Ведущий инженер по архитектуре кибербезопасности

в Azercell

О роли

Əsas vəzifələr

  • Review existing security technologies, tools, and measures to identify gaps and recommend improvements; develop targeted solutions to protect company systems and data against cyberattacks, unauthorized access, and emerging security threats.
  • Lead the end-to-end lifecycle of security systems and tools — from proof-of-concept (PoC) testing and design through implementation and formal handover — ensuring solutions meet both technical and business requirements before go-live.
  • Implement and continuously tune advanced protection policies and configurations within WAF and APM solutions, aligning them with the company's security architecture and risk management strategy; proactively take measures to prevent threats, minimize attack surface, and reduce false positive/negative rates in accordance with evolving business requirements.
  • Design and advocate for Zero Trust architecture principles across network, identity, and application layers; define segmentation strategies, micro-perimeters, and least-privilege access models.
  • Define and govern security architecture for cloud environments (IaaS/PaaS/SaaS), ensuring workload protection, data residency compliance, and alignment with cloud-native security best practices.
  • Author and maintain internal security architecture standards, design principles, and baseline configurations; establish a security review gate ensuring all new systems and features meet architectural requirements before go-live.
  • Identify and mitigate AI-specific threats including prompt injection (direct/indirect), training data poisoning, model extraction, membership inference, and adversarial inputs; apply OWASP Top 10 for LLM Applications and MITRE ATLAS frameworks to assess and manage AI risk across the organization.
  • Ensure integrity of the ML pipeline through artifact signing, model registry governance, dependency and notebook hygiene, and safe handling of model weights; define and enforce a security review gate for AI features prior to launch, along with an acceptable-use standard for AI across the company.
  • ML-Based Detection Engineering — Architect detection capabilities using anomaly detection and clustering techniques for alert triage; maintain realistic operational expectations around false-positive rates, data labeling challenges, and model drift in production security environments.
  • Hands-on experience with LLM guardrail/firewall products and red teaming frameworks (Garak, PyRIT); deep understanding of the Model Context Protocol (client/server model, stdio vs. HTTP transports, trust boundaries) and OAuth-based authorization design for MCP servers — including token scoping and prevention of confused-deputy attacks.

Tələblər

  • Higher education in Information Technology, Information/Cybersecurity, Applied Mathematics, Cybernetics, Computer Science, or a related field; a Master’s degree is preferred.
  • Minimum 3 years of experience in cybersecurity or information security, including experience in system administration (Windows/Linux) or network administration.
  • Strong written and verbal communication skills in Azerbaijani and English; Russian is an advantage.
  • Hands-on experience with WAF and application security.
  • Hands-on experience in AI/ML security, including threat modeling for AI systems, securing ML pipelines, and working with LLM security tools.
  • Strong knowledge of cybersecurity best practices, security technologies, and compliance frameworks such as NIST, ISO, GDPR, and PCI-DSS.
  • Understanding of risk management principles and the ability to analyze complex security challenges and develop effective solutions.
  • Experience with cloud and virtualization technologies.
  • Strong project management, communication, teamwork, and stakeholder management skills.
  • Strong decision-making and analytical skills, with a results-oriented mindset and a proactive approach to innovation and continuous self-development.
  • Professional certifications such as CCNA, RHCSA, CySA+, SecurityX, CISSP, CISM, or equivalent are preferred.

