At least 5 years in the field of information security. • Higher education in one of the following areas: o Information security; o Cybersecurity; o Information technology; o Computer systems and networks; o Telecommunications. • The availability of industry-specific certificates is approved. • At least 5 years of work experience in the field of information security, confirmed experience in designing security systems or leading complex information security projects. • A deep understanding of modern information security concepts (Zero Trust, DevSecOps, Cloud Security, etc.), principles for creating IT infrastructures, and risk management systems. • Possession of expert knowledge on information security methodologies and standards (e.g., ISO/IEC 27001, NIST, CIS, etc.). • Have experience in independently developing and successfully implementing information security policies, standards, and regulations at the company level. • The presence of professional certifications in the field (e.g., CISSP, CISM, CRISC, CEH, CISA) is positively evaluated.
• Strategic IT management: Developing, protecting, and monitoring the implementation of an information security strategy, as well as ensuring the company's cybersecurity.
• Architecture and methodology: Designing an integrated architecture of information protection systems (IPS), establishing information security standards, methodologies, and best practices for IT infrastructure and business processes.
• Risk management: Identification, assessment, and in-depth analysis of cyber threats; development and implementation of threat models and measures to minimize them.
• Regulatory support: Expert development, updating, and monitoring the implementation of high-level information security policies, regulations, and procedures.
• Ekspertiza va R&D: Axborotni himoya qilishning ilg‘or vositalarini tanlash, sinovdan o‘tkazish va joriy etishda ekspert yordamini ko‘rsatish. IT-yechimlarning xavfsizlik talablariga muvofiqligini aniqlash uchun texnologik audit o‘tkazish.
• Incident management: Coordinating the investigation of complex cyber incidents (as a leading expert), conducting root cause analysis, and developing systemic measures.
• Consulting and compliance: Acting as a key advisor to top management and related departments (IT, lawyers, risks); preparing analytical reports and recommendations for management on improving information security.
Fill out the form below, don't forget to upload your resume (in pdf, rar, zip, doc format).