Вакансии в ИБ | infosec
@infosec_work
Head of Information Security.
Локация: #Кипр (Relocation support)
Опыт: 8 лет.
Язык: English. B1 — Intermediate.
Зарплата: 9 000 — 12 000 €.
Компания: Scorewarrior.
Обязанности:
• Build a viable security system across the core domains: IAM (access management, MFA, SSO), infrastructure security (cloud, services, network), foundational SDLC/AppSec (security in the development process and in the code), and the processes and training around them. We expect you to start with a proper diagnosis of our landscape — and design the system for this company, rather than replaying a project from a previous job.
• Own security risks and speak both languages: business language with the CTO and CEO — risk, cost, and priorities; technology language with developers and infrastructure teams — architecture, trade-offs, and practical solutions.
• Make the right build-vs-buy calls: you know the security product market well enough to tell when a problem needs a tool, when a simpler method will do, and when the problem isn't in the tooling at all — it's in habits and heads.
• Introduce security as a partner, not a blocker: embed baseline practices so smoothly that teams barely notice them; for everything on top of that — inform, help when asked, and don't push when it's not the team's priority right now.
• Define how AI tools are used safely: own the policy and guardrails for the company-wide adoption of AI tools — what data can go where, and how teams can use them productively without creating new risks.
• Build the team: hire the first security engineers deliberately — knowing who you're hiring and why — and grow the function as the company's needs grow.
Требования:
• 8+ years of hands-on experience in security — real projects you designed, implemented, and stayed around long enough to see working. At the interview, we'll ask about specific cases, decisions, and their consequences — not about frameworks in theory.
• A background that gave you real systems experience. Two paths work equally well for us: a stable security engineering career from university onwards, or a transition into security from system administration, technical support, or network engineering. What matters is the result — you understand infrastructure and architecture from the inside, not from diagrams.
• Proven experience hiring and building a team — even a small one (2+ people). What matters is that it was deliberate: you can explain who you hired, why them, and how the team was structured around the actual problems.
• Experience building a security function, not just running one. You've taken security in an organization from an unclear state to a working system: assessed the landscape, set priorities, chose what to implement and what to skip — and can show what changed as a result.
• Strong awareness of the security product market. You can tell when a problem needs a tool, when a simpler method will do, and when the problem is in habits rather than tooling — and you have real examples of each call.
• A partner's operating style. You work through engineering teams, not above them: no separate authority demands, no blocking by default. Your practices get adopted because they make sense, not because they're mandatory.
Откликнуться.
#Офис
Локация: #Кипр (Relocation support)
Опыт: 8 лет.
Язык: English. B1 — Intermediate.
Зарплата: 9 000 — 12 000 €.
Компания: Scorewarrior.
Обязанности:
• Build a viable security system across the core domains: IAM (access management, MFA, SSO), infrastructure security (cloud, services, network), foundational SDLC/AppSec (security in the development process and in the code), and the processes and training around them. We expect you to start with a proper diagnosis of our landscape — and design the system for this company, rather than replaying a project from a previous job.
• Own security risks and speak both languages: business language with the CTO and CEO — risk, cost, and priorities; technology language with developers and infrastructure teams — architecture, trade-offs, and practical solutions.
• Make the right build-vs-buy calls: you know the security product market well enough to tell when a problem needs a tool, when a simpler method will do, and when the problem isn't in the tooling at all — it's in habits and heads.
• Introduce security as a partner, not a blocker: embed baseline practices so smoothly that teams barely notice them; for everything on top of that — inform, help when asked, and don't push when it's not the team's priority right now.
• Define how AI tools are used safely: own the policy and guardrails for the company-wide adoption of AI tools — what data can go where, and how teams can use them productively without creating new risks.
• Build the team: hire the first security engineers deliberately — knowing who you're hiring and why — and grow the function as the company's needs grow.
Требования:
• 8+ years of hands-on experience in security — real projects you designed, implemented, and stayed around long enough to see working. At the interview, we'll ask about specific cases, decisions, and their consequences — not about frameworks in theory.
• A background that gave you real systems experience. Two paths work equally well for us: a stable security engineering career from university onwards, or a transition into security from system administration, technical support, or network engineering. What matters is the result — you understand infrastructure and architecture from the inside, not from diagrams.
• Proven experience hiring and building a team — even a small one (2+ people). What matters is that it was deliberate: you can explain who you hired, why them, and how the team was structured around the actual problems.
• Experience building a security function, not just running one. You've taken security in an organization from an unclear state to a working system: assessed the landscape, set priorities, chose what to implement and what to skip — and can show what changed as a result.
• Strong awareness of the security product market. You can tell when a problem needs a tool, when a simpler method will do, and when the problem is in habits rather than tooling — and you have real examples of each call.
• A partner's operating style. You work through engineering teams, not above them: no separate authority demands, no blocking by default. Your practices get adopted because they make sense, not because they're mandatory.
Откликнуться.
#Офис
🤯 17
❤ 9
🔥 4
😁 4
🤔 3
82 3.8K
Обсуждение 0
Обсуждение не доступно в веб-версии. Чтобы написать комментарий, перейдите в приложение Telegram.
Обсудить в Telegram