Information Security Manager (BirEcoSystem – Birmarket)

İşin təsviri

Birmarket is the largest marketplace in Azerbaijan and part of BirEcoSystem. We are rapidly scaling our operations, strengthening our digital infrastructure, and building a mature information security system.

We are currently looking for an Information Security Manager who will locally implement and strengthen the Ecosystem’s security model.

Key Responsibilities:

  • Adapt and implement BirEcoSystem’s information security principles at the local level;
  • Build and enhance the information risk management framework within Birmarket;
  • Identify, assess, and clearly communicate information security risks to business and leadership;
  • Ensure enforcement of security standards, IAM principles, and compliance with local regulatory requirements;
  • Oversee vulnerability management, incident response, and threat monitoring processes;
  • Supervise cloud security environments (including Azure and others);
  • Conduct security risk assessments and oversee compliance requirements for local vendors and third-party partners;
  • Promote security awareness among employees;
  • Collaborate closely with the BirEcoSystem cybersecurity team and local management.

What You Will Focus on in the First Months:

  • Conduct a full assessment of the current security posture and risk landscape;
  • Strengthen and formalize risk management processes;
  • Initiate the implementation of frameworks such as NIST CSF and ISO 27001 into operational processes;
  • Establish transparent risk communication practices with business stakeholders;
  • Identify critical risk areas and prioritize control measures;
  • Develop and launch a security improvement roadmap aligned with the Ecosystem model.

Current Challenges:

  • Resistance from business units when implementing security controls;
  • The need to actively advocate for and enforce security requirements;
  • Balancing business agility with security standards;
  • Varying levels of process maturity across functions.

Team & Collaboration:

You will work directly with Birmarket’s local management and closely collaborate with the BirEcoSystem cybersecurity team.

Key stakeholders include:

  • IT Infrastructure
  • Development teams
  • Cloud engineers
  • Compliance / Legal
  • External vendors

This role requires a high level of autonomy and strategic influence.

You’re a Strong Fit If You Have:

  • 5+ years of experience in Information Security, including leadership roles;
  • Deep understanding of international security frameworks (NIST CSF, ISO 27001, etc.);
  • Strong expertise in information risk management;
  • Clear understanding of modern security architecture and control environments;
  • Ability to identify, structure, and assess security risks;
  • Proven experience communicating complex technical risks to non-technical business stakeholders;
  • Fluency in English, Russian, and Azerbaijani (written and spoken).

Nice to Have:

  • Hands-on experience with Azure security tools (Defender, Intune, security policies);
  • Understanding of SOC operations and log correlation principles;
  • Experience with Linux/Unix systems;
  • Knowledge of identity management systems;
  • Understanding of MDM (Apple, Android devices management);
  • Experience with Exchange, mail gateways, and anti-spam systems;
  • Development background or engineering experience;
  • Professional certifications such as CISSP, CISM, or equivalent.

Recruitment Process:

  • HR screening call.
  • Technical interview
  • Final meeting with top management.
  • Offer.

Interested candidates can apply by clicking the link provided in the “Apply” button.