сегодня

cyber security engineer

ориентир по рынку
вакансия зп не указана
в среднем 359 861 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

генерация резюме под вакансию

Загрузи резюме в профиль, чтобы сгенерировать временное CV под эту вакансию

сопроводительное письмо

Загрузи резюме в профиль, а нейросеть определит твою категорию. Затем ты сможешь генерировать сопроводительные письма для вакансий этой категории

описание

Greencastle Digital brings together talented people from digital tech, product development, customer experience, and marketing to create cutting-edge solutions in the betting and gaming industry.

задачи

  • Design, write, test and tune detections across Cortex XDR / XSIAM, cloud telemetry, identity telemetry, endpoint, network and application logs;
  • Treat detections as code by version-controlling rules, peer-reviewing changes, writing tests, measuring coverage against MITRE ATT&CK, and retiring unused detections;
  • Own log onboarding and parsing for new sources while collaborating with platform and application engineering teams;
  • Run structured threat hunts against hypotheses derived from threat intelligence, recent incidents and attacker tradecraft relevant to online gambling;
  • Lead deep-dive investigations on alerts escalated from the Palo Alto MSSP, determine root cause and full scope before hand-back;
  • Document findings clearly for future analysts;
  • Stand on the bridge during P1 and P2 incidents and personally drive containment and eradication actions with engineering teams;
  • Own the technical timeline, indicators of compromise, evidence trail and artefacts needed for regulator notification and post-incident review;
  • Deputise for the Head of Cybersecurity as Incident Commander when required;
  • Build and maintain SOAR playbooks to automate triage, enrichment, containment and notification;
  • Integrate detection and response tooling with the wider stack using clean code;
  • Serve as the primary technical interface to the Palo Alto managed SOC, review detections, challenge analysis, and escalate issues;
  • Run regular detection and response exercises with the MSSP;
  • Work with offensive security partners to run purple-team exercises and translate findings into hardened detections;
  • Use breach-and-attack-simulation tooling to continuously validate detection coverage.

требования

  • Demonstrable hands-on experience as a SOC analyst, detection engineer, threat hunter or incident responder;
  • Strong working knowledge of at least one major SIEM/XDR platform and the query language behind it;
  • Practical experience investigating in AWS including CloudTrail, GuardDuty, VPC flow logs, EKS audit logs, and IAM analysis;
  • Scripting competence in Python or an equivalent;
  • Solid grounding in MITRE ATT&CK, the diamond model and a structured approach to investigation;
  • Calm under pressure and comfortable on a bridge call at 03:00;
  • Nice to have: Experience in online gambling, payments, financial services or high-volume consumer environments, exposure to retail or distributed-endpoint estates, experience working with or inside an outsourced SOC arrangement, practitioner or vendor certifications such as GCIA, GCIH, GCFA, GNFA, BTL1, relevant degree.

условия

  • On-call rotation;
  • No conditions specified.

Если просят войти через iCloud, отправить коды из SMS, запустить код, что-то установить, перевести деньги или сделать что угодно, связанное с деньгами, не соглашайтесь: это признаки мошенничества.

прозрачные зарплаты в IT

Анонимные данные по зарплатам и грейдам

Посмотреть
График динамики зарплат
Откликнуться Добавить в трекер

Если просят войти через iCloud, отправить коды из SMS, запустить код, что-то установить, перевести деньги или сделать что угодно, связанное с деньгами, не соглашайтесь: это признаки мошенничества.