Научсофт·Минск·7 ч назад
Information Security Team Lead (Blue Team)
Ориентир по рынку≈ 235 000 – 470 000 ₽наш грубый ориентир по 200 вакансиям этого грейда на рынке, без учёта специальности: у работодателя вилка не указана
🏢 ОфисSeniorПолная занятость
Вакансия на английскомПереведёт заголовок и описание вакансии на русский
Наша компания
Nauchsoft is an international IT consulting and software development company. We have been in the IT business for 37 years and continue growing. We are looking for an experienced Information Security Team Lead (Blue Team) to join a team working on a large-scale banking and lending platform. This role is prospective and has been created in line with the company’s planned team expansion.
Чем предстоит заниматься
Operational Management of the Information Security Team (Blue Team) Supporting the Company’s Internal Infrastructure
Organize the execution of Information Security processes, including incident management, vulnerability management, and other related processes
Organize ongoing support of information security tools and controls within the information security system, including health monitoring, version upgrades, reconfiguration, and other maintenance activities
Organize changes to the information security system, including selection, testing, and implementation of information security tools, as well as optimization of Information Security processes
Prepare reports and project documentation in the field of Information Security, including policies, procedures, and user-facing articles
Collaborate with related departments, including IT, Compliance, Red Team, and other teams, as part of the responsibilities listed above
Наши требования
4–5 years of experience in operational management of an Information Security team
Knowledge of the legislation and regulatory requirements of the Republic of Belarus in the field of information security and cybersecurity
Knowledge and practical experience in the following technical areas
TCP/IP protocol stack and related services (DNS, DHCP, HTTP/HTTPS, NAT, etc.)
Firewalls, NGFW, IDS/IPS, WAF
SIEM platforms
EDR/XDR solutions
Vulnerability scanners
Windows and Linux system administration
Secure SDLC principles: threat modeling, secure code review, and basic OWASP practices
Higher education in Information Security or IT
Strong communication skills and clear verbal communication in Russian and English; English level B2 or higher, considering participation in presales calls
Experience working with international Information Security standards and practices, including ISO 27001, SOC 2, GDPR, PCI DSS, and others
Motivation, goal orientation, and attention to detail
Мы предлагаем
Opportunity for professional self-realization and growth
Friendly team
25-days of paid vacation
Medical insurance and 100% payment for sick leave
Professional training and obtaining certificates at the company's expense
Foreign language courses and other corporate programs
A variety of corporate events
Bonuses in case of wedding or a child’s birth
The possibility of remote work from any location
Hybrid work format
Periodic presence in the Minsk office is required
Дополнительно
Analyze and assess Information Security requests, including Secure SDLC-related topics
Participate in calls with prospective customers
Analyze customers’ Information Security processes and infrastructure and develop recommendations
Participate in the implementation of Information Security processes on customer projects, including the introduction of Secure SDLC practices
