SOC Analyst: рынок
SOC Analyst (Security Operations Center) — operational security role, focus на real-time monitoring, alert triage, incident detection & response. Front-line defense — watches SIEM / EDR / NDR alerts 24×7, investigates suspicious activity, escalates real incidents. Самый доступный entry-point в кибербезопасность (vs Security Engineer / Pentester — требуют больше опыта). Семейство ролей: SOC Analyst L1 (Tier 1) (alert triage — first responder, validates / dismisses / escalates alerts, часто shift work 24×7), SOC Analyst L2 (Tier 2) (deep investigation — analyzes escalated incidents, correlation, scoping), SOC Analyst L3 (Tier 3) (threat hunting + advanced incident response + detection engineering — overlap с Security Engineer), SOC Lead / SOC Manager (team leadership + shift management + metrics), Threat Hunter (proactive — hunt for threats SIEM missed), Detection Engineer (rising 2024+ — writes / tunes detection rules — SOC's engineering arm), Incident Responder (IR) (deep incident handling + forensics — often separate CSIRT team). EDR / XDR (endpoint visibility): CrowdStrike Falcon (leader), SentinelOne, Microsoft Defender for Endpoint, Palo Alto Cortex XDR. Russian: Kaspersky KEDR, MaxPatrol EDR. SOAR (automation — reduces SOC analyst toil): Palo Alto Cortex XSOAR, Splunk SOAR, Tines, Torq, Microsoft Sentinel Playbooks. NDR (Network Detection & Response): Darktrace + Vectra + PT NAD. Threat Intelligence: Recorded Future + Mandiant + MISP (open-source) + VirusTotal + AlienVault OTX. Ticketing / case management: TheHive (open-source SOC case management — popular), Jira Service Management, ServiceNow Security Operations. Frameworks & methodologies: MITRE ATT&CK (adversary TTPs taxonomy — must для modern SOC — alert mapping + coverage analysis), Cyber Kill Chain (Lockheed Martin — attack phases model), Diamond Model (intrusion analysis), Pyramid of Pain (IoC value hierarchy). Analysis tools: Wireshark (packet analysis), VirusTotal (file / URL / hash reputation), any.run + Joe Sandbox + Cuckoo (malware sandboxes), CyberChef (data decoding Swiss Army knife), Volatility (memory forensics — L3), OSINT tools (Shodan + urlscan.io + AbuseIPDB). Detection engineering (L3 / Detection Engineer): Sigma (vendor-agnostic detection rule format — standard 2026), YARA (malware pattern matching), Splunk SPL / Sentinel KQL rule authoring, Atomic Red Team + Caldera (adversary emulation для detection validation). Certifications: CompTIA Security+ → CompTIA CySA+ (Cybersecurity Analyst — SOC-focused), Blue Team Level 1 (BTL1) (Security Blue Team — practical SOC cert — rising 2024+), GIAC GSEC / GCIH / GCFA, Splunk Core Certified, Microsoft SC-200 (Security Operations Analyst). Languages: Python primary (alert enrichment + SOAR playbooks + automation), bash + PowerShell, KQL / SPL query languages. По данным Zorky CRM, открыто 8 активных вакансий с явной SOC-спецификой (реальный pool шире — many SOC roles classified как general Security Analyst / Security Engineer), медиана не публикуется. Топ-стек: cloud, aws, azure, gcp, python. 62% — удалёнка.
На рынке SOC Analyst сейчас 8 открытых вакансий, из них 1 со свежим наблюдением. Медианная зарплата не публикуется. Наблюдаемый пул специалистов — не публикуется.
62% SOC-вакансий — удалёнка или гибрид. SOC work cloud-based (SIEM / EDR / SOAR consoles remote-accessible). L1 shift work часто remote-able (follow-the-sun MSSP model). Российские банки SOC + госкомпании / ГосСОПКА — гибрид/офис за счёт regulatory + clearances. Russian MSSP — гибрид или remote после background-check. Международные MSSP — full-remote standard (MSSP business model — serve clients globally).
