ббр банк

Главный специалист Отдела кибербезопасности

Пилотирование и внедрение средств защиты;

ббр банк · На сервисе с: 06.06.26 16:33

↑ Вакансия с автоподнятием
Зарплата не указанаРоссияМоскваОфис

Обязанности:

  • Пилотирование и внедрение средств защиты;
  • Выявление, реагирование и предотвращение инцидентов ИБ, участие в проведении внутренних расследований;
  • Контроль и управление доступом к информационным ресурсам в информационных системах;
  • Установка и контроль обновлений серверов и рабочих станций Windows/Linux;
  • Настройка и администрирование средств защиты информации: NGFW, IPS/IDS, MDM; сканеров уязвимостей (Usergate, SecretNet Studio, vGate и т.д.);
  • Контроль и актуализация правил Firewall;
  • Обслуживание системы Kaspersky Security Center;
  • Анализ инцидентов и разработка контентных правил для DLP систем;
  • Развитие процессов SOC. Разработка правил корреляции. Написание сценариев реагирования и автоматизация их работы (playbook'и реагирования на инциденты);
  • Контроль программного обеспечения на соответствие требованиям информационной безопасности, выявление скрытого и потенциально вредоносного поведения программ;
  • Взаимодействие с подразделениями Банка в рамках функциональных обязанностей.

Требования:

  • Уверенные знания о работе сетей на базе TCP/IP, клиентских и серверных операционных систем Windows на уровне системного администратора;
  • Уверенное знание операционных систем Linux (администрирование, настройка), опыт выявления и устранения уязвимостей в Linux-системах;
  • Знание принципов обеспечения безопасности в ОС Windows, Windows Server, Linux: конфигурация, GPO, аудит;
  • Опыт администрирования средств антивирусной защиты информации, систем мониторинга и аудита событий;
  • Понимание принципов работы межсетевых экранов NGFW, средств защиты IDS/IPS;
  • Умение анализировать инциденты, в том числе определение источников и причин возникновения инцидентов, а также оценка их последствий.

Плюсом будет:

  • Опыт работы в направлении appsec (SAST, DAST, SCA);
  • Мониторинг форумов/чатов по темам «уязвимости, атаки, утечки, взломы»;
  • Опыт скриптовой автоматизации процессов Powershell, Python;
  • Опыт использования автоматизированных средств проверки ПО (Cuckoo Sandbox, Yara, VirusTotal);
  • Опыт работы с операционными системами Linux;
  • Опыт работы с криптографическими шлюзами отечественного производства (S-terra, VipNet, Континент);
  • Наличие высшего образования по направлению «Информационная безопасность» или наличие диплома о профессиональной переподготовке по программе «Информационная безопасность. Обеспечение защиты информации ограниченного доступа, не содержащей сведения, составляющие государственную тайну, криптографическими и не криптографическими методами» в объеме не менее 512 часов;
  • Опыт работы со средствами виртуализации.

Условия:

  • График работы: пн-чт с 9:00 до 18:00, пт – с 9:00 до 16:45;
  • Испытательный срок: 3 месяца;
  • Расширенный социальный пакет (после прохождения исп. срока): ДМС, включая туристическую страховку, доплата больничного до 100% заработка
  • Столовая в здании Банка;
  • Корпоративный транспорт от м."Беломорская", м."Сходненская", жд.ст. Химки (офис расположен в г. Химки, 15 минут от метро)
  • Охраняемая парковка для автомобилей сотрудников.

Похожие вакансии Кибербезопасность

Сайты компаний
V

Security Tech Lead

veeamНа сервисе с: 03.10.26 21:40
Зарплата не указанаПольшаЧехияPrague

Veeam is the Data and AI Trust Company, specializing in helping organizations ensure their data and AI are fully understood, secured, and resilient to enable the acceleration of safe AI at scale. As the market leader in both data resilience and data security posture management, Veeam is built for the convergence of identity, data, security, and AI risk. Headquartered in Seattle with offices in more than 30 countries, Veeam protects over 550,000 customers worldwide, who trust Veeam to keep their businesses running. Join us as we go fearlessly forward together, growing, learning, and making a real impact for some of the world’s biggest brands.

