Откликайтесь
на вакансии с ИИ

Cybersecurity Officer
Привлекательная роль уровня Head of Security с широкими полномочиями и возможностью влиять на стратегию всей компании. Удаленный формат и работа в растущем международном бизнесе добавляют ценности.
Сложность вакансии
Высокая сложность обусловлена необходимостью управления всеми аспектами безопасности: от стратегии и комплаенса до глубоко технических вопросов DevSecOps и реагирования на инциденты. Требуется опыт руководства крупной командой и стаж от 7 лет.
Анализ зарплаты
Зарплата в вакансии не указана, но для позиции такого уровня (Cybersecurity Officer/CISO) в международных компаниях с удаленным форматом работы рыночные показатели начинаются от $8,000 и могут достигать $15,000+ в месяц в зависимости от региона найма.
Сопроводительное письмо
I am writing to express my strong interest in the Cybersecurity Officer position at Growe. With over 7 years of experience in information security and a proven track record of leading multi-disciplinary security teams, I am confident in my ability to own and evolve your end-to-end security strategy. My background in scaling security programs within fast-paced organizations aligns perfectly with Growe's mission to drive results and embrace change.
Throughout my career, I have successfully implemented DevSecOps practices, managed complex cloud security architectures in AWS/GCP environments, and ensured compliance with ISO 27001 and GDPR standards. I take a pragmatic, hands-on approach to risk management and incident response, ensuring that security measures support rather than hinder business velocity. I am particularly drawn to Growe's collaborative culture and look forward to the opportunity to mentor your Cloud Security, SOC, and AppSec teams to achieve excellence.
Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в growe уже сейчас
Присоединяйтесь к Growe, чтобы возглавить кибербезопасность в динамичной международной среде и построить защиту мирового уровня!
Описание вакансии
Growe welcomes those who are excited to:
- Own end-to-end cybersecurity, information security, and IT security across the company, covering both internal security (breach attempts, internal network monitoring) and product security (product-related threats and risks);
- Define, evolve, and execute the company-wide cybersecurity strategy and security roadmap aligned with business and product priorities;
- Establish and enforce security policies, standards, procedures, and organization-wide security controls;
- Lead security risk management, including risk assessments, risk register ownership, and mitigation planning;
- Ensure compliance with regulatory and industry standards (e.g., GDPR, ISO 27001, SOC 2) and manage internal/external audits;
- Oversee secure architecture across cloud infrastructure, applications, SDLC, and IAM, including review of critical architectural decisions;
- Define and enforce security standards for encryption, key management;
- Own security operations, including monitoring, detection, response capabilities, and incident response for critical (P0/P1) events;
- Drive Application Security and DevSecOps practices (SAST, DAST, SCA, CI/CD security controls, threat modeling) in collaboration with engineering teams;
- Oversee IAM, endpoint, and workforce security, including access control models, EDR strategy, device security, and joiner/mover/leaver processes;
- Lead fraud prevention, vendor security, and internal/external abuse investigation processes, while managing security KPIs, reporting, budget, and team scaling;
- Manage a large cybersecurity team, including Cloud Security, SOC, Application Security / DevSecOps, Endpoint Security, IAM, and Information Security functions.
We need your professional experience:
- 7+ years of experience in cybersecurity, including experience in leadership role;
- Strong expertise in cloud security (AWS, GCP, or Azure);
- Solid understanding of application security and secure SDLC practices;
- Hands-on experience with SIEM, EDR, and incident response processes;
- Deep knowledge of identity and access management models (RBAC, ABAC, least privilege);
- Experience working with compliance frameworks such as ISO 27001, SOC 2, and GDPR;
- Proven track record of building and scaling security programs in growing organizations;
- English - upper-intermediate or higher (able to communicate in technical discussions).
We appreciate if you have those personal features:
- Strategic thinker with the ability to translate business needs into security initiatives;
- Hands-on and pragmatic approach, with readiness to dive into technical details when needed;
- Strong ownership mindset and accountability for end-to-end security outcomes;
- Ability to operate in a fast-paced, evolving environment and make data-driven decisions;
- Leadership skills with experience building, mentoring, and scaling teams;
- Strong problem-solving and critical thinking abilities;
- Effective communicator who can clearly articulate complex security topics to diverse audiences.
We are seeking those who align with our core values:
- GROWE TOGETHER: Our team is our main asset. We work together and support each other to achieve our common goals;
- DRIVE RESULT OVER PROCESS: We set ambitious, clear, measurable goals in line with our strategy and driving Growe to success;
- BE READY FOR CHANGE: We see challenges as opportunities to grow and evolve. We adapt today to win tomorrow.
Создайте идеальное резюме с помощью ИИ-агента

Навыки
- Cybersecurity
- Information Security
- Cloud Security
- AWS
- GCP
- Azure
- DevSecOps
- SAST
- DAST
- SCA
- ISO 27001
- SOC 2
- GDPR
- SIEM
- EDR
- Incident Response
- IAM
- RBAC
- ABAC
- Risk Management
Возможные вопросы на собеседовании
Проверка способности соотносить безопасность с бизнес-целями.
Как вы расставляете приоритеты в дорожной карте безопасности, когда требования бизнеса конфликтуют со строгими протоколами безопасности?
Оценка опыта в DevSecOps и автоматизации.
Опишите ваш опыт внедрения практик SAST/DAST в CI/CD пайплайны. С какими основными трудностями вы столкнулись при работе с инженерными командами?
Проверка навыков антикризисного управления.
Расскажите о самом сложном инциденте информационной безопасности (P0/P1), которым вы руководили. Каковы были ваши действия и извлеченные уроки?
Оценка лидерских качеств и масштабирования.
Как вы подходите к найму и удержанию талантов в таких разных направлениях, как SOC, AppSec и Cloud Security, в условиях дефицита кадров?
Проверка знаний в области облачной безопасности и комплаенса.
Как вы обеспечиваете соответствие требованиям GDPR и ISO 27001 в динамичной облачной инфраструктуре (AWS/GCP)?
Похожие вакансии
Trust & Safety Policy Manager
Staff Application Engineer, Workplace Technology
Senior Staff Analyst, GRC
Staff Security Engineer
Staff Software Engineer, IAM
IT / GRC External Auditor SOC 2 - LATAM
1000+ офферов получено
Устали искать работу? Мы найдём её за вас
Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!