Senior ICT Security Engineer
We are looking for an ICT Security Engineer to develop the company's SOC and infrastructure security.
We do high-frequency trading (HFT): we trade on markets worldwide with our own technology. Our geo-distributed infrastructure is cloud and bare-metal at once, and it has to work under 10x load and with microsecond latencies. So the security requirements here are specific: any control that adds latency or extra noise costs the business money. It is not enough to grow coverage and add new rules: you have to keep balancing detection completeness against the impact on the infrastructure.
What you will do
We are looking for an ICT Security Engineer who will take monitoring and the SOC to a new level, making coverage useful, noise controlled and investigations fast and reproducible. You will work where security meets engineering: figuring out where events come from, how they pass through the pipeline, where context is lost and how that affects detection quality.
Example tasks
- Reducing false positives and improving detection quality
- Introducing security controls into DevSecOps processes and CI/CD
- Developing the SIEM, from onboarding sources to writing parsers and correlation rules
- Monitoring and security of Kubernetes, cloud and bare-metal infrastructure
- Setting up alerting and scenarios for detecting suspicious activity
- Responding to infrastructure incidents, from the alert to a confirmed conclusion
What matters for this role
- Have secured Kubernetes and containerised environments
- Understand IaC principles and have worked with Terraform or Pulumi
- Administer Linux confidently
- Have automated routine work in Go, Python or Bash
- Have 5+ years of experience as a Security Engineer / SOC Engineer / Infrastructure Security Engineer
- Have built and developed a SIEM/SOC: you can audit monitoring coverage and draw up a plan to extend it
- Have written and tuned correlation rules, reducing the share of false positives without losing real incidents
- Have worked with Wazuh and/or ELK
Nice to have
- Have worked with eBPF tools (Auditd, Falco and similar)
- Have used SOAR platforms
- Have built vulnerability management processes
- Have worked in HFT or other high-load infrastructure
- Have built SOC processes from scratch
- Have worked with MITRE ATT&CK and IOC, from detection to investigation
- Have set up IAM/PAM, RBAC and monitoring of privileged access
- And more, so that you can perform at your maximum: ー monitoring and help with keeping key health indicators ー health insurance with dental care ー company events in different parts of the world ー monthly events: sports and wellness activities from the company ー food in the office from the best restaurants
- Rare experience of developing a SOC and infrastructure security in an environment that pays particular attention to reliability, response speed and the protection of critical systems
- Income in line with your personal contribution (a fixed salary + a half-yearly performance bonus)
- An environment for deep work: no meetings for the sake of meetings, short feedback loops, performance coaching for personal productivity
- A strong team: engineers from tier-1 companies and experienced industry specialists, winners and prize winners of olympiads in mathematics, programming and physics at the level of IMO, IOI, the All-Russian Olympiad and the ICPC semifinal