İşin təsviri
Birmarket is the largest marketplace in Azerbaijan and part of BirEcoSystem. We are rapidly scaling our operations, strengthening our digital infrastructure, and building a mature information security system.
We are currently looking for an Information Security Manager who will locally implement and strengthen the Ecosystem’s security model.
Key Responsibilities:
- Adapt and implement BirEcoSystem’s information security principles at the local level;
- Build and enhance the information risk management framework within Birmarket;
- Identify, assess, and clearly communicate information security risks to business and leadership;
- Ensure enforcement of security standards, IAM principles, and compliance with local regulatory requirements;
- Oversee vulnerability management, incident response, and threat monitoring processes;
- Supervise cloud security environments (including Azure and others);
- Conduct security risk assessments and oversee compliance requirements for local vendors and third-party partners;
- Promote security awareness among employees;
- Collaborate closely with the BirEcoSystem cybersecurity team and local management.
What You Will Focus on in the First Months:
- Conduct a full assessment of the current security posture and risk landscape;
- Strengthen and formalize risk management processes;
- Initiate the implementation of frameworks such as NIST CSF and ISO 27001 into operational processes;
- Establish transparent risk communication practices with business stakeholders;
- Identify critical risk areas and prioritize control measures;
- Develop and launch a security improvement roadmap aligned with the Ecosystem model.
Current Challenges:
- Resistance from business units when implementing security controls;
- The need to actively advocate for and enforce security requirements;
- Balancing business agility with security standards;
- Varying levels of process maturity across functions.
Team & Collaboration:
You will work directly with Birmarket’s local management and closely collaborate with the BirEcoSystem cybersecurity team.
Key stakeholders include:
- IT Infrastructure
- Development teams
- Cloud engineers
- Compliance / Legal
- External vendors
This role requires a high level of autonomy and strategic influence.
You’re a Strong Fit If You Have:
- 5+ years of experience in Information Security, including leadership roles;
- Deep understanding of international security frameworks (NIST CSF, ISO 27001, etc.);
- Strong expertise in information risk management;
- Clear understanding of modern security architecture and control environments;
- Ability to identify, structure, and assess security risks;
- Proven experience communicating complex technical risks to non-technical business stakeholders;
- Fluency in English, Russian, and Azerbaijani (written and spoken).
Nice to Have:
- Hands-on experience with Azure security tools (Defender, Intune, security policies);
- Understanding of SOC operations and log correlation principles;
- Experience with Linux/Unix systems;
- Knowledge of identity management systems;
- Understanding of MDM (Apple, Android devices management);
- Experience with Exchange, mail gateways, and anti-spam systems;
- Development background or engineering experience;
- Professional certifications such as CISSP, CISM, or equivalent.
Recruitment Process:
- HR screening call.
- Technical interview
- Final meeting with top management.
- Offer.
Interested candidates can apply by clicking the link provided in the “Apply” button.