Salary
≈ $20k – $46k per year (Estimated)
Location
Remote/Hybrid (Astana, Kazakhstan)
Seniority
Senior
Employment
Full-Time
Overview
Company
Impact
Profile match
KazDream is a Kazakh technology company founded in 2011 and headquartered in Astana. It develops data analytics and media monitoring systems. The company works with public institutions and large enterprises.
Задачи:
- Мониторинг, анализ и обеспечение visibility событий безопасности корпоративной инфраструктуры.
- Развитие и сопровождение процессов: Security Monitoring, Detection Engineering, Threat Hunting, Incident Investigation, Security Visibility.
- Разработка и сопровождение detection use-cases и detection logic для: SIEM, IDS/IPS, EDR/XDR, network monitoring systems, authentication telemetry.
- Разработка: IOC-based detection, TTP-based detection, behavior-based detection, anomaly detection сценариев.
- Разработка и оптимизация: correlation rules, anomaly detection rules, alert enrichment, threat detection pipelines.
- Контроль качества detection coverage и выявление blind spots в monitoring visibility.
- Контроль полноты: security telemetry, centralized logging, event visibility, detection coverage.
- Формирование требований к: security logging, telemetry collection, event correlation, monitoring coverage.
- Работа с SIEM-системами: анализ корреляции событий, enrichment security events, IOC correlation, ATT&CK mapping, выявление аномалий, анализ gaps в visibility инфраструктуры.
- Анализ telemetry data из: SIEM, EDR/XDR, network telemetry, authentication logs, centralized logging systems.
- Проведение hypothesis-driven threat hunting на основе: ATT&CK, IOC, telemetry, anomalous behavior, attacker TTP.
- Выявление признаков: persistence, lateral movement, credential abuse, command & control, privilege escalation, defense evasion.
- Проведение incident investigation и reconstruction attack chain.
- Анализ: IOC, TTP, malicious activity, attacker behavior, compromise scope.
- Координация и участие в расследовании инцидентов безопасности.
- Подготовка: containment recommendations, eradication recommendations, remediation recommendations, detection improvement recommendations.
- Использование Threat Intelligence для: enrichment, IOC correlation, ATT&CK mapping, detection improvement.
- Анализ сетевого трафика и telemetry data с использованием: Wireshark, tcpdump, NetFlow/sFlow, Zeek или аналогичных инструментов.
- Участие в процессе Vulnerability Management в части: attack surface analysis, externally exposed services, exploitation visibility, threat exposure analysis.
- Контроль и анализ: security visibility, uncontrolled infrastructure zones, detection blind spots, telemetry gaps.
- Разработка и сопровождение: detection standards, monitoring use-cases, incident investigation procedures, detection recommendations.
- Подготовка: incident reports, attack chain reports, detection recommendations, IOC reports, threat hunting reports.
- Взаимодействие с Infrastructure, DevOps: detections, incident investigation, telemetry, threat visibility.
Что мы ожидаем:
- Высшее образование в области информационных технологий или информационной безопасности.
- Опыт работы в SecOps, Detection Engineering, Threat Hunting, SOC или Incident Response не менее 4-5 лет.
- Отличное понимание: detection engineering, threat hunting, IOC/TTP analysis, attack chain analysis, incident investigation, telemetry analysis.
- Практический опыт разработки detection logic для: SIEM, IDS/IPS, EDR/XDR, authentication telemetry.
- Практический опыт работы с: SIEM, EDR/XDR, IDS/IPS, Threat Intelligence, centralized logging systems.
- Опыт работы с SIEM-платформами: ELK, Splunk, QRadar, Sentinel или аналогичными решениями.
- Практический опыт: IOC-based detection, TTP-based detection, behavior-based detection, anomaly detection.
- Опыт разработки: correlation rules, detection use-cases, alert enrichment, monitoring pipelines.
- Практический опыт проведения: threat hunting, incident investigation, attack chain reconstruction, compromise analysis.