⚠ зарплата известна у 1 из 8 вакансий; доля удалёнки — от 8 с указанным форматом; свежими наблюдениями считаются 1; тренд и сложность найма не показываются
Спрос и наблюдаемый пул
| Открытый спрос | 8 |
| Наблюдаемый пул | — не публикуется |
⚠ подходящих под вакансию кандидатов пока не считаем: показаны спрос и наблюдаемый пул
География спроса
| страна | вакансий |
|---|---|
| IN | 3 |
| GB | 3 |
Лидер по числу SOC-вакансий — Россия (0 позиций). Россия — Russian MSSP + банки internal SOC (Сбер Cyber Defense Center) + ГосСОПКА центры доминируют. Польша — SOC-friendly EU-хаб. Германия — Berlin + Munich enterprise. Международный remote через MSSP (Arctic Wolf / eSentire / Expel / Red Canary / Secureworks / Rapid7 MDR / Sophos MDR — business model inherently remote).
⚠ только число вакансий: зарплата по странам не публикуется
С чем используется вместе
Топ-стек SOC 2026: SIEM, EDR/XDR, SOAR (Cortex XSOAR + Splunk SOAR + Tines + Torq + Sentinel Playbooks), NDR (Darktrace + Vectra + PT NAD), Threat Intelligence, ticketing/case management (TheHive open-source + Jira Service Management + ServiceNow Security Operations), frameworks (MITRE ATT&CK must + Cyber Kill Chain + Diamond Model + Pyramid of Pain), analysis tools (Wireshark + VirusTotal + any.run / Joe Sandbox / Cuckoo sandboxes + CyberChef + Volatility memory forensics + Shodan / urlscan.io / AbuseIPDB / GreyNoise OSINT), detection engineering (Sigma vendor-agnostic standard + YARA + SPL/KQL rule authoring + Atomic Red Team / Caldera adversary emulation), Python primary + bash + PowerShell + KQL/SPL query languages.
Спрос по уровням
| уровень | вакансий |
|---|---|
| senior | 2 |
| middle | 1 |
SOC — лучший entry-point в кибербезопасность (L1 принимает junior без commercial experience — с certs + home lab). Career-flow: Entry (certs + home lab) → SOC L1 (1-2 года) → L2 (2-3 года) → L3 / Detection Engineer / Threat Hunter → либо SOC Lead / Manager, либо Security Engineer pivot (broader — higher ceiling), либо Incident Responder, либо Threat Intelligence Analyst, либо Pentester (offensive pivot). SOC L1 — не тупик, а проверенный launchpad: многие Senior Security Engineers / Pentesters начинали в SOC.
⚠ только сторона спроса: грейд наблюдаемого пула неизвестен у большинства
Откуда Zorky видит этот рынок
Наблюдение идёт из 3 источников; на крупнейший приходится 50.0% — рынок не держится на одном канале.
Свежие вакансии
- Associate SOC Analyst
- Mid SOC Analyst · IN
- Cyber Security Engineer / SOC Analyst · GB
- Senior SOC Analyst · GB · $8 668
- SOC Analyst
- Senior SOC Analyst · IN
- Cyber Security Engineer / SOC Analyst · GB
- SOC Analyst · IN
Свежие открытые SOC Analyst-вакансии — последние позиции в выборке (узкий pool явных SOC roles — реальный рынок значительно шире, SOC — один из самых ёмких security-сегментов by headcount). Полный список — в нашем CRM или по ссылке «смотреть все» ниже. Для broader view посмотрите security-engineer страницу.
Соседние рынки
SOC Analyst пересекается с Security Engineer (SOC L3 → engineering pivot — broader), Threat Hunter (SOC L3 sub-specialty), Incident Responder / IR (escalation target — часто separate CSIRT), Detection Engineer (SOC's engineering arm — rising 2024+), Threat Intelligence Analyst, Pentester (offensive pivot — understanding defense helps). Сравнение с security-engineer/appsec/cloud-security/iam/pentest/network-security — в SiblingSubnichesChart выше.
⚠ соседние рынки для сравнения ещё не определены
Как это посчитано
- Вакансия
- открытая вакансия, прошедшая гейт качества и содержащая не менее двух технологий
- Наблюдаемый кандидат
- кандидат, чей стек содержит эту технологию; агрегат, без единой записи наружу
- Подходящий кандидат
- пока не считается
- Окно
- открытые вакансии на момент сборки снимка
О данных
- Некоторые разрезы скрыты: по ним пока недостаточно полноты данных.
- Статистика строится только там, где выборка проходит порог качества.
