Если вы раньше входили через Google, сбросьте пароль для своей Gmail-почты через кнопку «Забыли пароль?» на экране входа. Затем войдите по email и новому паролю.
Если аккаунта ещё нет, зарегистрируйтесь с Gmail-почтой, после подтверждения почты мы предложим задать пароль.
Что нового
Загружаю обновления...
Что нового
Загружаю обновления...
Работа найдется быстрее с подпискойКандидат найдётся быстрее с подпиской
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
Eligibility for a European Security Clearence at EU-LEVEL SECRET
A prestigious European institution operates a Cyber Security Operations Centre focused on strengthening IT security across the organization.
задачи
Develop threat-informed detection content by translating cyber threat intelligence, incident reports and adversary techniques into documented threat vectors, detection hypotheses and measurable detection objectives;
Design, implement and maintain managed detection rules using the internal Detection Engineering framework;
Deploy detection rules across Security Operations Centre platforms, including SIEM and endpoint or runtime detection solutions;
Develop detection use cases for physical, virtual and containerised Linux workloads;
Address threats related to execution, persistence, privilege escalation, credential access, defence evasion, lateral movement and data exfiltration in container and Kubernetes environments;
Integrate and validate container-security telemetry sources, including runtime events, Kubernetes audit logs, orchestration events and relevant cloud control-plane logs;
Ensure that security data is properly normalised, enriched, ready for correlation and of sufficient quality for use within the corporate SIEM;
Continuously tune and optimise deployed detections, including false-positive reduction, exception and exclusion management, suppression logic, risk scoring and performance monitoring;
Conduct proactive threat-hunting and retro-hunting activities across containerised Linux workloads;
Document threat-hunting results and convert validated detection prototypes into production-ready managed detection rules;
Map detections to relevant threat techniques, identify detection coverage gaps and recommend improvements to logging and telemetry.
требования
Hold a qualification corresponding to at least Level 5 of the European Qualifications Framework;
Demonstrate in-depth knowledge of Linux operating systems and Linux security;
Demonstrate a strong understanding of attacker techniques affecting Linux environments;
Know process, file-system and network telemetry, audit sources, persistence techniques and privilege-escalation methods;
Have proven experience in detection engineering for containerised workloads;
Understand container runtime concepts, including namespaces, cgroups, image lifecycle and isolation boundaries;
Know common container attack paths, including container escape and breakout scenarios;
Have hands-on knowledge of Kubernetes security telemetry and threats;
Have experience with Kubernetes audit logging, RBAC abuse patterns, workload identities, admission controls and common security misconfigurations;
Have practical experience with at least one container runtime detection solution, such as Falco, Sysdig or an equivalent platform;
Have experience authoring and tuning runtime detection rules;
Have experience managing detection suppressions, exclusions and rule lifecycles in production environments;
Demonstrate the ability to design, test, validate, deploy and maintain detection logic through a structured detection lifecycle;
Be eligible for a European Security Clearance at EU-LEVEL SECRET.
условия
Freelancer agreement with an initial contract duration of 220 days, with the possibility for renewal;
20 Days of on-site office presence in Luxembourg at the client's site;