Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Analyst (Compliance and Controls) (SIEM, cloud security, compliance): Monitoring and responding to security incidents across Nebius infrastructure while maintaining compliance with security controls and standards with an accent on Microsoft Sentinel, Entra ID, Purview, and cloud compliance. Focus on investigating incidents, remediating technical violations, implementing detection and automation, and providing audit evidence across frameworks such as SOX, DORA, GDPR, and SOC II.
Location: Amsterdam, Netherlands, or remote in Europe
Company
Nebius builds a full-stack AI cloud platform for data processing, model training, and production deployment, with infrastructure spanning compute, storage, networking, and applied AI.
What you will do
- Monitor, investigate, and respond to security incidents across SIEM, CSPM, and other security solutions.
- Assess the impact of incidents on compliance posture and remediate technical compliance violations.
- Design and implement detections for compliance violations.
- Collaborate with internal and external auditors to provide evidence of adherence to compliance requirements.
- Create and maintain automation for security compliance and incident investigations using Logic Apps, PowerShell scripts, and Sentinel playbooks.
- Document and report incidents, investigations, and compliance requirements while collaborating with Technology, SecOps, Compliance, and Audit teams.
Requirements
- 2+ years of hands-on experience as a security analyst using SIEM, EDR, and CSPM technologies in enterprise environments.
- Experience with Microsoft Sentinel, including KQL queries, analytic rules, automation playbooks, and dashboards.
- Experience with Microsoft Entra ID and Microsoft Purview.
- Experience providing and validating audit evidence for SOX, DORA, GDPR, or SOC II controls in cloud environments.
- Experience remediating security incidents and understanding identity and access management lifecycles, SIEM, SOAR, and compliance frameworks such as NIST.
- Intermediate written and spoken English is required.
Nice to have
- Microsoft SC-200, SC-300, or SC-400 certifications.
- Experience with cloud security posture management, vulnerability management, EDR, or compliance violation remediation.
- Familiarity with DevOps practices, Git, and Azure DevOps for security automation.
- Scripting or development experience with PowerShell, RESTful APIs, Microsoft Graph API, Python, or Bash.
Culture & Benefits
- Competitive compensation.
- Career growth and learning opportunities.
- Flexibility, ownership, and a collaborative working environment.
- Opportunity to work on impactful AI projects in an international environment.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →