Если вы раньше входили через Google, сбросьте пароль для своей Gmail-почты через кнопку «Забыли пароль?» на экране входа. Затем войдите по email и новому паролю.
Если аккаунта ещё нет, зарегистрируйтесь с Gmail-почтой, после подтверждения почты мы предложим задать пароль.
Что нового
Загружаю обновления...
Что нового
Загружаю обновления...
Работа найдется быстрее с подпискойКандидат найдётся быстрее с подпиской
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
Fortegra provides insurance services and safeguards organizational data, applications, infrastructure, and AI systems across on-premises, cloud, and SaaS environments.
задачи
Monitor and tune SIEM, EDR/XDR, SOAR, email security, DLP, and CSPM solutions;
Lead investigations into escalated security incidents, including triage, forensic analysis, containment, eradication, and recovery;
Develop and maintain detections aligned with MITRE ATT&CK and the organization’s threat model;
Conduct tabletop exercises, purple-team engagements, and incident management drills;
Maintain incident response runbooks and playbooks;
Lead vulnerability remediation across endpoints, servers, cloud workloads, containers, and SaaS applications;
Design and execute vulnerability assessments, penetration tests, red-team exercises, and security audits;
Maintain hardened security baselines for workstations, servers, cloud resources, containers, and network devices;
Consume and operationalize threat intelligence;
Design, implement, and review cloud security controls;
Advance the organization’s Zero Trust strategy;
Review Infrastructure-as-Code manifests and maintain policy-as-code guardrails;
Partner with IT and identity teams on IAM, SSO, MFA, privileged access management, and conditional access policies;
Enforce secure coding practices and deliver annual secure-development training;
Integrate and tune security testing in CI/CD pipelines;
Establish and maintain software supply chain controls, including SBOM generation and dependency review;
Lead threat-modeling sessions for new products, services, and AI-enabled features;
Define and enforce policies for the safe adoption and use of AI tools;
Assess and mitigate AI/ML security risks;
Apply AI security frameworks when evaluating vendors, internal AI products, and AI-generated code;
Review AI-generated code for security vulnerabilities and licensing issues;
Partner with Legal, Privacy, and Engineering on AI data handling, retention, and disclosure practices;
Evaluate and deploy AI-assisted security tooling;
Build lightweight automations and scripts to streamline security workflows;
Validate the accuracy and safety of AI-driven security tooling and document its operating envelope;
Prepare for and respond to internal and external IT audits and risk assessments;
Recommend and assist with deploying, integrating, and configuring security solutions;
Maintain current knowledge of security threats, defensive tooling, and AI-related risks;
Provide periodic on-call support for security incidents;
Perform other assigned duties.
требования
Bachelor’s degree in Computer Science, Information Security, or a related technical field, or equivalent professional experience;
4+ Years of experience in information security, security engineering, or a closely related role;
Experience with cybersecurity frameworks including NIST CSF, NIST 800-53, ISO 27001, CIS Controls, and MITRE ATT&CK;
Hands-on experience securing AWS, Azure, or GCP environments;
Experience with vulnerability management, patching, and remediation across servers, endpoints, containers, and cloud workloads;
Experience integrating security into CI/CD pipelines;