About the Role

Veeam Data Cloud is rapidly scaling, and we’re committed to unifying our security approach across all teams to ensure consistent product protection.

We’re seeking a Security Tech Lead to drive the design and rollout of standardized security solutions and help establish a dedicated Software Security Engineering platform team. In this role, you’ll work closely with the Director of Security Engineering to turn our unified strategy into an actionable engineering roadmap, shaping a strong and cohesive security framework.

What You’ll Do

  • Lead the architecture and implementation of shared security primitives across Veeam Data Cloud
  • Translate high-level security strategy into a concrete, prioritized engineering roadmap for cloud services and platform capabilities
  • Act as a hands-on technical leader – write and review production code, drive design and code reviews, mentorship
  • Establish and promote secure-by-default patterns and shared libraries to streamline security across teams 
  • Build the foundation for a Software Security Engineering platform to manage shared security services and tools 
  • Collaborate with product, platform, SRE, and compliance teams to ensure security solutions are robust and easy to adopt 
  • Enhance security posture through automation, guardrails, and policy-as-code 

Technologies You’ll Work With

  • Languages & Frameworks: Go, Python, and TypeScript (and related service/API frameworks)
  • Cloud & Platform: Modern cloud-native architectures (microservices, event-driven systems, multi-tenant SaaS) using AWS, Azure, and GCP
  • Security & Identity: Authentication and authorization services, identity providers, security control planes, guardrails, secure logging
  • Tooling & Practices: Code and design review, CI/CD, observability and logging stacks, policy-as-code and security automation

What You’ll Bring

  • Strond coding skills (Golang, Python, or TypeScript)
  • Extensive experience building distributed, cloud-native systems
  • Practical expertise in authentication/authorization, security guardrails, and secure observability for production systems
  • Proven technical leadership: architecture, roadmap influence, and mentoring engineers
  • Strong product mindset, focusing on platform security that empowers other teams
  • Skilled at cross-team collaboration and clear communication of complex topics
  • Preference for automation, reusable platforms, and secure-by-default approaches over one-off solutions

Bonus Skills

  • Experience building or leading platform and product security teams providing shared services to multiple product teams
  • Background in multi-tenant SaaS and large-scale control/data planes
  • Familiarity with modern security practices (e.g., zero trust, least privilege, policy-as-code, security service meshes)
  • Experience working with regulatory or enterprise security requirements

What You’ll Get 

  • 25 vacation days, 4 sick days, 21 paid medical leave days, plus 4 extra global VeeaMe Days for self-care and 24 paid volunteer hours annually through Veeam Cares
  • Premium private medical insurance for employees and dependents
  • Daily meal vouchers for restaurants and groceries (180 CZK per working day)
  • Flexible cafeteria platform with thousands of lifestyle benefit options
  • Multisport Card for gym and wellness, with family add-on options
  • Annual public transport reimbursement up to a set limit
  • Corporate mobile plan with optional family tariff
  • Opportunities to learn and grow through on-demand libraries (LinkedIn Learning, O’Reilly), mentoring, workshops and learning events like our annual Global Day of Learning

#LI-TK1

Veeam Software is an equal opportunity employer and does not tolerate discrimination in any form on the basis of race, color, religion, gender, age, national origin, citizenship, disability, veteran status or any other classification protected by federal, state or local law. All your information will be kept confidential.

Personal data collected during the recruitment process will be processed in accordance with our Recruiting Privacy Notice, which explains how your information is collected, used, and handled in connection with hiring activities. By applying for this position, you consent to this processing. 

By submitting your application, you confirm that the information provided, including any supporting documents, is complete and accurate to the best of your knowledge. Any misrepresentation, omission, or falsification may result in disqualification from consideration or, if discovered after employment begins, termination of employment.

