Если вы раньше входили через Google, сбросьте пароль для своей Gmail-почты через кнопку «Забыли пароль?» на экране входа. Затем войдите по email и новому паролю.
Если аккаунта ещё нет, зарегистрируйтесь с Gmail-почтой, после подтверждения почты мы предложим задать пароль.
Что нового
Загружаю обновления...
Что нового
Загружаю обновления...
Работа найдется быстрее с подпискойКандидат найдётся быстрее с подпиской
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
EPAM helps enterprises through software products, open-source solutions, and accelerators.
задачи
Monitor security alerts and logs across endpoints, networks, cloud environments, and applications using SIEM/SOAR platforms;
Investigate and respond to security incidents through triage, containment, and root-cause analysis;
Develop and tune detection rules, correlation logic, and alerting to reduce false positives and close coverage gaps;
Build and maintain incident-response automation and SOAR playbooks;
Conduct vulnerability management, including scanning, prioritization, and remediation coordination with engineering teams;
Perform threat hunting to proactively identify malicious activity;
Support the deployment and integration of security tooling, including EDR, SIEM, cloud security posture tools, and IAM;
Participate in the on-call rotation for security incidents;
Contribute to post-incident reviews and documentation, including runbooks and RCAs;
Collaborate with IT, DevOps, and engineering teams to harden infrastructure and enforce security best practices;
Assist with compliance and audit activities, including SOC 2 and ISO 27001.
требования
5+ Years of experience in security operations, incident response, or a related field;
At least 1 year of relevant leadership experience;
Hands-on expertise with SIEM tools, including Splunk, Sentinel, Elastic, or QRadar, and EDR tools;
Solid understanding of networking, Linux/Windows operating systems, and AWS, Azure, or GCP cloud environments;
Familiarity with common attack techniques and frameworks, including MITRE ATT&CK and the NIST Cybersecurity Framework;
Scripting proficiency in Python, Bash, or PowerShell for automation and tooling;
Background in vulnerability management and remediation workflows;
Strong analytical and problem-solving skills, with the ability to remain calm during incidents;
Clear written and verbal communication skills for documentation and cross-team collaboration;
English proficiency at B2 level;
Nice to have: Experience with SOAR platforms such as Palo Alto XSOAR or Tines, security certifications such as Security+, GCIH, GCIA, CISSP, or OSCP, background in threat intelligence or purple/red team collaboration, familiarity with container/Kubernetes security, experience in a regulated finance industry.