We are seeking for experienced Cyber Security Manager, who will be responsible for leading the implementation and continuous improvement of AIFCA's Secure Software Development Lifecycle (SDLC), application security controls, and data protection initiatives. The successful candidate will work closely with development, infrastructure, and business teams to embed security-by-design principles throughout the software development lifecycle while supporting broader cybersecurity and data protection activities.
Key Responsibilities
-
Lead the implementation and continuous improvement of AIFCA's Secure Software Development Lifecycle (SDLC).
-
Implement and manage SAST and DAST solutions and integrate them into CI/CD pipelines.
-
Establish secure coding standards, security review processes, and application security controls.
-
Monitor application security vulnerabilities and coordinate remediation activities.
-
Conduct threat modeling and application security risk assessments.
-
Ensure alignment of development practices with OWASP and industry security standards.
-
Provide security guidance and awareness training to developers and stakeholders.
-
Collaborate with internal teams and vendors to embed security-by-design principles into projects.
-
Support Data Loss Prevention (DLP) and data protection initiatives using Microsoft Purview and related technologies.
-
Review security logs, alerts, and user activities to identify security risks and suspicious behavior.
-
Participate in access management processes, including provisioning, recertification, and joiner/mover/leaver reviews.
-
Develop, maintain, and improve cybersecurity policies, procedures, standards, and guidelines.
-
Support information security audits, risk assessments, and compliance reviews.
-
Investigate and respond to security incidents, cybersecurity requests, and service desk tickets.
-
Support procurement, vendor management, and budgeting activities related to cybersecurity solutions and services.
Requirements
-
Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Software Engineering, or a related field; Master's degree is an advantage.
-
Minimum 3 years of experience in cybersecurity, information security, or application security.
-
Hands-on experience with Secure Software Development Lifecycle (SDLC) practices.
-
Practical experience with SAST and DAST tools such as SonarQube, Checkmarx, Fortify, OWASP ZAP, or Burp Suite.
-
Strong knowledge of secure coding practices, OWASP Top 10, threat modeling, and vulnerability management.
-
Experience working with software development teams and CI/CD environments.
-
Familiarity with Microsoft security technologies, including Microsoft Purview, is an advantage.
-
Professional certifications such as Security+, CEH, CC, CSSLP, GWAPT, or OSWE are preferred.
-
Strong analytical, problem-solving, communication, and stakeholder management skills.
-
Proficiency in English, Russian, and Kazakh.

