远程工作雷达

网络安全经理 / 信息安全经理

Cybersecurity Manager / Information Security Manager

开发工程职能支持全球可投(据职位描述推断)
公司Day Translations, Inc.
薪资未公开
工作地点Worldwide
地域资格全球可投(据职位描述推断)
时区要求日间重叠约 9 小时,基本正常作息
用工类型Part Time
发布时间2 天前
数据来源Himalayas
前往 Himalayas 查看并投递 →
全球可投:该职位未限制候选人所在地区。仍需注意薪资可能按地区折算,以及实际签约方式(正式雇佣 / 独立合同)。

Day Translations 是一家全球性的翻译和口译公司。我们通过精准、本地化的翻译、口译和外包服务,以及为个人、组织和各类企业量身定制的多种语言解决方案,帮助改善全球沟通。
职位地点:远程工作(全球)
工作时间:待定
我们正在寻找一名网络安全经理,负责领导并亲自实施公司范围内的安全计划。我们希望找到一位技术能力强、积极主动,并能像攻击者一样思考以在问题发生前发现弱点的人。作为网络安全经理,你将全面负责保护我们的员工、系统、终端设备、客户信息和云基础设施。理想的候选人应具备丰富的 Microsoft 365 安全、终端防护、身份管理、防钓鱼和事件响应实践经验。
职责:

  • 管理和加强 Microsoft 365 和 Outlook 邮件安全,包括 Microsoft Defender for Office 365、Safe Links、Safe Attachments 以及防钓鱼和仿冒保护
  • 使用企业级 EDR/XDR 解决方案(如 Microsoft Defender for Endpoint、CrowdStrike Falcon 或 SentinelOne)实施和管理公司范围的终端防护
  • 通过 Microsoft Intune 或等效的 MDM 平台管理员工设备,强制执行安全更新、加密、屏幕锁定和应用控制
  • 配置和管理 Microsoft Defender Attack Surface Reduction (ASR) 规则,以防止恶意脚本、宏、凭证窃取和勒索软件
  • 管理 Microsoft Entra ID、条件访问和公司范围的多因素认证(MFA),包括防钓鱼认证方法如 FIDO2 和密码密钥
  • 实施并维护公司批准的密码管理器,强制执行强凭证策略,包括特权账户保护和离职时会话撤销
  • 部署和管理网络和 DNS 过滤解决方案(如 Cloudflare Gateway、Cisco Umbrella 或 Zscaler),阻止所有员工渠道中的恶意域名
  • 使用 Microsoft Purview 或等效工具实施和管理数据防泄漏(DLP)控制,防止客户、员工和公司数据未经授权的传输或泄露
  • 维护 SPF、DKIM 和 DMARC 的正确配置和执行,防止域名伪造,并推动实现完整的 DMARC 执行
  • 建立和管理持续的安全培训和意识计划
查看英文原文

Day Translations is a global translation and interpreting company. We help improve worldwide communication through accurate, localized translations, interpretation, and outsourcing services, and a wide variety of tailored language solutions for individuals, organizations, and businesses of all sizes.
Location: Remote job (worldwide)
Schedule: To be determined.
We are seeking a Cybersecurity Manager to lead and personally implement our company-wide security program. We are looking for someone highly hands-on technically, proactive, and capable of thinking like an attacker to identify weaknesses before they become incidents. As Cybersecurity Manager, you will take full ownership of protecting our employees, systems, endpoints, client information, and cloud infrastructure. The ideal candidate has deep practical experience with Microsoft 365 security, endpoint protection, identity management, phishing prevention, and incident response.
Responsibilities:

  • Manage and strengthen Microsoft 365 and Outlook email security, including Microsoft Defender for Office 365, Safe Links, Safe Attachments, and anti-phishing and impersonation protection
  • Implement and manage company-wide endpoint protection using enterprise EDR/XDR solutions such as Microsoft Defender for Endpoint, CrowdStrike Falcon, or SentinelOne
  • Manage employee devices through Microsoft Intune or an equivalent MDM platform, enforcing security updates, encryption, screen locking, and application controls
  • Configure and manage Microsoft Defender Attack Surface Reduction (ASR) rules to protect against malicious scripts, macros, credential theft, and ransomware
  • Manage Microsoft Entra ID, Conditional Access, and company-wide MFA, including phishing-resistant authentication methods such as FIDO2 and passkeys
  • Implement and maintain a company-approved password manager and enforce strong credential policies, including privileged account protection and session revocation during offboarding
  • Deploy and manage web and DNS filtering solutions (such as Cloudflare Gateway, Cisco Umbrella, or Zscaler) to block malicious domains across all employee channels
  • Implement and manage Data Loss Prevention controls using Microsoft Purview or equivalent, protecting client, employee, and company data from unauthorized transfer or exfiltration
  • Maintain proper configuration and enforcement of SPF, DKIM, and DMARC to prevent domain spoofing and progress toward full DMARC enforcement
  • Build and manage an ongoing employee security awareness program, including phishing simulations, awareness training, and a clear phishing-reporting process
  • Develop and maintain a cybersecurity incident response procedure covering phishing, compromised accounts, malware, ransomware, data theft, and lost devices
  • Implement centralized security monitoring and alerting across company systems, covering login anomalies, endpoint threats, data exfiltration, and policy violations
  • Conduct regular vulnerability scanning, prioritize findings by business risk, coordinate remediation, and manage periodic penetration testing
  • Support compliance with security standards and client requirements including ISO 27001, SOC 2, and HIPAA
  • Conduct an initial full audit of the cybersecurity environment, identify gaps, and deliver a phased security rollout plan with implementation priorities and costs

Requirements:

  • Proven hands-on experience implementing and managing Microsoft 365 security, including Microsoft Defender for Office 365, Microsoft Defender for Endpoint, Microsoft Intune, and Microsoft Entra ID
  • Practical experience with EDR/XDR platforms (CrowdStrike, SentinelOne, or equivalent)
  • Experience preventing phishing attacks and Business Email Compromise (BEC)
  • Experience with identity and access management, MFA, Conditional Access, and Zero Trust principles
  • Experience with Data Loss Prevention, DNS/web filtering, and SIEM/security monitoring
  • Experience developing and executing incident response procedures
  • Strong verbal and written communication skills in English, including the ability to communicate cybersecurity risks clearly to non-technical stakeholders and train employees
  • Ability to work independently, take full ownership of problems through resolution, and prioritize issues according to actual business risk
  • Experience with CrowdStrike, SentinelOne, Abnormal Security, Cloudflare Gateway, Cisco Umbrella, Zscaler, or similar platforms is a strong advantage
  • Relevant certifications (such as CISSP, CEH, Microsoft Security certifications, or equivalent) are a plus

Important: This position requires your full professional commitment during scheduled working hours. Job stacking and conflicting concurrent employment are not permitted. We monitor productivity and work activity, and any undisclosed conflicting employment may result in termination.
To be considered for this position, you'll need to:

  • Submit your application.
  • Complete the Emotional Intelligence and Wonderlic assessment after submitting your application.

Both steps are required to move forward in the evaluation process.
Please note: Candidates may be asked to complete a background check before hiring.
Please note that all application questions are mandatory. If any question is left incomplete or does not have a full answer, the application may be disqualified, or we may reach out to you for clarification.
Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

← 返回全部职位