научсофт

Head of Cybersecurity Practice

Nauchsoft is an international IT consulting and software development company. We have been in the IT business for 37 years and continue growing.​​​​​​​

научсофт · На сервисе с: 31.08.26 15:56

Зарплата не указанаБеларусьМинскУдалёнка

Nauchsoft is an international IT consulting and software development company. We have been in the IT business for 37 years and continue growing.​​​​​​​

We are looking for Head of Cybersecurity Practice. This role is prospective and has been created in line with the company’s planned team expansion.

Head of Cybersecurity Practice is responsible for three key areas:

  • Penetration Testing / Offensive Security
  • Defensive Security
  • Security Monitoring & SIEM

The primary mission of the role is to develop these areas into strong Cybersecurity capabilities within the company: define the strategy and roadmap, build and grow teams, increase technical maturity, introduce modern security practices, and ensure high-quality delivery of Cybersecurity services.

This role combines strategy, technical leadership, team management, and development of Cybersecurity services for clients.

Key Responsibilities

Cybersecurity Strategy & Capability Development

  • Define the Cybersecurity strategy and roadmap for Penetration Testing, Defensive Security, and Security Monitoring & SIEM.
  • Set goals, priorities, and key development areas for each practice.
  • Align Cybersecurity capability development with current and future business and client needs.
  • Develop technical expertise and the overall Cybersecurity competency portfolio within the company.
  • Define required technologies, tools, methodologies, and engineering standards.
  • Establish consistent technical approaches across Cybersecurity practices.
  • Ensure high quality of delivery and technical solutions across all Cybersecurity services.
  • Build effective collaboration between Cybersecurity and Engineering, Infrastructure, DevOps, Cloud, and other technical teams.
  • Track Cybersecurity market trends, emerging threats, technologies, and practices, and introduce relevant approaches within the company.
  • Define measurable goals and drive execution of the Cybersecurity roadmap.

Team Leadership

  • Lead the heads/leads and teams across Penetration Testing, Defensive Security, and Security Monitoring & SIEM.
  • Evolve the team structure in line with business growth and project demand.
  • Participate in hiring key specialists and building strong teams.
  • Develop technical leaders and strengthen expertise within each area.
  • Define clear ownership, collaboration processes, and performance expectations.
  • Create an environment that supports professional growth, knowledge sharing, and competency development across Cybersecurity teams.
  • Set team development priorities and ensure sufficient capacity for current and future projects.
  • Mentor technical leads and support them in complex technical and organizational decisions.

Penetration Testing / Offensive Security

  • Develop the Penetration Testing and Offensive Security practice.
  • Ensure a high technical standard across Web, API, Infrastructure, Cloud, and other types of security assessments.
  • Develop and improve penetration testing methodologies and standards.
  • Ensure the quality of assessment results, reporting, and client recommendations.
  • Strengthen team expertise in modern attack techniques, vulnerabilities, and exploitation approaches.
  • Oversee the technical quality of complex and critical security assessments.

Defensive Security

  • Develop the company’s Defensive Security capabilities.
  • Define and improve approaches to protecting cloud environments, infrastructure, endpoints, and corporate systems.
  • Increase the security maturity of technical environments and client solutions.
  • Develop security architecture and security controls within the Defensive Security practice.
  • Build effective collaboration between the Defensive Security team and Engineering, DevOps, Cloud, and Infrastructure teams.
  • Ensure the adoption of modern defensive security practices, hardening approaches, and vulnerability management.

Security Monitoring & SIEM

  • Develop the Security Monitoring & SIEM practice.
  • Define and improve approaches to monitoring, detection, and analysis of security events.
  • Increase automation within Security Operations.
  • Improve detection capabilities and incident analysis processes.
  • Ensure effective collaboration between SIEM, Defensive Security, and Penetration Testing teams in threat detection, analysis, and prevention.
  • Develop approaches to Incident Detection & Response and coordination with technical teams.

