directum

Инженер по информационной безопасности (Python)

Мы — крупная IT компания, создающая системы с богатым набором возможностей и искусственным интеллектом на борту. Наша компания помогает крупным и небольшим организациям развивать свой бизнес и становится эффективнее.

directum На сервисе с: 08.10.26 14:14

Зарплата не указанаРоссияИжевскОфис

Работа в офисе в г. Ижевск!

Мы — крупная IT компания, создающая системы с богатым набором возможностей и искусственным интеллектом на борту. Наша компания помогает крупным и небольшим организациям развивать свой бизнес и становится эффективнее.

Наши решения, как правило, относятся к ключевым системам предприятия. Поэтому обеспечение информационной безопасности наших продуктов и нашей инфраструктуры становится критически важными для обеспечения непрерывности бизнеса наших заказчиков.

Мы ищем инженеров ИБ для более масштабного развития практик информационной безопасности для нашей компании.

Чем предстоит заниматься:

  • аудитом ИБ предоставляемых сервисов;

  • активным противодействием возможным атакам на сервисы компании;

  • мониторингом, предотвращением и расследованием инцидентов безопасности в инфраструктуре компании;

  • выявлением и моделированием угроз ИБ;

  • анализом уязвимости сервисов компании;

  • формированием требований к обеспечению РБПО/SDLC;

  • настройкой и сопровождением СКУД и видеонаблюдения;

  • установкой, настройкой и сопровождением технических и программных средств защиты информации (провайдеры аутентификации, средства сетевой защиты, средства антивирусного контроля, средства криптозащиты, СЗИ от НСД);

  • консультацией внутренних служб по вопросам ИБ;

  • выполнением требований ФСТЭК по внутренней ИБ;

  • разработкой требований по ИБ к продуктам компании по требованиям ФСТЭК России.

Какие навыки важны:

  • опыт работы в области ИБ от 2-х лет;

  • навыки администрирования ОС Windows\Linux, сетевого оборудования и средств защиты: антивирусы, СЗИ от НСД, средства криптозащиты;

  • базовые навыки программирования (Bash\Powershell\Python и пр.);

  • базовый уровень технических знаний в области СКУД и систем видеонаблюдения;

  • а также приветствуется наличие образования в области ИБ и сертификатов по программным продуктам и железу (Microsoft, Cisco).

Похожие вакансии Кибербезопасность

hh.ru
xello

AppSec инженер

xelloНа сервисе с: 08.10.26 16:32
Зарплата не указанаРоссияМоскваУдалёнка

Xello – IT-компания, прошедшая путь от стартапа до одного из ключевых игроков на рынке информационной безопасности. Мы создаём передовые продукты в сфере кибербезопасности, направленные на предотвращение хакерских атак. Наши решения помогают бизнесам любого масштаба защищать свои критические данные и данные клиентов.
Мы аккредитованная IT-компания в Минцифры и резиденты Сколково, и наши сотрудники могут воспользоваться предлагаемыми льготами.

Наша команда регулярно участвует в профильных конференциях, а проекты реализуются на современном технологическом стеке, что обеспечивает инновационность и качество наших решений.

Мы работаем с передовым технологическим стеком и решаем сложные задачи, связанные с созданием высоконагруженных систем и архитектурных компонентов. У нас вы будете участвовать в разработке решений, которые взаимодействуют с операционными системами и инфраструктурой, обрабатывают сотни тысяч событий в секунду и оптимизируют процессы хранения данных и коммуникации между компонентами. Мы ценим инновации и открыты для экспериментов, постоянно используем современные подходы и инструменты в разработке.

Наша команда разрабатывает собственную платформу для работы с событиями безопасности и решает сложные задачи, связанные со сбором, обработкой и анализом данных в режиме реального времени.



