security engineer for centralized security monitoring
ориентир по рынку
вакансия
зп не указана
в среднем
346 799 ₽
мэтч
Загрузи резюме, чтобы видеть мэтчи с вакансией
подготовься к отклику
ai-инструменты
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузи резюме
О рекламодателе
ОБЩЕСТВО С ОГРАНИЧЕННОЙ ОТВЕТСТВЕННОСТЬЮ "ЦЕНТР НАЦИОНАЛЬНЫХ ИНТЕЛЛЕКТУАЛЬНЫХ СИСТЕМ" ИНН: 9704271170
описание
The customer provides digital infrastructure, cloud services, cybersecurity, data-driven solutions, and managed IT support. It helps organizations modernize technology environments, strengthen security, and improve the reliability and scalability of digital operations. The project provides cybersecurity and digital services for international organizations in a multi-tenant environment, supporting centralized security monitoring, threat detection, and cyber defense operations.
задачи
Administer, maintain, and upgrade the SIEM platform, including its health, performance, capacity, and licensing
Onboard and normalize new network, endpoint, cloud, identity, and application log sources, including in multi-tenant setups
Develop, tune, and maintain detection rules, correlation searches, dashboards, and reports
Reduce false positives with SOC analysts and implement new use cases
Build and maintain SOAR playbooks and integrations
Maintain documentation, data retention policies, and access control
Support audits and compliance reporting
требования
At least 5 years of IT or cybersecurity experience, including at least 3 years administering an enterprise SIEM in production
Hands-on experience with at least one major SIEM: Microsoft Sentinel, Splunk ES, IBM QRadar, or Elastic Security
Hands-on experience onboarding, parsing, and normalizing log sources using Syslog, CEF, Windows Event Forwarding (WEF), and API-based cloud connectors
Experience writing detection content in a platform query language such as KQL, SPL, AQL, or equivalent
Understanding of MITRE ATT&CK for mapping detection coverage
Clean professional records and willingness to undergo background verification
Upper-Intermediate English or above
Будет плюсом: Vendor certifications such as Microsoft SC-200, Splunk Certified Admin/Architect, or IBM QRadar; SOAR experience with Sentinel Logic Apps, Splunk SOAR, or Cortex XSOAR; multi-tenant SIEM or MSSP experience; scripting and automation with Python or PowerShell and Infrastructure as Code; detection-as-code practices such as Sigma and Git-based rule management
условия
Stable and competitive salary and an extensive benefits package