Client Engagement & Presales

  • Participate in Cybersecurity presales activities and in the development of the company’s Cybersecurity service offering.
  • Join discovery sessions and technical meetings with prospective and existing clients.
  • Help define scope, delivery approach, team composition, and technical solutions for Cybersecurity engagements.
  • Contribute to technical proposals, estimates, and solution descriptions.
  • Represent the company’s Cybersecurity expertise in meetings with enterprise clients.
  • Advise clients on architecture, security, and capability-related topics.
  • Help shape new Cybersecurity services and offerings based on market and client needs.
What We Expect
  • Strong technical background in Cybersecurity / Information Security.
  • Experience leading Cybersecurity teams and/or multiple technical Security areas.
  • Experience managing through technical leads would be a strong advantage.
  • Good understanding of both Offensive Security and Defensive Security.
  • Practical understanding of SIEM, SOC, Security Monitoring, and Incident Response.
  • Experience with cloud environments and modern IT infrastructure.
  • Strong understanding of modern attack techniques, vulnerabilities, and security controls.
  • Experience building and developing Cybersecurity processes, methodologies, and technical standards.
  • Ability to evaluate the quality of technical solutions and provide direction on complex security topics.
  • Ability to operate effectively at both strategic and technical levels.
  • Experience developing technical teams and leaders.
  • Ability to define priorities and translate strategy into a clear roadmap and measurable results.
  • Strong leadership, communication, and stakeholder management skills.
  • Ability to work with clients and technical teams at senior management / technical leadership level.
  • English level sufficient for working with international teams and clients.
Nice to Have
  • Experience in IT outsourcing / IT services / consulting.
  • Experience working with enterprise clients.
  • Experience in Cybersecurity presales and shaping Cybersecurity solutions around client needs.
  • Experience developing a Cybersecurity practice, competency center, or service line.
  • Understanding of IT outsourcing economics, including utilization, capacity planning, project profitability, and resource management.
  • Experience developing and launching new Cybersecurity services.
  • Certifications such as OSCP, CISSP, CISM, GIAC, or similar.
Role Specifics

This is not a traditional CISO / GRC role. The main focus is on developing technical Cybersecurity capabilities, teams, and client-facing services.

Head of Cybersecurity Practice is not expected to be deeply hands-on in day-to-day delivery. However, the role requires sufficient technical depth to review and challenge technical decisions, participate in complex cases, set technical direction, and maintain a high level of expertise across the teams.

We offer:

  • Opportunity for professional self-realization and growth.
  • Friendly team.
  • 25-days of paid vacation.
  • Medical insurance and 100% payment for sick leave.
  • Professional training and obtaining certificates at the company's expense.
  • Foreign language courses and other corporate programs.
  • A variety of corporate events.
  • Bonuses in case of wedding or a child’s birth.
  • The possibility of remote work from any location.

Похожие вакансии Кибербезопасность

hh.ru
лига цифровой экономики

Инженер информационной безопасности

лига цифровой экономикиНа сервисе с: 12.08.26 13:45↑ Вакансия с автоподнятием
Зарплата не указанаРоссияМоскваОфис

Проекты по эксплуатации распределенной инфраструктуры гос. заказчиков в части обеспечения информационной безопасности

Твои задачи:

  • Администрирование и сопровождение средств защиты информации
  • Участие в процессе внутренней безопасности подразделения
  • Опыт работы с ОС семейства Windows и Linux
  • Будет плюсом опыт работы со средствами антивирусной защиты (например, Kaspersky), SIEM, системами контроля привилегированных пользователей (например, СКДПУ), реагирования на инциденты ИБ (например, R-Vision) и сканерами уязвимостей (например, MaxPatrol 8 / MaxPatrol VM).
  • Опыт работы с системами виртуализации (например, VMware/VirtualBox) и системами мониторинга (Zabbix или др.)
  • Знание актуальных техник и тактик кибератак, а также нормативной базы по ИБ (приказы ФСТЭК № 21, 117 и 239).
    Теоретические и практические знания сетевых технологий (TCP/IP, VLAN, Routing, Troubleshooting)
  • Навыки автоматизации процессов (написание скриптов, например Python и Bash)

