Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузи резюме
О рекламодателе
ОБЩЕСТВО С ОГРАНИЧЕННОЙ ОТВЕТСТВЕННОСТЬЮ "ЦЕНТР НАЦИОНАЛЬНЫХ ИНТЕЛЛЕКТУАЛЬНЫХ СИСТЕМ" ИНН: 9704271170
описание
The Global Information and Cyber Security Defence function builds and operates an enterprise cyber deception and Insider Risk Management programme integrated with Microsoft security products. Its work aims to detect adversaries earlier and deliver unified detection, investigation, and response across endpoint, identity, email, and cloud workloads.
задачи
Own and lead the enterprise cyber deception programme, including strategy, architecture, deployment, operations, and continuous improvement
Design, deploy, and operate a layered deception fabric across on-premises, hybrid, and multi-cloud environments
Act as the technical authority for deception engineering and Microsoft Defender XDR across the enterprise
Lead the design, implementation, and optimisation of Microsoft Defender XDR across endpoint, identity, email, and cloud-app workloads
Integrate deception signals into Defender XDR and Microsoft Sentinel as high-fidelity detections
Define and enforce a unified detection and response strategy across the Microsoft security stack
Lead the design and implementation of Microsoft Purview Data Loss Prevention policies
Define and enforce data protection controls to prevent unauthorised data exfiltration and misuse
Use Microsoft Insider Risk Management to detect risky user behaviour, including data leaks, policy violations, and insider threats
Correlate DLP, IRM, and identity signals with Microsoft Defender XDR to provide unified incident context
Collaborate with Risk, Compliance, and Legal teams to align DLP and insider risk controls with regulatory and business requirements
Optimise detection use cases combining identity, data, and behavioural analytics
Extend deception and Defender-style detection capabilities across AWS, GCP, and OCI
Ensure consistent detection, deception, and response coverage across hybrid and multi-cloud environments
Contribute to automation of deception deployment, detection, investigation, and response workflows using Microsoft Sentinel SOAR, Logic Apps, and Microsoft Security Copilot
Define KPIs and metrics for deception engagement, detection coverage, and response maturity
Improve detection, hunting, and deception capabilities in line with emerging threats and adversary tradecraft
Lead and grow a team of Defender XDR and Deception Engineers, setting technical direction, standards, and delivery priorities
Partner with SOC, CTI, Identity, Cloud, and Engineering teams to embed deception and Defender XDR detection into enterprise platforms
Mentor deception engineers, detection engineers, threat hunters, and SOC analysts
Communicate deception strategy, detection coverage, residual risk, and security improvements to senior stakeholders
Lead incident response across identity, endpoint, email, and cloud domains
требования
Hands-on experience with open-source and commercial deception and honeypot platforms
Advanced KQL for detection engineering and threat hunting at scale
Experience with detection-as-code, CI/CD of detection content, and security content management
Strong knowledge of adversary tradecraft and MITRE ATT&CK, MITRE Engage, MITRE D3FEND, and the cyber kill chain
Experience leveraging Agentic AI, Microsoft Security Copilot, or AI/ML in security operations
Proven experience designing and operating enterprise cyber deception programmes at scale
Extensive hands-on experience operating and engineering Microsoft Defender XDR in large enterprises
Deep expertise across Microsoft Defender for Identity, Microsoft Sentinel, Microsoft Security Copilot, Microsoft Defender for Cloud Apps, and Defender for Cloud
Strong scripting and automation experience with PowerShell, Python, or equivalent
Deep understanding of Zero Trust architecture and identity-centric defence
Будет плюсом: experience contributing to red-team or purple-team exercises and breach-and-attack simulation programmes, Microsoft security certifications (SC-200, AZ-500, SC-100), industry certifications (CISSP, GCIA, GCFA, GCIH, OSCP, or equivalent), cloud certifications across AWS, GCP, or OCI
условия
Локация: Лондон
25 Days of annual leave plus an extra WTW day
Private healthcare, life insurance, group income protection, and regular health assessments
Defined contribution pension scheme with matched company contributions up to 10%
Employee assistance programme and a fully paid volunteer day
Optional electric vehicle car scheme, share scheme, cycle-to-work programme, dental and optical cover, critical illness protection, and other perks