petr diakovski

Главный специалист по информационной безопасности (Континент 4, Соболь 4)

Наш клиент — аккредитованная Минцифры российская научно-производственная ИТ-компания полного цикла с собственным R&D-центром и производством в Санкт-Петербурге. В связи с плановым расширением деятельности и получением профильных лицензий ,…

petr diakovski На сервисе с: 05.10.26 13:25

от 200k ₽РоссияСанкт-ПетербургОфис

Наш клиент — аккредитованная Минцифры российская научно-производственная ИТ-компания полного цикла с собственным R&D-центром и производством в Санкт-Петербурге. В связи с плановым расширением деятельности и получением профильных лицензий, мы ищем ведущего эксперта в команду ИБ.

В целях соблюдения внутренней политики конфиденциальности и информационной безопасности, точное название компании и адрес компании предоставляются успешным кандидатам по итогам первичного собеседования.

Вам предстоит осуществлять технический контроль ИТ-подрядчика, развивать систему мониторинга и управлять ключевыми средствами защиты (в приоритете — продукты «Кода Безопасности»). Мы гарантируем полностью «белую» заработную плату выше рыночного уровня, сильную инженерную культуру и полное отсутствие бюрократии ради бюрократии.

Обязанности и задачи:

  • Управление и эксплуатация СЗИ: технический контроль, приемка работ у ИТ-подрядчика и администрирование ПАК «Континент 4» (ЦУС на платформе IPC-R300) и СДЗ «Соболь 4» (PCIe, A7).
  • Мониторинг и Incident Response: ежедневный анализ событий ИБ, расследование инцидентов (от веб-атак до шифровальщиков), базовый сбор цифровых доказательств и оптимизация плейбуков реагирования.
  • Технический аудит контура: регулярный аудит конфигураций серверов (Windows/Linux) и сетевого оборудования, поиск и устранение уязвимостей, настройка политик безопасности.
  • Администрирование ИБ-систем: развитие и сопровождение систем DLP, PAM, SIEM (уровня Solar Dozor, InfoWatch, SearchInform), NGFW, а также корпоративного VPN (OpenVPN, WireGuard).
  • Участие в подготовке компании к лицензированию, актуализация внутренних регламентов и политик ИБ с учетом требований законодательства.
Требования:

Важно: вакансия открыта в связи с получением лицензий, поэтому соответствие одному из следующих пунктов по образованию/стажу является обязательным условием:

  • Высшее профильное образование по направлению «Информационная безопасность» + опыт работы в ИБ от 3 лет (с подтвержденным стажем в ТК).
  • Иное высшее образование + профессиональная переподготовка по ИБ по программам, согласованным с ФСТЭК/ФСБ России, + стаж работы в ИБ от 3 лет (подтвержденный записью в ТК).​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​
  • Строго практический опыт развертывания и администрирования ПАК «Континент 4» и СДЗ «Соболь». Наличие действующих вендорских сертификатов «Кода Безопасности» будет вашим ключевым преимуществом!
  • Уверенные знания администрирования Windows (журналы событий, службы, права доступа) и Linux.
  • Глубокое понимание сетевой безопасности: стек TCP/IP, DNS, HTTP/HTTPS, VLAN, опыт работы с МЭ (UserGate, Ideco, Cisco ASA, iptables).
  • Опыт работы с ИБ-системами: уверенное чтение логов, знание жизненного цикла инцидента, базовое владение Wireshark.
  • Понимание нормативной базы: 152-ФЗ, 187-ФЗ, ПП 127, ПП 313 (знание ГОСТ 57580.1-2017 будет плюсом).
  • Будет преимуществом: навыки автоматизации (PowerShell, Bash, Python) и базовые знания в области компьютерной форензики.​​​​​​​

Что мы предлагаем:

  • Доход выше рынка: полностью официальная («белая») заработная плата (уровень обсуждается индивидуально с успешным кандидатом, мы готовы перекупать сильных экспертов).
  • Забота о здоровье: пакет ДМС после испытательного срока.
  • Надежность: работа в стабильной аккредитованной ИТ-компании, официальное оформление по ТК РФ.
  • Комфортный график: гибкое начало рабочего дня на ваш выбор (в 9:00, 9:30 или 10:00).
  • Современный офис и производство в Санкт-Петербурге.

Похожие вакансии Кибербезопасность

Сайты компаний
andersen

Vulnerability Management Consultant

andersenНа сервисе с: 05.10.26 14:14
Зарплата не указанаКипрГерманияИспанияПортугалияЧехияЛюксембургЛатвияЛитваЭстонияВенгрияФинляндияФранцияАвстрияДанияИталия

Andersen is hiring a Vulnerability Management Consultant for a project strengthening cybersecurity, managing vulnerabilities, and protecting critical systems in an international environment.

The customer is a large international organization that relies on modern technology and digital solutions to support its operations. Its activities involve secure IT infrastructure, data management, digital services, and the adoption of emerging technologies to improve operational efficiency and reliability.

The project is focused on providing cybersecurity and digital services for international organizations within a complex multi-tenant environment. It includes cyber defense operations, security incident management, and continuous protection of critical systems and services to ensure secure and reliable operations worldwide.

  • Running and improving the end-to-end vulnerability management process: discovery, scanning, prioritization, remediation tracking and verification.
  • Configuring and operating vulnerability scanning tools for infrastructure, cloud and web applications.
  • Prioritizing vulnerabilities by risk, using CVSS, EPSS, exploitability, threat intelligence and asset criticality.
  • Coordinating remediation with IT, application and infrastructure owners across multiple client organizations.
  • Managing exceptions and risk acceptance, and track SLA compliance.
  • Producing KPI/KRI reports and dashboards for technical and management audiences.
  • Advising on patch management, hardening baselines (e.g. CIS Benchmarks) and attack surface reduction.
  • Experience in cybersecurity for 5+ years, including 3+ years in vulnerability management.
  • Hands-on experience with at least one enterprise scanning platform (Tenable Nessus/Tenable.io/Tenable.sc, Qualys VMDR, Rapid7 InsightVM or Microsoft Defender Vulnerability Management).
  • Risk-based prioritization (CVSS, EPSS, CISA KEV, asset criticality).
  • Experience coordinating remediation across multiple teams and tracking SLAs.
  • Knowledge of patch management for Windows, Linux and network devices, and of hardening standards (CIS).
  • Clean record, ready for background verification.
  • Level of English – from Upper-Intermediate and above.
  • Cloud security posture management (e.g. Defender for Cloud, Wiz, Prisma Cloud).
  • Web application and container scanning.
  • Attack surface management tools.
  • Knowledge of ISO 27001 or NIST CSF.
  • Scripting (Python, PowerShell) for reporting automation and API integrations.
  • Certifications: CISSP, CompTIA Security+ or CySA+, vendor certifications (Tenable, Qualys).
  • Experience in teamwork with leaders in FinTech, Healthcare, Retail, Telecom, and others. Andersen cooperates with such businesses as Samsung, Siemens, Johnson & Johnson, BNP Paribas, Ryanair, Mercedes, TUI, Verivox, Allianz, T-Systems, etc..
  • The opportunity to change the project and/or develop expertise in an interesting business domain.
  • Guarantee of professional, financial, and career growth! The company has introduced systems of mentoring and adaptation for each new employee.
  • The opportunity to earn up to an additional 1,000 EUR per month, depending on the level of expertise, which will be included in the annual bonus, by participating in the company's activities.
  • Access to the corporate training portal, where the entire knowledge base of the company is collected and which is constantly updated.
  • Bright corporate life (parties / pizza days / PlayStation / fruits / coffee / snacks / movies).
  • Certification compensation (AWS, PMP, etc).
  • Referral program.
  • Private health insurance and sports compensation, depending on the type of employment.

Join us!

Сайты компаний
T

Information Security Engineer (SOC L2)

tabbyНа сервисе с: 05.10.26 13:47
Зарплата не указанаСаудовская АравияRiyadhОфис

About the role

Tabby creates financial freedom in the way people shop, earn and save by reshaping their relationship with money. Over 25 million users choose Tabby to stay in control of their spending and make the most out of their money.

The company’s flagship offering allows shoppers to split their payments online and in-store with no interest or fees. Over 70,000 global brands and small businesses, including Amazon, Noon, IKEA, and SHEIN use Tabby to accelerate growth and gain loyal customers by offering easy and flexible payments online and in stores.
Tabby generates over $18 billion in annual transaction volume for its partner brands and is the highest-rated, most-reviewed, largest, and fastest-growing FinTech in the GCC region.

Tabby launched in 2019 and has since raised +$1 billion in equity and debt funding from global and regional investors, and is now valued at $6,5 billion.

As Information Security Engineer, you’ll play a key part in monitoring and defending our infrastructure, applications, and cloud environments from cyber threats. 

You’ll lead incident response efforts, develop and tune detection rules, investigate security events, and collaborate with cross-functional teams to strengthen our security posture.

Responsibilities

Security Monitoring & Detection
  • Monitor and analyze logs and alerts from a wide range of sources including firewalls, intrusion detection/prevention systems (IDS/IPS), endpoints, servers, and cloud platforms.
  • Perform correlation of events from multiple sources to identify advanced threats and unusual patterns of behavior.
  • Fine-tune alert thresholds and detection logic to reduce false positives and improve signal-to-noise ratio.
  • Maintain dashboards and reporting to provide real-time visibility into security posture.

