3 сен

cyber security engineer in cybersecurity

выше рынка на 170,2%
вакансия 867 127 ₽
в среднем 320 875 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовьтесь к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме

описание

Eligibility for a European Security Clearence at EU-LEVEL SECRET

A prestigious European institution operates a Cyber Security Operations Centre focused on strengthening IT security across the organization.

задачи

  • Develop threat-informed detection content by translating cyber threat intelligence, incident reports and adversary techniques into documented threat vectors, detection hypotheses and measurable detection objectives;
  • Design, implement and maintain managed detection rules using the internal Detection Engineering framework;
  • Deploy detection rules across Security Operations Centre platforms, including SIEM and endpoint or runtime detection solutions;
  • Develop detection use cases for physical, virtual and containerised Linux workloads;
  • Address threats related to execution, persistence, privilege escalation, credential access, defence evasion, lateral movement and data exfiltration in container and Kubernetes environments;
  • Integrate and validate container-security telemetry sources, including runtime events, Kubernetes audit logs, orchestration events and relevant cloud control-plane logs;
  • Ensure that security data is properly normalised, enriched, ready for correlation and of sufficient quality for use within the corporate SIEM;
  • Continuously tune and optimise deployed detections, including false-positive reduction, exception and exclusion management, suppression logic, risk scoring and performance monitoring;
  • Conduct proactive threat-hunting and retro-hunting activities across containerised Linux workloads;
  • Document threat-hunting results and convert validated detection prototypes into production-ready managed detection rules;
  • Map detections to relevant threat techniques, identify detection coverage gaps and recommend improvements to logging and telemetry.

требования

  • Hold a qualification corresponding to at least Level 5 of the European Qualifications Framework;
  • Demonstrate in-depth knowledge of Linux operating systems and Linux security;
  • Demonstrate a strong understanding of attacker techniques affecting Linux environments;
  • Know process, file-system and network telemetry, audit sources, persistence techniques and privilege-escalation methods;
  • Have proven experience in detection engineering for containerised workloads;
  • Understand container runtime concepts, including namespaces, cgroups, image lifecycle and isolation boundaries;
  • Know common container attack paths, including container escape and breakout scenarios;
  • Have hands-on knowledge of Kubernetes security telemetry and threats;
  • Have experience with Kubernetes audit logging, RBAC abuse patterns, workload identities, admission controls and common security misconfigurations;
  • Have practical experience with at least one container runtime detection solution, such as Falco, Sysdig or an equivalent platform;
  • Have experience authoring and tuning runtime detection rules;
  • Have experience managing detection suppressions, exclusions and rule lifecycles in production environments;
  • Demonstrate the ability to design, test, validate, deploy and maintain detection logic through a structured detection lifecycle;
  • Be eligible for a European Security Clearance at EU-LEVEL SECRET.

условия

  • Freelancer agreement with an initial contract duration of 220 days, with the possibility for renewal;
  • 20 Days of on-site office presence in Luxembourg at the client's site;
  • Trips are not compensated.

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.