Пълно описание
We are seeking a high-level Consultant to advise and support the continuous improvement of our IT Service and Security Operations team. This role combines technical oversight, strategic process design, and operational coordination across key tools and workflows. You will act as an internal advisor and technical bridge across IT, security, and service management domains.
The main responsibilities for the position are:
- Provide strategic input on monitoring strategy, security event handling, and operational maturity.
- Oversee the continuous monitoring of security and/or system events and incidents.
- Analyze and respond to cybersecurity threats and vulnerabilities.
- Coordinate incident response activities and manage security breaches.
- Conduct in-depth Threat Intelligence analysis of threat data.
- Identify and mitigate potential security risks.
- Manage and maintain security tools and technologies.
- Monitor the performance and effectiveness of security systems.
- Support tool governance, platform lifecycle discussions, and risk-aligned monitoring practices.
- Assist in defining process improvements and maintaining regulatory or internal control alignment.
- Facilitate knowledge transfer, documentation standardization, and operational scaling efforts.
Our requirements (Fundamentals):
- Experience: Minimum of 5+ years of experience in cybersecurity or security operations with proven track record in managing security incidents and threat analysis.
- Significant experience in IT service management, security operations, or infrastructure monitoring.
- Previous involvement in platform optimization, cross-team alignment, or monitoring architecture.
- Demonstrated ability to operate across departments and influence decisions with data and logic.
- Familiarity with enterprise-grade monitoring, detection, and incident handling tools.
- Strategic communication and documentation capabilities, with a process-oriented mindset.
- Network & Security Skills: Strong knowledge understanding of networking protocols (TCP/IP) and security solutions like firewalls, IDS/IPS systems, and VPNs3.
- SIEM Expertise: configure correlation rules, build dashboards, and manage alerts
- Incident Response: techniques for identifying, isolating, and mitigating security incidents.
- Bachelor’s degree in computer science, Information Security, or a related field.
- Advanced certifications such as CISSP, CISM, or CEH is highly desirable.
Advantage (Considered as a Plus):
- Experience advising or leading multi-platform monitoring environments. / Web application firewalls, IPS/IDS, Antispam solutions/
- Experience with EDR and XDR solutions.
- Tool governance and risk alignment knowledge (e.g., IT controls, audit readiness).
- Familiarity with enterprise frameworks (e.g., ITIL, NIST, MITRE ATT&CK).
- Advanced certifications such as CISSP, CISM, or CEH is highly desirable.
- SANS Institute Certifications, EC-Council's SOC Essentials Course (S|CE), Splunk Architect, Microsoft Azure Security Engineer.
- IТ or security experience in financial institutions.
We offer:
- A strategic role with influence on platform governance and operational roadmap.
- Opportunities to shape cross-functional detection and response practices.
- Engagement in coordination, advisory, and improvement-focused initiatives.
- A mature environment that values critical thinking, depth, and systemic insight.
Социални Придобивки
- health_and_safety iconДопълнително Здравно Осигуряване
- date_rangeДопълнителен Годишен Отпуск