- Понимание MITRE ATT&CK в части: Initial Access, Execution, Persistence, Defense Evasion, Credential Access, Discovery, Lateral Movement, Command and Control, Exfiltration.
- Понимание: attacker behavior, TTP, IOC lifecycle, detection blind spots, telemetry gaps.
- Практический опыт анализа telemetry data: network telemetry, authentication telemetry, endpoint telemetry, cloud telemetry.
- Опыт анализа: malicious traffic, credential abuse, lateral movement, command & control activity, persistence mechanisms.
- Опыт работы с: Wireshark, tcpdump, NetFlow/sFlow, Zeek или аналогичными инструментами.
- Понимание: centralized logging, telemetry pipelines, security visibility, detection coverage.
- Базовое понимание: Linux, Windows, cloud infrastructure, networking в контексте incident investigation и telemetry analysis.
- Навыки автоматизации и скриптинга: Python, Bash, PowerShell - будут преимуществом.
- Опыт анализа malware behavior - будет преимуществом.
- Понимание процессов Vulnerability Management и exploitation visibility.
- Аналитическое мышление, способность самостоятельно расследовать инциденты и принимать технические решения в условиях инцидента.
- Умение взаимодействовать с DevOps, Infrastructure, SOC и Security командами.
- Умение документировать: attack chain, IOC, TTP, technical findings, detection recommendations.
Дополнительные требования:
- Понимание: Threat Intelligence, ATT&CK-based detection, detection maturity, security telemetry architecture.
- Опыт интеграции: SIEM, EDR/XDR, IDS/IPS, Threat Intelligence Platform, centralized monitoring systems.
- Понимание принципов: hybrid infrastructure visibility, Kubernetes telemetry, container security visibility.
- Понимание современных TTP атакующих групп.
- Приветствуются сертификаты: Security+, Splunk, GCIA, GCIH, Blue Team certifications.
- Уверенное чтение технической документации на английском языке.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,634 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Free forever. No card. Under a minute.
Your match
How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.
Recommended for you based on this role
Similar stack
Same company
Astana
≈ $28k – $65k per year (Estimated) • In office • Full-Time • 12+ years exp • Bengaluru
Bash
PowerShell
Python
Node JS
JavaScript
Node JS
Commander.js
AI/ML
AI Agents
DevOps
Amazon EC2
Amazon EKS
AWS
Azure
Kubernetes
Amazon ECS
IAM
Cybersecurity
Crowdstrike
Zero Trust
Apply
Senior Infrastructure & Cloud Engineer
1 day ago
≈ $42k – $104k per year (Estimated) • In office • Internship • 5+ years exp
Bash
PowerShell
Python
DevOps
Amazon EC2
Amazon EKS
Ansible
AWS
AWS Lambda
Azure
CentOS Stream
Chef
CI/CD
CloudFormation
Configuration Management
Datadog
FinOps
GCP
Git
GitHub Actions
GitLab CI
Grafana
Hyper-V
Istio
Jenkins
Kubernetes
KVM
Linkerd
Platform Engineering
Prometheus
Puppet
Service Mesh
Splunk
Terraform
Ubuntu
VMWare
Windows Server
Amazon CloudWatch
Amazon ECS
Amazon S3
API Gateway
AWS Step Functions
GitHub
GitLab
IAM
Cybersecurity
GDPR
ISO 27001
SOC 2
Apply
Junior DevOps Engineer
1 day ago
≈ $11k – $24k per year (Estimated) • Remote/Hybrid • Saint Petersburg
Bash