- Отсутствие блока не означает нулевое значение.
Сейчас скрыто разрезов: 10.
Данные на 2026-09-27
Направление: Security
Соседние специализации
Частые вопросы
Ответы пересчитываются автоматически.
Какой стек чаще всего требуют от SOC Analyst?
Топ-5: cloud, aws, azure, gcp, python. SIEM query languages: SPL (Splunk) или KQL (Kusto — Sentinel) — must для investigation + detection. EDR / XDR: CrowdStrike Falcon (leader) / SentinelOne / Microsoft Defender for Endpoint / Palo Alto Cortex XDR. Russian: Kaspersky KEDR / MaxPatrol EDR. SOAR (automation — reduces toil): Palo Alto Cortex XSOAR / Splunk SOAR / Tines / Torq / Microsoft Sentinel Playbooks. NDR: Darktrace / Vectra / PT NAD. Threat Intelligence: Recorded Future / Mandiant / MISP (open-source) / VirusTotal / AlienVault OTX. Ticketing / case management: TheHive (open-source SOC case management — popular) / Jira Service Management / ServiceNow Security Operations. Frameworks & methodologies — must: MITRE ATT&CK (adversary TTPs taxonomy — modern SOC maps все alerts к ATT&CK techniques + coverage gap analysis), Cyber Kill Chain (Lockheed Martin — attack phases), Diamond Model (intrusion analysis), Pyramid of Pain (IoC value hierarchy). Analysis tools: Wireshark (packet analysis) / VirusTotal (file / URL / hash reputation) / any.run + Joe Sandbox + Cuckoo (malware sandboxes — detonate suspicious files) / CyberChef (data decoding Swiss Army knife — base64 / hex / encryption) / Volatility (memory forensics — L3) / OSINT tools (Shodan + urlscan.io + AbuseIPDB + GreyNoise). Detection engineering (L3 / Detection Engineer): Sigma (vendor-agnostic detection rule format — standard 2026 — write once, convert к Splunk / Sentinel / Elastic), YARA (malware pattern matching), Splunk SPL / Sentinel KQL rule authoring, Atomic Red Team + Caldera (adversary emulation для detection rule validation). Languages: Python primary (alert enrichment + SOAR playbooks + automation) + bash + PowerShell + KQL / SPL query languages.
SOC Analyst vs Security Engineer vs Threat Hunter vs Incident Responder — в чём разница?
SOC Analyst (эта страница) — operational role, real-time monitoring + alert triage + incident detection. Front-line defense. L1 / L2 / L3 tier structure. Часто shift work 24×7. Самый доступный entry. Security Engineer (general) — engineering role, builds + maintains security infrastructure (SIEM / EDR / IAM / network security configuration). Strategy + automation focus, не real-time monitoring. См. Security Engineer (general). Threat Hunter — proactive specialty: hunt for threats что SIEM signature-based detection пропустила (hypothesis-driven hunting using ATT&CK + behavioral analysis). Часто SOC L3 sub-specialty. Incident Responder (IR) — reactive deep specialty: handles confirmed major incidents (containment + eradication + recovery + forensics + post-mortem). Часто separate CSIRT team или external IR consultancy. Detection Engineer (rising 2024+) — SOC's engineering arm: writes + tunes detection rules (Sigma / SPL / KQL), reduces false-positive rates, builds detection coverage против ATT&CK. Bridge SOC ↔ Security Engineering. Reality 2026 (relationship): SOC L1 (triage) → L2 (investigation) → L3 (advanced — часто = Threat Hunter / Detection Engineer hybrid). Security Engineer builds the tools SOC uses. IR takes over когда SOC confirms major incident. Career-flow из SOC: SOC L3 → либо Security Engineer (broader engineering — higher ceiling), либо Threat Hunter (proactive deep), либо Incident Responder (reactive deep), либо Detection Engineer (engineering-leaning), либо SOC Manager (people management), либо Pentester (offensive pivot — understanding defense helps), либо Threat Intelligence Analyst. SOC — best launchpad: даёт broad exposure ко всем security domains, потом specialize.
Как устроена SOC tier structure — L1 / L2 / L3 responsibilities?
