Ukrainian IT company
Nova Digital, which is part of the NOVA group of companies, is a powerful manufacturer of web applications and software for architectures of any complexity and load . We create, maintain and constantly improve software products, the convenience of which has already been appreciated by 32 million private and business clients of Nova Poshta. We are expanding our team, so we are currently looking for a
SOC Team LeadWhat will you do- Management and coordination of SOC activities to ensure effective monitoring and response to security incidents
- Ensuring 24/7 operation of SOC
- Responsibility for continuous monitoring of critical information systems and analysis network activity with the aim of preventing potential threats and detecting anomalies
- Managing the process of investigating security incidents and ensuring their timely resolution
- Controlling and processing events and security incidents from systems (SIEM, EDR, WAF, etc.) ), requests from employees or customers
- Creation and improvement of incident response procedures and protocols and ensuring compliance of procedures with internal policies and external regulatory requirements
- Collaboration with other departments to ensure the overall information security of the organization
- Support professional development of the SOC team, providing them with knowledge of new threats and security technologies< /li>
- Tracking changes in legislation and information security standards, adaptation of SOC processes in accordance with new requirements
- Preparation of regular reports about the state of information security and SOC activity for the management of the organization
- Responsibility for the implementation of automated solutions for the performance of regular tasks of the department
About you- Education: Higher education in the field of information security, information technology or related disciplines
- Work experience in the field of information security from 5 years. At least 2 years of experience managing a SOC team or similar unit
- In-depth understanding of information security, network security and protection technologies
- In-depth knowledge of Advanced Persistent Threats (APT) tactics, techniques and methods< /li>
- Deep understanding of tactics, techniques and methods of possible attacks (Phishing, Spoofing, Malware, DDoS, Injection, Web attacks, etc.)
- Skills and experience in implementing and administering security incident monitoring and management systems such as: SIEM, IDS/IPS, WAF, EDR, DLP, Sandboxing, Threat intelligence, etc.)
- Skills in investigating security incidents and managing their response processes
- Experience writing scripts to automate tasks (for example, in Python, Bash, PowerShell)
- Knowledge of the main standards and regulatory requirements in the field of information security (ISO/IEC 27001, NIST, CIS, NIS 2 Directive)
- Ability to communicate clearly and effectively with different levels of management and by technical specialists
- Proficiency in English at an intermediate level or higher
Will advantage- Availability of CISSP, CISM, GCIH, CEH certifications or equivalent
- Practical experience of AWS, GCP, Azure
We offer- Official employment
- Paid vacation
- Medical insurance
- Necessary equipment for work
- Corporate culture that motivates and charges with positivity
- I work in a socially responsible company that follows trends, values the ideas of employees and develops together with them
Send your resume, let's get to know each other :)< /div>