Incident Response & Investigation
  • Serve as a frontline responder for security incidents, managing incidents through their lifecycle – detection, containment, eradication, recovery, and lessons learned.
  • Coordinate with internal stakeholders and external vendors during high-severity incidents or data breaches.
  • Perform root cause analysis and forensic investigations using endpoint and network-based artifacts.
  • Maintain detailed incident documentation and contribute to post-mortem analysis and reports.

Threat Intelligence & Detection Rule Development
  • Research emerging threats and trends. 
  • Contribute to the creation and tuning of detection rules, threat-hunting queries, and use cases across multiple platforms including cloud environments.
  • Maintaining CTI Platform along with the integration of the CTI feeds with the security controls to have active CTI driven detections.

Collaboration and Communication
  • Communicate effectively with cross-functional teams including IT, DevOps, Risk, and Compliance during incidents and investigations.
  • Provide concise and clear updates during incident handling to stakeholders and management.
  • Mentor junior analysts and assist in training efforts within the SOC team.

Qualifications

  • 2–3 years of experience in a SOC or cybersecurity operations role, ideally in a fast-paced fintech or enterprise environment.
  • Strong knowledge of security best practices, including incident handling, alert triage, log analysis, and threat modeling.
  • Understanding of online technologies, REST APIs, microservices, and modern application architectures.
  • Experience working in a culturally diverse and collaborative environment.
  • Familiarity with DLP, AV, and anti-malware systems from an operational monitoring perspective.
  • Experience with phishing detection, user behavior analytics, and security awareness campaigns.
  • Security certifications such as Security+, CySA+, eCIR, eCTHPv2, GCIA, or GMON (preferred but not required).
  • Strong communication skills, especially for coordinating incident response and writing clear incident reports.
  • Experience with SIEM platforms, SOAR tools, EDR/XDR, and Threat Intelligence platforms.
  • Familiarity with cloud environments and cloud-native logging and monitoring tools.
  • Scripting experience (e.g., Python) to automate tasks and improve SOC efficiency.
hh.ru
Megaputer Intelligence, Компания

Ведущий специалист по информационной безопасности

Megaputer Intelligence, КомпанияНа сервисе с: 05.10.26 14:33
Зарплата не указанаРоссияМоскваУдалёнка

Мы ищем

Инициативного руководителя, готового решать задачи ИБ как самостоятельно, так и управляя небольшой командой, лично участвуя в операционных задачах. Человека, который умеет совмещать стратегическое видение и практическое исполнение. Не боится ручной работы, умеет взять инициативу и выстраивать процессы с нуля.​​​​​​​

Обязанности:

  • Разработка, актуализация и контроль исполнения организационно-распорядительной документации по ИБ: политики, регламенты, инструкции, положения;
  • Приведение ИТ-систем, производимых продуктов и документации к требованиям сертификаций МО, ФСТЭК, ФСБ;
  • Интеграция безопасности в CI/CD-процессы и автоматизацию проверок;
  • Подготовка документации, методики испытаний и сопровождение процессов сертификации продуктов компании регуляторами;
  • Проведение и документирование анализа уязвимостей;
  • Организация процессов SSDLC: статический и динамический анализ кода, управление зависимостями;
  • Взаимодействие с разработкой и DevOps для внедрения практик обеспечения безопасности ИТ системы;
  • Эксплуатация и обеспечение бесперебойной работы СЗИ: антивирусная защита, межсетевые экраны, системы обнаружения вторжений/предотвращения, DLP-системы;
  • Организация и проведение внутренних проверок и аудитов системы ИБ, взаимодействие с регуляторами в ходе контрольных мероприятий;
  • Участие в процедурах закупок и заключении договоров в соответствии с законодательством о закупках.
Требования:
  • Высшее техническое образование в области ИБ или ИТ очной формы обучения и стаж работы 3-5 лет в области прикладной ИБ;
  • При наличии непрофильного образования - прохождение программы профессиональной переподготовки в области ИБ 360+ ч в соответствии с Приказом Минобрнауки № 1316;
  • Знание и опыт применения нормативно-правовой базы РФ в области ИБ;
  • Опыт разработки и экспертизы документов по ИБ: организационно-распорядительной, проектной и эксплуатационной документации, моделей угроз и нарушителя;
  • Опыт администрирования средств защиты;
  • Умение проводить аудит, тестирование на проникновение и анализ уязвимостей;
  • Навыки работы с инструментами для анализа защищенности и тестирования на проникновение;
  • Понимание интеграции безопасности в CI/CD-процессы и автоматизацию проверок;
  • Опыт прохождения проверок ФСТЭК и ФСБ (как преимущество).
Условия:
  • Трудовой договор;
  • Реальное влияние на техническую стратегию;
  • Конкурентная зарплата по итогам собеседования;
  • Офис в пешей доступности от м. Бауманская и Красносельская.

HireSeeker собирает вакансии со всех площадок и присылает только релевантные. Бесплатно.