Сайты компаний
V

DevSecOps

veeamНа сервисе с: 03.10.26 21:16
Зарплата не указанаСШАКанадаSan Jose

Veeam is the Data and AI Trust Company, specializing in helping organizations ensure their data and AI are fully understood, secured, and resilient to enable the acceleration of safe AI at scale. As the market leader in both data resilience and data security posture management, Veeam is built for the convergence of identity, data, security, and AI risk. Headquartered in Seattle with offices in more than 30 countries, Veeam protects over 550,000 customers worldwide, who trust Veeam to keep their businesses running. Join us as we go fearlessly forward together, growing, learning, and making a real impact for some of the world’s biggest brands.

About the Role

Securiti's platform processes billions of data events per day across hundreds of enterprise clouds. As a DevSecOps Engineer, you will build and maintain the invisible infrastructure that makes this scale possible—ensuring developers can ship features daily while maintaining fortress-level security.

You will be responsible for designing self-healing deployment pipelines that turn infrastructure into code, security into automation, and complexity into reliability. Your work ensures that when a customer onboards petabytes of data, our platform scales transparently—without manual intervention.

Responsibilities

  • Security-First Infrastructure: Architect and implement infrastructure-as-code using Terraform and CloudFormation, ensuring every deployment follows zero-trust principles and least-privilege access models.

  • Kubernetes at Scale: Design and optimize our Kubernetes clusters to handle massive workloads, implementing intelligent autoscaling, pod security policies, and network segmentation that protects sensitive customer data.

  • Zero-Downtime Deployments: Build sophisticated CI/CD pipelines using ArgoCD, Spinnaker, and GitOps patterns that enable blue/green and canary deployments—allowing us to ship multiple times per day with zero customer impact.

  • Observability Engineering: Implement comprehensive monitoring and alerting using Prometheus, Grafana, and ELK, creating dashboards that surface anomalies before they become incidents.

  • Multi-Cloud Orchestration: Manage infrastructure across AWS, Azure, and GCP, building abstraction layers that allow our platform to run anywhere while maintaining consistent security postures.

  • Performance Under Fire: Be on-call to diagnose and resolve production issues in real-time, using your deep systems knowledge to troubleshoot complex distributed systems problems across the stack.

  • Automation-First Mindset: Write Python and Go tooling that automates repetitive operational tasks, turning hours of manual work into seconds of automated execution.

 

Requirements

  • Experience: 5+ years of software development with deep operational experience in cloud-native environments (AWS, Azure, GCP).

  •  Infrastructure as Code Mastery: Expert-level proficiency with Terraform or AWS CloudFormation, with a portfolio of reusable modules and patterns.

  • Container Orchestration: Production experience running Kubernetes at scale, including deep knowledge of networking, security contexts, and stateful workloads.

  • CI/CD Architecture: Hands-on experience designing GitOps-based deployment pipelines using tools like ArgoCD, Spinnaker, Jenkins, or GitHub Actions.

  • Development Skills: Professional coding ability in Python or Golang—you're not just configuring tools, you're building them.

  • Database Operations: Working knowledge of SQL (Postgres), NoSQL (MongoDB/Elasticsearch), and Graph databases (Neo4j, Neptune) for operational troubleshooting and performance tuning.

  • Linux & Networking Fundamentals: Deep understanding of Linux systems administration, bash scripting, network routing, load balancing, and service mesh architectures.

  • Monitoring & Observability: Experience implementing full-stack observability with metrics, logs, and traces using Prometheus, Grafana, ELK, or similar tooling.

 

Bonus Points

  • Security Certifications: AWS Security Specialty, CKS (Certified Kubernetes Security Specialist), or equivalent security-focused credentials.

  • Service Mesh Experience: Hands-on work with Istio, Linkerd, or Consul for advanced traffic management and zero-trust networking.

  • Chaos Engineering: Experience with fault injection frameworks (Chaos Monkey, Litmus) to build resilient systems.

  • GitOps Evangelism: You've championed GitOps practices and trained teams on declarative infrastructure patterns.

  • Cost Optimization: Track record of reducing cloud spend through intelligent resource management and architectural improvements.

