Высшее образование в области информационных технологий или информационной безопасности
Опыт работы в SecOps, Detection Engineering, Threat Hunting, SOC или Incident Response не менее 4–5 лет
Отличное понимание: detection engineering, threat hunting, IOC/TTP analysis, attack chain analysis, incident investigation, telemetry analysis
Практический опыт разработки detection logic для: SIEM, IDS/IPS, EDR/XDR, authentication telemetry
Практический опыт работы с: SIEM, EDR/XDR, IDS/IPS, Threat Intelligence, centralized logging systems
Опыт работы с SIEM-платформами: ELK, Splunk, QRadar, Sentinel или аналогичными решениями
Практический опыт: IOC-based detection, TTP-based detection, behavior-based detection, anomaly detection
Опыт разработки: correlation rules, detection use-cases, alert enrichment, monitoring pipelines
Практический опыт проведения: threat hunting, incident investigation, attack chain reconstruction, compromise analysis
Понимание MITRE ATT&CK в части: Initial Access, Execution, Persistence, Defense Evasion, Credential Access, Discovery, Lateral Movement, Command and Control, Exfiltration
Понимание: attacker behavior, TTP, IOC lifecycle, detection blind spots, telemetry gaps
Практический опыт анализа telemetry data: network telemetry, authentication telemetry, endpoint telemetry, cloud telemetry
Опыт анализа: malicious traffic, credential abuse, lateral movement, command & control activity, persistence mechanisms
Опыт работы с: Wireshark, tcpdump, NetFlow/sFlow, Zeek или аналогичными инструментами
Понимание: centralized logging, telemetry pipelines, security visibility, detection coverage
Базовое понимание: Linux, Windows, cloud infrastructure, networking в контексте incident investigation и telemetry analysis
Навыки автоматизации и скриптинга: Python, Bash, PowerShell — будут преимуществом
Опыт анализа malware behavior — будет преимуществом
Понимание процессов Vulnerability Management и exploitation visibility
Аналитическое мышление, способность самостоятельно расследовать инциденты и принимать технические решения в условиях инцидента
Умение взаимодействовать с DevOps, Infrastructure, SOC и Security командами
Умение документировать: attack chain, IOC, TTP, technical findings, detection recommendations
Понимание: Threat Intelligence, ATT&CK-based detection, detection maturity, security telemetry architecture
Опыт интеграции: SIEM, EDR/XDR, IDS/IPS, Threat Intelligence Platform, centralized monitoring systems
Понимание принципов: hybrid infrastructure visibility, Kubernetes telemetry, container security visibility
Понимание современных TTP атакующих групп
Приветствуются сертификаты: Security+, Splunk, GCIA, GCIH, Blue Team certifications
Уверенное чтение технической документации на английском языке