Мы ищем инженера Product Security/Application Security, который будет отвечать за безопасность наших продуктов на всех этапах разработки — от архитектуры до CI/CD и поставки артефактов. Вам предстоит выстраивать процессы secure SDLC, анализировать архитектуру сложных систем и помогать командам разработки создавать безопасные продукты. Эта роль предполагает глубокое погружение в архитектуру, инфраструктуру разработки и современные угрозы software supply chain.

Чем предстоит заниматься:

  • Формирование и развитие процессов secure SDLC
  • Внедрение и настройка инструментов SAST/SCA/Secret scanning
  • Разработка security требований к продуктам и архитектуре
  • Анализ и повышение безопасности CI/CD инфраструктуры
  • Внедрение практик artifact signing, SBOM, dependency security
  • Разработка политики управления зависимостями
  • Взаимодействие с командами разработки на всех этапах жизненного цикла продукта

Что мы ждём от кандидата:

  • Опыт работы в области Application Security/Product Security от 5 лет
  • Глубокое понимание архитектуры современных приложений и типовых уязвимостей
  • Понимание Linux internals, сетевых протоколов и принципов работы ОС
  • Опыт работы с инструментами SAST/SCA/DAST
  • Понимание безопасности CI/CD и supply chain
  • Опыт проведения threat modeling и security design review
  • Опыт анализа архитектуры сложных систем
  • Понимание принципов secure SDLC
  • Навыки взаимодействия с командами разработки

Будет плюсом:

  • Опыт работы в компаниях, разрабатывающих продукты информационной безопасности
  • Опыт исследования уязвимостей и участия в bug bounty/security research
  • Понимание атак на EDR, endpoint-security и инфраструктурные продукты
  • Опыт работы с container security и cloud security
  • Опыт построения product security программы с нуля
  • Публичные выступления, статьи или исследования в области безопасности
Сайты компаний
N

APAC Regional Security Manager

nebiusНа сервисе с: 08.10.26 16:28
Зарплата не указанаСингапур

About Nebius:

Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.

Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.

Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.

The role

Nebius is looking for a APAC Regional Security Manager. In this role, you will be responsible for the security strategy, governance, and operational oversight of all sites within a defined geographic region. 

 

Your responsibilities will include: 

  • Lead and oversee security operations across multiple sites and data centers in the region. 
  • Ensure compliance with corporate security standards, policies, and regulatory requirements. 
  • Manage regional security budgets, forecasts, and resource planning. 
  • Support site security teams and guide risk mitigation and security best practices. 
  • Lead regional incident management and escalation processes. 
  • Drive security projects, audits, assessments, and continuous improvement initiatives. 
  • Coordinate with internal stakeholders, vendors, and local authorities. 
  • Report regional security performance, risks, and KPIs to senior leadership. 

We expect you to have: 

  •  Proven experience managing large-scale security operations globally.
  •  Deep understanding of data center security and compliance frameworks.
  •  Strong leadership, strategic thinking, and communication skills.
  •  Experience managing teams and influencing senior stakeholders.
  •  Excellent English – Written and spoken
  • Working knowledge of spoken and written English 

It will be an added bonus if you have: 

  • Background in governmental security systems. 
  •  Familiarity with access control systems (ACS) and CCTV.
  •  Experience in large, global organizations.

Benefits & Perks:

  • Competitive compensation
  • Career growth and learning opportunities
  • Flexibility and ownership
  • Collaborative and innovative culture
  • Opportunity to work on impactful AI projects
  • International environment and talented teams

What's it like to work at Nebius:

Fast moving - Bold thinking - Constant growth - Meaningful impact - Trust and real ownership - Opportunity to shape the future of AI 

Equal Opportunity Statement:

Nebius is an equal opportunity employer. We are committed to fostering an inclusive and diverse workplace and to providing equal employment opportunities in all aspects of employment. We do not discriminate on the basis of race, color, religion, sex (including pregnancy), national origin, ancestry, age, disability, genetic information, marital status, veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by applicable law.

