Information Security Engineer

Müraciət et
Müraciət et
CV yüklə (doc, docx, pdf)

İşin təsviri

  • The Information Security Engineer is responsible for ensuring the effective governance of information systems, compliance with international and national information security standards, risk management, and internal audit activities within the company. The role includes monitoring information security processes, implementing controls, raising awareness, and supporting the management of information systems in alignment with the company’s strategic objectives.

Key Responsibilities

  • Align information security objectives with the company’s strategic plans and business goals to ensure secure operations.
  • Monitor compliance with IT standards and ensure the governance of Information Systems Management Directorate units.
  • Oversee Information Security Management System (ISMS) activities in accordance with international standards (ISO 27001, COBIT) and national regulations (Defense Industry Security Directive, etc.).
  • Identify and assess risks to company assets, determine risk values, and manage information system risks.
  • Plan and implement measures to reduce, eliminate, or transfer identified risks and threats to ensure information security.
  • Plan and conduct internal audits related to information systems security, prepare audit reports, and coordinate with relevant units to address nonconformities.
  • Collaborate with the Legal department to define and review technical information security clauses in Non-Disclosure Agreements (NDAs) and third-party contracts.
  • Establish a recording system for information security incidents, create an incident management platform, and ensure its operation and functionality.
  • Organize and deliver internal training to raise information security awareness among employees.
  • Audit and monitor IT systems for proper patch management, administrator access, and security log compliance in alignment with ITIL/security standards.
  • Conduct regular vulnerability assessments using tools, analyze scan results, and coordinate with IT teams to ensure timely remediation and patching of critical flaws.
  • Oversee privileged access management (PAM) controls and regularly review high-risk administrator log records to detect unauthorized activities.
  • Manage and continuously optimize data loss prevention (DLP) policies and data classification frameworks to protect the company’s sensitive intellectual property and financial assets.

Requirements

  • Bachelor’s or Master’s degree in Information Technology, Cybersecurity, Computer Engineering, or a related field
  • Minimum 3–5 years experience in information security, IT governance, or ISMS implementation
  • Industry-standard certifications such as CISA, CISM, CISSP, ISO 27001 Lead Auditor/Implementer, or ITIL Foundation are highly desirable.
  • Experience with risk management, internal audits, and compliance reporting
  • Practical experience in system monitoring, incident management, and NDA handling
  • Strong analytical, problem-solving, and coordination skills
  • Ability to develop and deliver internal information security training
  • Familiarity with system and database administration monitoring tools and log management
  • English – UpperIntermediate level, Russian – preferred, Turkish – an advantage

Interested candidates are requested to submit their CVs to career@azroksan.azn with “Information Security Engineer” indicated in the subject line.

Note: Only shortlisted candidates will be contacted