Information Security specialist
Описание
We are looking for a Technical Information Security Specialist. The main responsibilities of this role include providing technical support during security audits, assessing the security of systems, and operating and enhancing a SIEM solution based on the Elastic Stack. Responsibilities Technical support for internal and external information security audits. Collection, analysis, and preparation of technical evidence for audits and compliance assessments. Verification of system configurations for compliance with information security requirements and internal policies. Participation in the review and approval of infrastructure changes, system integrations, architectural solutions, and access control configurations. Conducting technical risk assessments during the implementation of new systems and services. Administration and continuous improvement of Elastic SIEM (ELK). Development and optimization of detection rules, alerts, and Kibana dashboards. Monitoring, investigation, and analysis of information security events and incidents. Collaboration with IT teams, software developers, and information system owners. Requirements 2+ years of experience in Information Security, SIEM, or SOC. Hands-on experience with Elastic Stack / Elastic SIEM. Understanding of log collection, processing, and normalization principles. Experience working with authentication and access management logs. Understanding of IAM and IdP concepts, including SSO and MFA. Knowledge of Linux and Windows administration and security. Experience analyzing information system configurations and identifying technical security risks. Basic knowledge of SQL. Solid understanding of PostgreSQL and MySQL architecture, administration, logging, and security. Practical knowledge of information security standards, methodologies, and best practices. Experience with Jira and Confluence. Ability to document technical findings and provide clear, actionable recommendations. Nice to have: Experience applying AI in the field of Information Security. Experience with Okta, Google Workspace, and Google Cloud Platform (GCP). Knowledge of AWS security services and security mechanisms. Experience with SOAR platforms and solutions. Automation skills using Python or Bash. Familiarity with Information Security standards and methodologies. Experience developing detection rules and incident response playbooks. We offer Competitive remuneration. 5/2 work schedule. Remote work work. Flexiable start of working days.