, preferably AKS.
  • Experience with Infrastructure as Code, preferably Terraform.
  • Experience with identity, secrets, and certificate management.
  • Understanding of software supply-chain security practices such as SBOM, artifact signing, provenance, and secure artifact promotion.
  • Ability to combine architecture and technical leadership with hands-on implementation and troubleshooting.
  • Experience mentoring or technically guiding engineers and working across development, platform, security, and architecture teams.
  • Level of English – from Upper-Intermediate and above.
  • Experience in banking, financial services, or another regulated industry.
  • Experience with Jenkins and Bitbucket, including migration to Azure DevOps.
  • Experience with Azure security services such as Key Vault, Azure Container Registry, Defender for Cloud / Containers, and Microsoft Sentinel.
  • Hands-on experience with security tools such as SonarQube, Sonatype, Gitleaks, Checkov, OWASP ZAP, DefectDojo, or similar.
  • Experience with software supply-chain security, including SBOM generation, artifact signing, provenance, and secure artifact promotion.
  • Experience with vulnerability-management and SIEM solutions.
  • Experience with policy-as-code and Kubernetes security controls such as Azure Policy, OPA, Gatekeeper, or other admission controls.
  • Understanding of DORA, audit traceability, segregation of duties, and security requirements in regulated environments.
  • Experience in teamwork with leaders in FinTech, Healthcare, Retail, Telecom, and others. Andersen cooperates with such businesses as Samsung, Siemens, Johnson & Johnson, BNP Paribas, Ryanair, Mercedes, TUI, Verivox, Allianz, T-Systems, etc..
  • The opportunity to change the project and/or develop expertise in an interesting business domain.
  • Job conditions – you can work both fully remotely and from the office or can choose a hybrid variant.
  • Guarantee of professional, financial, and career growth! The company has introduced systems of mentoring and adaptation for each new employee.
  • The opportunity to earn up to an additional 1,000 EUR per month, depending on the level of expertise, which will be included in the annual bonus, by participating in the company's activities.
  • Access to the corporate training portal, where the entire knowledge base of the company is collected and which is constantly updated.
  • Bright corporate life (parties / pizza days / PlayStation / fruits / coffee / snacks / movies).
  • Certification compensation (AWS, PMP, etc).
  • Referral program.
  • Private health insurance and sports compensation, depending on the type of employment.

Join us!

HireSeeker собирает вакансии со всех площадок и присылает только релевантные. Бесплатно.