 

 

What you'll get

  • Unlimited paid time off, 12 paid holidays including 4 global VeeaMe Days for self-care and 24 paid volunteer hours annually through Veeam Cares
  • Paid parental leave: 8 weeks for all parents, 16 weeks for birthing parents
  • Medical, dental, and vision coverage starting on your first day
  • Mental health support, therapy sessions, and digital wellness tools via our Employee Assistance Program
  • 401(k) retirement plan with company matching contributions
  • Fertility, adoption, and surrogacy support through Maven, plus paid volunteer time
  • AirVet: 24/7 virtual veterinary care at no cost
  • Legal services, identity protection, and supplemental health insurance options
  • Tax-advantaged spending accounts for healthcare, dependent care, and commuting
  • Opportunities to learn and grow through on-demand libraries (LinkedIn Learning, O’Reilly), mentoring, workshops, and learning events like our annual Global Day of Learning

Pay Transparency

Veeam is committed to pay transparency and equitable compensation. For this role, the compensation range below reflects the expected total target compensation (TTC), inclusive of base pay and a competitive performance-based bonus. For roles with a commission plan, the compensation range represents On Target Earnings (OTE), which includes base salary plus variable commission. When determining compensation, Veeam takes into consideration factors such as experience, education, skills, and geographic zone. Offers are typically made below the midpoint of the range.

In addition to compensation, Veeam provides a comprehensive benefits package, including health coverage, retirement plans, and unlimited time off.

Compensation Range (TTC / OTE)
$153,480—$255,720 USD

Veeam Software is an equal opportunity employer and does not tolerate discrimination in any form on the basis of race, color, religion, gender, age, national origin, citizenship, disability, veteran status or any other classification protected by federal, state or local law. All your information will be kept confidential.

Personal data collected during the recruitment process will be processed in accordance with our Recruiting Privacy Notice, which explains how your information is collected, used, and handled in connection with hiring activities. By applying for this position, you consent to this processing. 

By submitting your application, you confirm that the information provided, including any supporting documents, is complete and accurate to the best of your knowledge. Any misrepresentation, omission, or falsification may result in disqualification from consideration or, if discovered after employment begins, termination of employment.

Сайты компаний
V

Senior Cyber-Security Operations Analyst, Product AppSec

veeamНа сервисе с: 03.10.26 21:11
Зарплата не указанаСША

Veeam is the Data and AI Trust Company, specializing in helping organizations ensure their data and AI are fully understood, secured, and resilient to enable the acceleration of safe AI at scale. As the market leader in both data resilience and data security posture management, Veeam is built for the convergence of identity, data, security, and AI risk. Headquartered in Seattle with offices in more than 30 countries, Veeam protects over 550,000 customers worldwide, who trust Veeam to keep their businesses running. Join us as we go fearlessly forward together, growing, learning, and making a real impact for some of the world’s biggest brands.

#LI-REMOTE #LI-JC2

About the Role

We're looking for a Senior Cyber Security Operations Analyst to design, build, and scale secure enterprise development and QA environments across Azure-based software delivery ecosystems. You'll enhance Azure DevOps platform capabilities, improve CI/CD pipeline architecture, and integrate security throughout the software development lifecycle. This role works closely with Engineering, QA, Release Engineering, Platform Engineering, and Product Security teams to improve build reliability, deployment consistency, and operational efficiency. 

Due to the fact that this position will deal with highly sensitive data and will support federal customers, we are only considering US citizens at this time. Security clearance is not required, but there is a slight chance it maybe requested in the future 

What You’ll Do

  • Design, implement, and enhance Azure DevOps platform capabilities, including reusable CI/CD templates, pipeline standards, and developer enablement tooling
  • Build and optimize secure CI/CD pipelines supporting multiple product lines, integrating security scanning, secrets management, artifact validation, and policy enforcement
  • Build and support scalable development and QA environments, improving provisioning, configuration management, and deployment automation
  • Implement and maintain infrastructure-as-code solutions using Terraform, Ansible, and PowerShell across Azure cloud environments
  • Partner with Product Security and Infrastructure teams to embed secure-by-design principles into SDLC workflows and support vulnerability remediation initiatives
  • Monitor CI/CD platform health and troubleshoot pipeline failures, deployment issues, and environment-related problems
  • Mentor junior engineers and promote DevSecOps best practices across Engineering, QA, Security, and Infrastructure teams 

