Our client is an ambitious Ukrainian MilTech startup. For 4 years, the team has developed 8+ complex air defense systems (Hardware + Software), which are already certified and successfully protect the skies of Ukraine and EU countries.Now we are looking for Information Security Specialist who is ready to take on the role of Owner of functions and build an information security system (ISMS) "from scratch".This is a position for a specialist who wants to build the security architecture himself and
Our client is an ambitious Ukrainian MilTech startup. For 4 years, the team has developed 8+ complex air defense systems (Hardware + Software), which are already certified and successfully protect the skies of Ukraine and EU countries.
Now we are looking for Information Security Specialist who is ready to take on the role of Owner of functions and build an information security system (ISMS) "from scratch".
- This is a position for a specialist who wants to build the security architecture himself and in the future become a CISO of the company.
- Building the function "from scratch" - you define the strategy yourself (EDR, SIEM, DLP) and implement standards without excessive bureaucracy.
- Work at the interface of hardware and software, protection of strategically important developments.
- Your work directly strengthens the country's defense capability.
Key areas of responsibility:
- Development of policies, asset register and data classification.
- Technical Cyber Defense: implementation and administration of controls (EDR/XDR, SIEM, DLP, PAM, MDM). Ensuring the security of networks and cloud environments.
- Risk management: carrying out risk assessment, formation of Risk Register and their minimization plans for management.
- Incident Response: construction of monitoring, response (IRP) and recovery processes after incidents (BCP/DRP).
- Compliance & Awareness: ensuring compliance with the GDPR and the "On the Protection of Personal Data"; conducting trainings for the team.
- Vendor Security: audit of suppliers and control of IS requirements in contracts (NDA, SLA, DPA).
Our expectations:
- Experience 5+ years in Cyber/Information Security or IT Security.
- Practical experience implementing ISO 27001 architecture, on-prem and cloud security environments.
- Experience with SIEM, EDR, IAM, PAM. Understanding of SOC/IR processes.
- Knowledge of GDPR requirements, risk assessment methodologies and vulnerability management.
Would be an advantage: professional education and certifications (CISSP, CISM, CEH or ISO 27001 Auditor/Implementer).
Working conditions:
- Office in Kyiv (Right Bank).
- Office format, Mon-Fri, 09:00 - 18:00.
- Official employment and reservation (subject to the availability of appropriate military registration documents).
- Remuneration is negotiable. individually depending on experience and level of expertise.