Что мы обеспечим:

  • Технику для комфортной работы
  • ДМС, частичную компенсацию фитнеса, доступ к сервису корпоративных скидов, внутренние обучение и многое другое
  • Работу в профессиональной среде, состоящей из высококлассных экспертов, которая позволит тебе быстро расти как эксперту
  • Ежегодные сессии профессионального развития, результатом которой является план индивидуального развития каждого сотрудника и получение обратной связи
  • Сообщества по интересам: Лига Спорта, Лига Творчества, Лига Интеллекта и др., а также возможность организовать свое сообщество и получить поддержку от компании
Соц.сети
C
Зарплата не указанаРоссияМоскваГибрид

Руководитель группы дежурных аналитиков SOC

Локация: #Москва (гибрид)
Зарплата: ₽. Обсуждается на собеседовании.
Компания: ••••••••

Обязанности:
• Операционное управление сменой:

— Организация сдачи/приёмки дежурств
— Контроль укомплектованности и графика дежурств
— Распределение нагрузки между дежурными аналитиками
— Мониторинг и соблюдение KPI и SLA

• Управление инцидентами в зоне ответственности команды:
— Управление обработкой инцидентов в системе IRP и JiraSM
— Обеспечение эскалации инцидентов на команду CERT

• Работа с командой:
— Менторство и обучение команды L1
— Контроль метрик и качества работы дежурных аналитиков
— Распределение проектных задач и контроль за их выполнением
— Общее управление командой, проведение 1:1

• Коммуникации и отчётность:
— Формирование отчётностей по итогам смен
— Оперативное уведомление заинтересованных лиц об инцидентах
— Взаимодействие с другими подразделениями компании в своей зоне ответственности

• Технические и процессные задачи:
— Ведение базы знаний и документации подразделения
— Участие в создании контента SOC в своей зоне ответственности
— Тюнинг системы мониторинга, настройка исключений и фильтров

Требования:
• Глубокое понимание киберугроз, методов атаки и принципов работы сетей/систем
• Способность ясно мыслить и принимать решения при критических инцидентах
• Знание модели Kill Chain, фреймворка MITRE ATT&CK и цикла обработки инцидентов SANS Incident Response (SANS IR)

••••••••

#Гибрид

hh.ru
В

Специалист по информационной безопасности

винити ранНа сервисе с: 24.09.26 17:31
140k–160k ₽РоссияМоскваОфис
Обязанности:
  • организация категорирования объектов КИИ и актуализация результатов;

  • подготовка пакета организационно-распорядительных документов по защите информации (Приказ о назначении ответственных, Политика ИБ, Инструкции для администраторов и пользователей);

  • организация регистрации и реагирования на компьютерные атаки;

  • выдача УКЭП, МЧД, настройка работы в различных ГИС;

  • внедрение и эксплуатация программных и аппаратных средств информационной безопасности.

Требования:
  • высшее образование по специальностям «Информационная безопасность», «Компьютерная безопасность» или смежным техническим специальностям (информатика, вычислительная техника);
    - профессиональная переподготовка: наличие дипломов о профессиональной переподготовке по программам в области защиты информации (объем не менее 500 часов);
    - стаж в сфере обеспечения ИБ: от 3 лет.
    Опыт в организации защиты объектов КИИ или в государственных НИИ. Взаимодействие с регуляторами. Глубокое знание № 187-ФЗ, 149-ФЗ, 152-ФЗ, 63-ФЗ и др. Понимание категорирования объектов КИИ, разработки моделей угроз, создания Систем обнаружения атак.
  • Желательно наличие сертификатов: CISA, CISM, CISSP (международные); «Специалист по защите информации» (национальный стандарт).

Условия:
  • оформление по ТК РФ;

  • ежегодный оплачиваемый отпуск 28 дней;

    расположение: 5 мин. от м. Сокол;

    испытательный срок: 3 месяца;

    бесплатная парковка для сотрудников;

    полный соц. пакет.

HireSeeker собирает вакансии со всех площадок и присылает только релевантные. Бесплатно.