Technologies You’ll Work With

  • CI/CD platforms: Azure DevOps, GitHub Actions, Jenkins
  • IaC and automation: Terraform, Ansible, PowerShell, Python, Bash
  • Containerization: Docker, Kubernetes
  • Cloud: Azure (primary), with familiarity across AWS or GCP
  • Security tooling: SAST, SCA, secrets management, artifact repositories
  • Agentic AI and modern automation approaches

What You’ll Bring

  • 8+ years of experience in DevSecOps, DevOps, Platform Engineering, or Build Engineering
  • Strong hands-on experience with Azure DevOps, CI/CD pipeline engineering, and build and release automation
  • Experience with Terraform, Docker, Kubernetes, Git, PowerShell, Python, and Bash
  • Solid understanding of DevSecOps practices, IaC, Secure SDLC, and cloud security
  • Experience with software supply chain security frameworks (SLSA, NIST SSDF, OWASP SCVS)
  • Bachelor's degree in Computer Science, Engineering, or equivalent experience 

Bonus Skills

  • Experience implementing agentic AI engineering and development solutions
  • Relevant certifications such as Azure DevOps Engineer Expert, CDP, GCSA, CCSP, CKS, or HashiCorp Terraform Associate
  • Experience in regulated or compliance-driven environments
  • Familiarity with policy enforcement workflows, artifact repositories, and secrets management platforms 

What you'll get

  • Unlimited paid time off, 12 paid holidays including 4 global VeeaMe Days for self-care and 24 paid volunteer hours annually through Veeam Cares
  • Paid parental leave: 8 weeks for all parents, 16 weeks for birthing parents
  • Medical, dental, and vision coverage starting on your first day
  • Mental health support, therapy sessions, and digital wellness tools via our Employee Assistance Program
  • 401(k) retirement plan with company matching contributions
  • Fertility, adoption, and surrogacy support through Maven, plus paid volunteer time
  • AirVet: 24/7 virtual veterinary care at no cost
  • Legal services, identity protection, and supplemental health insurance options
  • Tax-advantaged spending accounts for healthcare, dependent care, and commuting
  • Opportunities to learn and grow through on-demand libraries (LinkedIn Learning, O’Reilly), mentoring, workshops, and learning events like our annual Global Day of Learning

Compensation Transparency

Veeam is committed to pay transparency and equitable compensation. For this role, the compensation range below reflects the expected total target compensation (TTC), inclusive of base pay and a competitive performance-based bonus. For roles with a commission plan, the compensation range represents On Target Earnings (OTE), which includes base salary plus variable commission. When determining compensation, Veeam takes into consideration factors such as experience, education, skills, and geographic zone. Offers are typically made below the midpoint of the range.

In addition to compensation, Veeam provides a comprehensive benefits package, including health coverage, retirement plans, and unlimited time off.

U.S. Geographic Zones & Compensation Ranges (TTC / OTE)
Zone 1: San Francisco Bay Area, New York City Boroughs
$174,960—$324,960 USD
Zone 2: Washington, California (excluding San Francisco Bay Area)
$160,380—$297,880 USD
Zone 3: Texas, Illinois, North Carolina, Colorado, Massachusetts, Pennsylvania, Virginia, Oregon, Nevada, Hawaii, New York (excluding NYC boroughs); Sales roles located in Georgia, Ohio, and Arizona
$145,800—$270,800 USD
Zone 4: All other US locations
$126,846—$235,596 USD

Veeam Software is an equal opportunity employer and does not tolerate discrimination in any form on the basis of race, color, religion, gender, age, national origin, citizenship, disability, veteran status or any other classification protected by federal, state or local law. All your information will be kept confidential.

Personal data collected during the recruitment process will be processed in accordance with our Recruiting Privacy Notice, which explains how your information is collected, used, and handled in connection with hiring activities. By applying for this position, you consent to this processing. 

By submitting your application, you confirm that the information provided, including any supporting documents, is complete and accurate to the best of your knowledge. Any misrepresentation, omission, or falsification may result in disqualification from consideration or, if discovered after employment begins, termination of employment.

HireSeeker собирает вакансии со всех площадок и присылает только релевантные. Бесплатно.