Applicants must be authorized to work in the country in which they apply and will be required to provide proof of employment eligibility as a condition of hire. 

If you need accommodations during the application process, please let us know.

Сайты компаний
N

Security Compliance Coordinator

nebiusНа сервисе с: 08.10.26 16:28
Зарплата не указанаИзраильTel Aviv

About Nebius:

Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.

Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.

Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.

The role

The Security Compliance Coordinator supports the day-to-day execution and scaling of the company's security compliance program. This hands-on role coordinates audits and certifications, performs control and evidence reviews, supports supplier compliance reviews within Third Party Risk Management (TPRM), and drives assigned actions to closure across multiple stakeholders. The coordinator works alongside other team members and is expected to contribute professional judgment, not only administrative tracking. 

Your responsibilities will include: 

Compliance and Audit Operations 

  • Coordinate external audits, certifications, and readiness activities, including SOC 2 and ISO-based programs, evidence collection, control populations, sampling, and auditor requests. 
  • Perform recurring control testing and evidence reviews; identify gaps and inconsistencies and track findings, corrective actions, and remediation commitments through closure. 
  • Maintain organized, audit-ready records and provide clear status reporting on milestones, risks, dependencies, and overdue actions. 

TPRM and Supplier Compliance Reviews 

  • Conduct compliance reviews of new and existing suppliers as part of the TPRM process, assessing questionnaires, SOC reports, ISO certifications, policies, and other security and compliance evidence against applicable requirements. 
  • Identify missing, expired, or insufficient supplier evidence and material compliance gaps; coordinate clarifications and remediation and document the resulting assessment, decision, escalation, or accepted exception. 

Governance and Compliance Projects 

  • Support the policy and procedure lifecycle, including inventory maintenance, owner coordination, scheduled reviews, approval tracking, publication, and reporting. 
  • Support the implementation and operation of the GRC platform, including workflows, evidence automation, integrations, data quality, reporting, and user adoption. 
  • Support the integration of new entities, services, and sites into the compliance program, including scope extensions and data-center documentation and evidence coordination. 
  • Maintain workplans and Jira tasks and develop practical templates, metrics, and reporting that improve visibility and consistency across assigned workstreams. 

We expect you to have: 

  • 2-3 years of experience in information security compliance, GRC, IT audit, IT risk, or a closely related field. 
  • Working knowledge of information security controls, audit and certification cycles, and frameworks such as ISO 27001 or SOC 2. 
  • Ability to review evidence critically, identify missing or inconsistent information, and follow issues through to a clear and documented resolution. 
  • Prior exposure to TPRM, supplier security or compliance assessments, or review of third-party assurance documentation is an advantage. 
  • Strong organizational and English communication skills, with the ability to manage multiple workstreams and summarize requirements, findings, and status accurately. 
  • Proficiency with Jira, Confluence, and Excel or equivalent spreadsheet tools; experience with GRC platforms is an advantage. 

 

Benefits & Perks:

  • Competitive compensation
  • Career growth and learning opportunities
  • Flexibility and ownership
  • Collaborative and innovative culture
  • Opportunity to work on impactful AI projects
  • International environment and talented teams

What's it like to work at Nebius:

Fast moving - Bold thinking - Constant growth - Meaningful impact - Trust and real ownership - Opportunity to shape the future of AI 

Equal Opportunity Statement:

Nebius is an equal opportunity employer. We are committed to fostering an inclusive and diverse workplace and to providing equal employment opportunities in all aspects of employment. We do not discriminate on the basis of race, color, religion, sex (including pregnancy), national origin, ancestry, age, disability, genetic information, marital status, veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by applicable law.

Applicants must be authorized to work in the country in which they apply and will be required to provide proof of employment eligibility as a condition of hire. 

If you need accommodations during the application process, please let us know.

HireSeeker собирает вакансии со всех площадок и присылает только релевантные. Бесплатно.