Astanahub Logo
Vacancies

Information Security Consultant

Archive
Astana Full-time Full-time

The vacancy has been archived and is no longer active

Main requirements

  • Higher technical education (IT, cybersecurity, information systems or related);
  • Work experience of at least 2 years in the field of IT audit, information security consulting or IT systems administration;
  • It will be a plus: knowledge and practical application of ISO 22301, ISO 9001, ISO 27001 LA/LI, CISA, CEH, Security+ certificates or analogues;
  • Knowledge of Kazakh and English languages will be an advantage.

Technical knowledge:

  • Network technologies: understanding TCP/IP, network architecture, principles of firewall, VPN, VLAN, routing – a level sufficient for analyzing network schemes during the survey;
  • Operating systems: basic Windows administration (Active Directory, Group Policy, Event Viewer) and Linux (syslog reading, journal, rights management);
  • Reading and analyzing system logs and event logs – the ability to identify anomalies and signs of incidents;
  • Practical experience working with vulnerability scanning tools (Nessus, OpenVAS or analogues);
  • Confident knowledge of ISO/IEC 27001, ISO/IEC 27002 at the level of practical application;
  • Knowledge of the National Legislation of the Republic of Kazakhstan in the field of IT and information security: The Law "On Informatization", requirements of the NBK No. 48, ET-832;
  • Understanding the risk-based and process-based approach;
  • MS Office at the expert level (Word, Excel with formulas/macros, PowerPoint); plus – Power BI.

Professional skills:

  • The ability to independently conduct an IT/information security survey of an organization and issue a report;
  • Development of normative documents on the content (not just according to the template, but understanding the essence);
  • Good written language: a clear, structured presentation of technical requirements for a non-technical audience;
  • Systematic thinking, attention to detail, and the ability to work on multiple projects at the same time.

What you will do

  • Conducting a comprehensive survey of the IT infrastructure and the state of information security among clients: interviews, configuration analysis, network architecture study, analysis of system logs and events;
  • GAP analysis: assessment of compliance of the current state with the requirements of the standards and the NPA of the Republic of Kazakhstan, the formation of recommendations;
  • Development of internal regulatory documents (policies, regulations, instructions, procedures) based on ISO 27001, NBRK No. 48, ET-832;
  • Information security risk assessment and management: threat identification, vulnerability analysis, development of risk management plans;
  • Instrumental vulnerability and source code scanning, results analysis;
  • Participation in the construction of ISMS, preparation for ISO 27001 certification and IS testing;
  • Formation of registers of information assets;
  • Preparation of reports, presentations and project documentation for clients;
  • Post-project support: advising clients on embedded documents and processes.

What we offer

  • Official employment in the Republic of Kazakhstan;
  • Development and career growth;
  • Decent salary level, salary + bonuses for closing projects;
  • Business trips are possible;
  • Team building, table tennis and chess tournaments;
  • Opening hours: 5/2, from 9:00 a.m. to 6:00 p.m. or from 9:30 a.m. to 6:30 p.m.
search
All statuses
New
Viewed
Under review
Invitation
Confirm
Rejected
Name Work Experience Contacts Response date Notes Response status
reach

There are no responses yet

When someone responds to a vacancy, a list of candidates will appear here

99 Views
BugBounty WhatsApp Telegram
We use cookies to ensure the proper functioning of our website and for analytics. By continuing to use the website, you confirm your acceptance of the use of cookies. More
Share