WTW
28 сен

security engineer in enterprise cyber deception

ориентир по рынку
вакансия зп не указана
в среднем 323 895 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовься к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузи резюме

Рекламный баннер: ОБЩЕСТВО С ОГРАНИЧЕННОЙ ОТВЕТСТВЕННОСТЬЮ "ЦЕНТР НАЦИОНАЛЬНЫХ ИНТЕЛЛЕКТУАЛЬНЫХ СИСТЕМ"
О рекламодателе
ОБЩЕСТВО С ОГРАНИЧЕННОЙ ОТВЕТСТВЕННОСТЬЮ "ЦЕНТР НАЦИОНАЛЬНЫХ ИНТЕЛЛЕКТУАЛЬНЫХ СИСТЕМ"
ИНН: 9704271170

описание

The Global Information and Cyber Security Defence function builds and operates an enterprise cyber deception and Insider Risk Management programme integrated with Microsoft security products. Its work aims to detect adversaries earlier and deliver unified detection, investigation, and response across endpoint, identity, email, and cloud workloads.

задачи

  • Own and lead the enterprise cyber deception programme, including strategy, architecture, deployment, operations, and continuous improvement
  • Design, deploy, and operate a layered deception fabric across on-premises, hybrid, and multi-cloud environments
  • Act as the technical authority for deception engineering and Microsoft Defender XDR across the enterprise
  • Lead the design, implementation, and optimisation of Microsoft Defender XDR across endpoint, identity, email, and cloud-app workloads
  • Integrate deception signals into Defender XDR and Microsoft Sentinel as high-fidelity detections
  • Define and enforce a unified detection and response strategy across the Microsoft security stack
  • Lead the design and implementation of Microsoft Purview Data Loss Prevention policies
  • Define and enforce data protection controls to prevent unauthorised data exfiltration and misuse
  • Use Microsoft Insider Risk Management to detect risky user behaviour, including data leaks, policy violations, and insider threats
  • Correlate DLP, IRM, and identity signals with Microsoft Defender XDR to provide unified incident context
  • Collaborate with Risk, Compliance, and Legal teams to align DLP and insider risk controls with regulatory and business requirements
  • Optimise detection use cases combining identity, data, and behavioural analytics
  • Extend deception and Defender-style detection capabilities across AWS, GCP, and OCI
  • Ensure consistent detection, deception, and response coverage across hybrid and multi-cloud environments
  • Contribute to automation of deception deployment, detection, investigation, and response workflows using Microsoft Sentinel SOAR, Logic Apps, and Microsoft Security Copilot
  • Define KPIs and metrics for deception engagement, detection coverage, and response maturity
  • Improve detection, hunting, and deception capabilities in line with emerging threats and adversary tradecraft
  • Lead and grow a team of Defender XDR and Deception Engineers, setting technical direction, standards, and delivery priorities
  • Partner with SOC, CTI, Identity, Cloud, and Engineering teams to embed deception and Defender XDR detection into enterprise platforms
  • Mentor deception engineers, detection engineers, threat hunters, and SOC analysts
  • Communicate deception strategy, detection coverage, residual risk, and security improvements to senior stakeholders
  • Lead incident response across identity, endpoint, email, and cloud domains

требования

  • Hands-on experience with open-source and commercial deception and honeypot platforms
  • Advanced KQL for detection engineering and threat hunting at scale
  • Experience with detection-as-code, CI/CD of detection content, and security content management
  • Strong knowledge of adversary tradecraft and MITRE ATT&CK, MITRE Engage, MITRE D3FEND, and the cyber kill chain
  • Experience leveraging Agentic AI, Microsoft Security Copilot, or AI/ML in security operations
  • Proven experience designing and operating enterprise cyber deception programmes at scale
  • Extensive hands-on experience operating and engineering Microsoft Defender XDR in large enterprises
  • Deep expertise across Microsoft Defender for Identity, Microsoft Sentinel, Microsoft Security Copilot, Microsoft Defender for Cloud Apps, and Defender for Cloud
  • Strong scripting and automation experience with PowerShell, Python, or equivalent
  • Deep understanding of Zero Trust architecture and identity-centric defence
  • Будет плюсом: experience contributing to red-team or purple-team exercises and breach-and-attack simulation programmes, Microsoft security certifications (SC-200, AZ-500, SC-100), industry certifications (CISSP, GCIA, GCFA, GCIH, OSCP, or equivalent), cloud certifications across AWS, GCP, or OCI

условия

  • Локация: Лондон
  • 25 Days of annual leave plus an extra WTW day
  • Private healthcare, life insurance, group income protection, and regular health assessments
  • Defined contribution pension scheme with matched company contributions up to 10%
  • Employee assistance programme and a fully paid volunteer day
  • Optional electric vehicle car scheme, share scheme, cycle-to-work programme, dental and optical cover, critical illness protection, and other perks

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайся: это мошенничество.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайся: это мошенничество.