🛡 Vacancy: System Engineer (preparing requirements for SIEM integrations)
Project: Outstaff / Infrastructure Security
Duration: 1 year
Location: Russian Federation (Moscow, regions of the Russian Federation) — remote
Citizenship: Russian Federation, CIS
Salary: from 200 thousand rubles
Responsibilities:
- Prepare requirements for SIEM integrations
- Transform business requirements into technical tasks
- Configure event collection from non-standard sources (self-study, writing normalizers, correlation rules)
- Work with Linux/Windows Server, AD, network equipment, and information security tools
- Write scripts for automation (Python, Bash, PowerShell)
Key Requirements (mandatory):
- Experience with SIEM — integrating systems not "out-of-the-box": studying the source → writing a normalizer → correlation rules
- Understanding of event collection mechanisms: SQL, REST API, Syslog, WEF, SNMP, OPSEC, JSON, SCP (SSH), FTP
- Linux Server / Windows Server / AD (deployment, administration, architecture)
- DBMS (SQL)
- Network equipment (switches, routers, firewalls), knowledge of network and cryptographic protocols
- Infrastructure services: DNS, DHCP, NTP, SMTP, hypervisors, monitoring, backup, CMDB
- Information security tools (DLP, IPS, AV, FW, Proxy, AF, IRP, TI)
- Scripting skills (Python / Bash / PowerShell) — key
- Git
- Text data processing: regexp, SQL, Excel (grouping, filtering, data extraction)
Will be a plus:
- Understanding of MITRE ATT&CK, cyber attack lifecycle, incident response
- Experience with JSON, Windows, AD, SIEM (even deeper)
Work format:
- Fully remote
- 1-year project
- Citizenship of the Russian Federation or CIS
How to apply:
Write to Telegram FreeHRarka