Responsibilities:
Perform risk analysis for IT projects and third-party vendor relationships.
Develop and implement information security policies, procedures, and methodologies.
Deploy and manage core security tools: Wazuh SIEM, vulnerability management, and WAF systems.
Coordinate security control implementation and lead incident response efforts.
Proactively monitor IT infrastructure security and drive vulnerability remediation.
Create and maintain the corporate information security risk register and heat maps.
Represent KPMG/NITSO as a delegate at industry conferences.
Ensure full compliance with mandatory training and labor protection requirements.
Conduct comprehensive security reviews for infrastructure and new projects.
Requirements:
Core Skills: Technical skills, vulnerability management, script language proficiency, risk management.
Preferred:
Knowledge of standards: ISO2700x, NIST, SANS, PCI DSS.
Knowledge of risk methodologies: CRAMM, Octave, OWASP.
Knowledge of secure application development cycle (SDLC).
Elite Business Group
Астана
от 300000 KZT
SoftwareONE Kazakhstan (СофтвареУан Казахстан)
Астана
от 300000 KZT
Астана
от 300000 KZT
АйТи Сервис Менеджмент
Астана
от 300000 KZT
Auslogics Labs Pty Ltd
Астана
от 300000 KZT