高级IT安全顾问(网络安全评估与服务)(男/女/其他)
Senior IT Security Consultant (Cybersecurity Assessments & Services) (m/f/d)
我们正在寻找一位经验丰富的高级IT安全顾问,为一家领先的国际客户提供网络安全评估和安全咨询服务。
该顾问将负责执行安全评估、分析安全风险、支持安全架构决策,并提供改进建议以提升客户整体的安全态势。
服务交付将在奥地利远程进行。根据具体的客户项目,可能需要偶尔到现场。
地点:奥地利(远程)
合同类型:B2B承包商/自由职业者
持续时间:5个月(可延长)
工作时间:全职(40小时/周)
语言:德语(商务流利)
职责:
- 对基础设施、系统、应用和云环境进行技术IT安全评估
- 执行安全检查、漏洞评估和风险分析
- 进行威胁建模并识别潜在的安全风险
- 评估云架构在安全需求和保护要求方面的表现
- 支持IT安全架构的设计与改进
- 开发技术安全概念、指南和文档
- 支持安全事件管理活动
- 支持渗透测试活动和安全测试流程
- 执行内部和外部基础设施安全评估
- 支持系统、网络和应用的安全加固措施实施
- 支持技术审计和合规活动
- 协助信息安全管理体系(ISMS)相关工作
所需技能与经验:
- 至少3年IT安全领域专业经验(5年以上优先)
- 在网络安全评估和安全咨询方面有扎实的实践经验
- 熟悉TCP/IP和网络安全概念
- 具备以下经验:
- 防火墙
- VPN
- 互联网安全
- 身份与访问管理(IAM)
- 公钥基础设施(PKI)
- 加密技术
- 入侵检测/防御系统(IDS/IPS)
- 网站和代理安全
- 熟悉安全标准和框架,包括ISO 27001
- 具备信息安全管理体系(ISMS)经验
- 具备风险评估和威胁建模经验
- 能够编写技术安全文档和建议
加分技能
- 云安全经验(Azure、AWS、GCP)
查看英文原文
We are looking for an experienced Senior IT Security Consultant to support cybersecurity assessment and security consulting activities for a leading international client.
The consultant will be responsible for performing security assessments, analyzing security risks, supporting security architecture decisions, and providing recommendations to improve the customer’s overall security posture.
The service delivery will be performed remotely from Austria. Occasional on-site presence may be required depending on specific customer engagements.
Location: Austria (Remote)
Contract Type: B2B Contractor / Freelance Engagement
Duration: 5 months (extension possible)
Working Time: Full-time (40 hours/week)
Language: German language skills (business fluent)
Responsibilities:
- Perform technical IT security assessments for infrastructure, systems, applications, and cloud environments
- Conduct security checkups, vulnerability assessments, and risk analyses
- Perform threat modeling and identify potential security risks
- Evaluate cloud architectures regarding security requirements and protection needs
- Support the design and improvement of IT security architectures
- Develop technical security concepts, guidelines, and documentation
- Support Security Incident Management activities
- Support penetration testing activities and security testing processes
- Perform internal and external infrastructure security assessments
- Support implementation of security hardening measures for systems, networks, and applications
- Support technical audits and compliance activities
- Assist with Information Security Management System (ISMS) activities
Required Skills & Experience:
- Minimum 3 years of professional experience in IT Security (5+ years preferred)
- Strong practical experience with cybersecurity assessments and security consulting
- Good knowledge of TCP/IP and network security concepts
- Experience with:
- Firewalls
- VPN
- Internet Security
- Identity and Access Management (IAM)
- Public Key Infrastructure (PKI)
- Encryption technologies
- Intrusion Detection / Prevention Systems (IDS/IPS)
- Web and Proxy Security
- Knowledge of security standards and frameworks, including ISO 27001
- Experience with Information Security Management Systems (ISMS)
- Experience with risk assessments and threat modeling
- Ability to create technical security documentation and recommendations
Nice-to-Have Skills
- Cloud Security experience (Azure, AWS, GCP)
- Penetration Testing experience
- Vulnerability Management
- IEC 62443 knowledge
- ITIL knowledge
- Security Audit experience
- Static Code Analysis experience
Certifications (Advantage)
- CISSP
- CISM
- CEH
- ISO 27001 Lead Auditor
- ISO 27001 Lead Implementer
Originally posted on Himalayas