Job Details

Information Security
Senior
Remote
Full time
May 2

Monitoring and Response Engineer

RUB 350,000

Monitoring and Response Engineer at T-Bank. Remote work. Salary from 350,000 ₽. Design and implement security incident monitoring and response processes in cloud environments.

• Design and implement security incident monitoring and response processes in cloud environments (AWS, GKE/Kubernetes). • Detect, analyze, and manage incidents: triage, investigation, conclusion and recommendation formulation, MTTR reduction. • Develop and improve detection content: correlation rules, alerts, signatures/behavioral scenarios, evaluate effectiveness (precision/recall, noise, coverage). • Formulate hypotheses based on current attacker techniques (TTPs) in the context of cloud-native and K8s infrastructure. • Identify blind spots with Red Team and Threat Hunting, conduct root cause analysis of incidents. • Improve security processes through Post Incident Activity.

• You have experience in building monitoring and response processes. • You have an excellent understanding of operating systems, networks, and modern technologies: Kubernetes, cloud platforms. • You understand cloud-native logging architecture and observability tools. • You have a deep understanding of attacker techniques and experience with offensive tools. • You have experience developing detection rules. • You are proficient in Python and one scripting language: Bash, PowerShell, or another. • You can formulate quality hypotheses and evaluate monitoring quality. • You have English language proficiency at B1-B2 level.

AWS
Kubernetes
TTP
Python
Threat Hunting
Red Team
Observability
Cloud-native
PowerShell
Bash
Security Incident Response

Don't miss a single job

Subscribe to our Telegram channel

Subscribe

Similar jobs

Head of Information Security Monitoring and Response (SOC)

Head of Information Security Monitoring and Response (SOC) at CDEK. Remote work option. Experience: 3-6 years. Salary discussed at interview.

С
СДЭК

AI Security Engineer

AI Security Engineer at T-Bank. Moscow. Salary is negotiable. Development of traffic inspection logic between applications and LLM, research into AI agent behavior, testing and validation of controls.

Russia
Т
Т-Банк

SIEM Engineer

SIEM Engineer with 1-3 years of experience in Moscow. Salary discussed during interview. Company: T1. Responsibilities include SIEM system administration, data source integration, parser development, and system optimization.

Russia
T
T1