PowerShell
DevOps
CI/CD
Docker
Git
GitLab CI
Hyper-V
kubectl
Kubernetes
Proxmox VE
VMWare
GitLab
Apply
Platform Operations Engineer
1 day ago
≈ $54k – $159k per year (Estimated) • In office • Full-Time • 4+ years exp • Bachelor's Degree • Singapore
Bash
PowerShell
Python
DevOps
Ansible
AWS
Azure
Chef
Docker
Hyper-V
Incident Management
Kubernetes
Puppet
Red Hat
Terraform
VMWare
Windows Server
Apply
Системный администратор
1 day ago
≈ $15k – $38k per year (Estimated) • In office • Contractor • Bachelor's Degree • Saint Petersburg
Bash
PowerShell
Python
DevOps
Hyper-V
Nagios
SLI/SLO/SLA
VMWare
Windows Server
Zabbix
Apply
Backend-разработчик
4 days ago
≈ $17k – $46k per year (Estimated) • In office • Full-Time • Astana
Node JS
Python
TypeScript
JavaScript
Databases
PostgreSQL
Supabase
AI/ML
Claude
Claude Code
Copilot
Cursor
LLM
Windsurf
Frontend
React.js
Mobile
Firebase
DevOps
Docker
GitHub
Apply
Frontend-разработчик
4 days ago
In office • Full-Time • Astana
Node JS
SQL
TypeScript
JavaScript
Databases
Supabase
AI/ML
Claude
Claude Code
Copilot
Cursor
LLM
Frontend
Ant Design
React.js
shadcn/ui
Tailwind CSS
Radix UI
DevOps
Rest API
GitHub
Apply
Manual QA engineer
4 days ago
≈ $6k – $25k per year (Estimated) • Remote/Hybrid • Full-Time • 1+ year exp • Bachelor's Degree • Astana
SQL
AI/ML
LLM
DevOps
CI/CD
Git
Grafana
Kibana
Rest API
Design
Figma
Management
Confluence
Jira
QA
Postman
Swagger
Apply
Chief Technical Officer (CTO)
11 days ago
≈ $30k – $64k per year (Estimated) • In office • Full-Time • 5+ years exp • Astana
Java
C#
C#
.NET
AI/ML
LLM
DevOps
CI/CD
Kubernetes
Apply
Senior Product Manager
11 days ago
≈ $24k – $49k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • Astana
Apply
Fullstack-разработчик
7 hours ago
$22k – $38k per year (net) • In office • Full-Time • 3+ years exp • Astana
Python
TypeScript
JavaScript
Python
Alembic
Celery
FastAPI
Litestar
Pydantic
SQLAlchemy
structlog
Databases
ClickHouse
ElasticSearch
MinIO
NATS
Neo4j
PostgreSQL
Redis
AI/ML
LLM
OpenAI
Pydantic AI
Frontend
Mantine
React Hook Form
React.js
Recharts
shadcn/ui
Tailwind CSS
TanStack Router
TanStack Table
Vite
Zustand
Radix UI
DevOps
Amazon S3
Ansible
Docker
Git
GitLab
GitLab CI
Grafana
gRPC
Terraform
QA
Playwright
Pytest
Apply
Senior UX/UI Designer
10 hours ago
$9.5k – $14k per year • In office • Astana
Mobile
UIKit
Design
FigJam
Figma
Apply
C# .NET разработчик (WPF)
1 day ago
≈ $14k – $39k per year (Estimated) • In office • Full-Time • 3+ years exp • Astana
C#
C++
C#
.NET
Entity Framework Core
Databases
PostgreSQL
AI/ML
ONNX
OpenCV
Mobile
MVVM
DevOps
CI/CD
Docker
Rest API
Apply
Apply
AI Engineer (LLM-агенты, RAG)
1 day ago
≈ $15k – $43k per year (Estimated) • Equity • In office • Full-Time • Astana
PHP
Python
Python
Asyncio
FastAPI
Pydantic
SQLAlchemy
Databases
ElasticSearch
pgvector
PostgreSQL
Qdrant
AI/ML
Claude
Claude Code
CrewAI
Fine-tuning
Function Calling
Google ADK
LangChain
Langfuse
LangGraph
LLM
LoRA
Model Context Protocol
RAG
Scikit-learn
vLLM
NLP
Prompt Engineering
PEFT
Anthropic
OpenAI
OpenAI Codex
DevOps
Docker
Git
QA
Pytest
Apply
This is one of many
368,634 more open roles from verified company boards, updated every day.