Əsas vəzifələr

  • Review existing security technologies, tools, and measures to identify gaps and recommend improvements; develop targeted solutions to protect company systems and data against cyberattacks, unauthorized access, and emerging security threats.
  • Lead the end-to-end lifecycle of security systems and tools — from proof-of-concept (PoC) testing and design through implementation and formal handover — ensuring solutions meet both technical and business requirements before go-live.
  • Implement and continuously tune advanced protection policies and configurations within WAF and APM solutions, aligning them with the company's security architecture and risk management strategy; proactively take measures to prevent threats, minimize attack surface, and reduce false positive/negative rates in accordance with evolving business requirements.
  • Design and advocate for Zero Trust architecture principles across network, identity, and application layers; define segmentation strategies, micro-perimeters, and least-privilege access models.
  • Define and govern security architecture for cloud environments (IaaS/PaaS/SaaS), ensuring workload protection, data residency compliance, and alignment with cloud-native security best practices.
  • Author and maintain internal security architecture standards, design principles, and baseline configurations; establish a security review gate ensuring all new systems and features meet architectural requirements before go-live.
  • Identify and mitigate AI-specific threats including prompt injection (direct/indirect), training data poisoning, model extraction, membership inference, and adversarial inputs; apply OWASP Top 10 for LLM Applications and MITRE ATLAS frameworks to assess and manage AI risk across the organization.
  • Ensure integrity of the ML pipeline through artifact signing, model registry governance, dependency and notebook hygiene, and safe handling of model weights; define and enforce a security review gate for AI features prior to launch, along with an acceptable-use standard for AI across the company.
  • ML-Based Detection Engineering — Architect detection capabilities using anomaly detection and clustering techniques for alert triage; maintain realistic operational expectations around false-positive rates, data labeling challenges, and model drift in production security environments.
  • Hands-on experience with LLM guardrail/firewall products and red teaming frameworks (Garak, PyRIT); deep understanding of the Model Context Protocol (client/server model, stdio vs. HTTP transports, trust boundaries) and OAuth-based authorization design for MCP servers — including token scoping and prevention of confused-deputy attacks.

Tələblər

  • Higher education in Information Technology, Information/Cybersecurity, Applied Mathematics, Cybernetics, Computer Science, or a related field; a Master’s degree is preferred.
  • Minimum 3 years of experience in cybersecurity or information security, including experience in system administration (Windows/Linux) or network administration.
  • Strong written and verbal communication skills in Azerbaijani and English; Russian is an advantage.
  • Hands-on experience with WAF and application security.
  • Hands-on experience in AI/ML security, including threat modeling for AI systems, securing ML pipelines, and working with LLM security tools.
  • Strong knowledge of cybersecurity best practices, security technologies, and compliance frameworks such as NIST, ISO, GDPR, and PCI-DSS.
  • Understanding of risk management principles and the ability to analyze complex security challenges and develop effective solutions.
  • Experience with cloud and virtualization technologies.
  • Strong project management, communication, teamwork, and stakeholder management skills.
  • Strong decision-making and analytical skills, with a results-oriented mindset and a proactive approach to innovation and continuous self-development.
  • Professional certifications such as CCNA, RHCSA, CySA+, SecurityX, CISSP, CISM, or equivalent are preferred.

Подходишь ли ты на эту вакансию?

Загрузи CV — за 10 секунд увидишь процент совпадения, свою цену на рынке и чего не хватает в резюме.

Проверить CV
Локация
Баку, Tbilisi prospekti 149, Yasamal,
Опыт
3+ лет
Занятость
Полная занятость
Зарплата
Не указана
Опубликовано
15 сентября 2026
Языки
Azerbaijani, English, Russian
Дедлайн
15 октября 2026
Просмотры
23

О компании

Azercell
Telecom · Baku
Все вакансии Azercell

Ваш отклик

Этот работодатель принимает отклики у себя на сайте. Перейдите на страницу вакансии и заполните форму там.

Перейти на страницу работодателя

Похожие вакансии

Все похожие вакансии

Другие открытые объявления по роли «Архитектор безопасности» в городе Баку.

PASHA Sığorta
Senior · 1–2 летБаку
З/п не указана

Ведущий специалист по прикладной безопасности программ обеспечивает безопасность программ и проводит тесты на проникновение.

Penetration TestingDockerKubernetesCI/CD+11
Откликнуться
Все похожие вакансии
Не указана
Ведущий инженер по архитектуре кибербезопасности
Откликнуться