Classic SOC tier model 2026 (некоторые modern SOC переходят к «tierless» model, но tier structure остаётся dominant): L1 (Tier 1) — Alert Triage Analyst: Responsibilities: monitor SIEM / EDR / NDR alert queue 24×7, perform initial triage (validate alert — true positive / false positive / benign), follow established playbooks, enrich alerts (look up IPs / hashes / domains в threat intel), escalate confirmed / suspicious incidents к L2, dismiss false positives. Skills: SIEM basics, alert interpretation, playbook execution, attention to detail under repetitive load. Typical: shift work (часто 12-hour shifts 24×7 rotation), entry-level (1-2 года experience или fresh с certs). Burnout risk высокий (repetitive + night shifts) — typical L1 tenure 1-2 года перед promotion. L2 (Tier 2) — Incident Responder / Investigator: Responsibilities: deep investigation escalated incidents, correlation across data sources (SIEM + EDR + network + cloud logs), scope incident (что affected, timeline reconstruction), determine attack technique (MITRE ATT&CK mapping), recommend containment actions, handle malware analysis (basic — sandbox detonation), document incident thoroughly. Skills: investigation methodology, log analysis depth, malware analysis basics, ATT&CK fluency, SIEM query mastery (SPL / KQL). L3 (Tier 3) — Senior Analyst / Threat Hunter / Detection Engineer: Responsibilities: handle most complex / sophisticated incidents (APT-level), threat hunting (proactive — hypothesis-driven search for threats SIEM missed), detection engineering (write + tune detection rules — Sigma / SPL / KQL — reduce false-positive rates + improve coverage), advanced malware analysis + reverse engineering basics, forensics (memory — Volatility, disk), mentor L1 / L2, develop playbooks, adversary emulation (Atomic Red Team / Caldera для validate detections). Skills: deep technical expertise, threat hunting methodology, detection engineering, programming (Python для automation), forensics. SOC Lead / SOC Manager: team leadership, shift scheduling, SOC metrics ownership (MTTD — Mean Time to Detect, MTTR — Mean Time to Respond, alert volume, false-positive rate, escalation accuracy), SLA management, hiring, customer communication (для MSSP). Cross-cutting: SOC metrics — MTTD / MTTR / dwell time / alert-to-incident ratio / analyst-touch-rate. Modern trends 2026: SOAR automation reduces L1 toil (automate 50%+ repetitive triage), «tierless SOC» model (некоторые orgs flatten hierarchy — all analysts investigate, specialization vs tier), AI-assisted triage (LLM-based alert summarization + enrichment — rising 2024+). Shift reality: 24×7 coverage требует follow-the-sun model (multiple geo locations) или night shift rotations (burnout management critical).
Можно ли работать SOC Analyst удалённо?
Да, 62% SOC Analyst-вакансий — full-remote или гибрид. SOC work primarily cloud-based (SIEM / EDR / SOAR consoles + dashboards — all accessible remotely). L1 shift work — many SOC поддерживают remote 24×7 coverage (analysts work shifts from home — особенно follow-the-sun MSSP model где разные geo locations покрывают разные часовые пояса). Аутсорсеры — обычно remote. Российские банки SOC — гибрид/офис за счёт regulatory + security clearances (особенно для госкомпаний + ГосСОПКА-связанных центров — on-site mandatory). Russian MSSP — гибрид или remote после security background-check. Госкомпании / ГосСОПКА — гибрид/офис обязательный (air-gapped environments + clearances). Международные MSSP (Arctic Wolf / eSentire / Expel / Red Canary / Secureworks / Rapid7 MDR / Sophos MDR) — full-remote standard (MSSP business model inherently remote-friendly — serve clients globally). Big Tech SOC — гибрид-standard. Caveat для shift work: night shifts требуют reliable home setup + quiet space. Time zone — SOC roles часто требуют overlap с team coverage windows. Релокант-хабы: Польша / Германия / Сербия / Грузия. Английский для international SOC-remote — must (особенно MSSP — serve English-speaking clients + vendor docs Splunk / CrowdStrike / Sentinel).
Чем Detection Engineer (rising 2024+) отличается от SOC Analyst?
SOC Analyst (L1 / L2) — consumes detection rules: responds к alerts that detection rules generate. Reactive. Detection Engineer (rising specialty 2024+ — часто evolved from SOC L3) — creates + maintains detection rules: SOC's engineering arm. Day-to-day: 1) Write detection rules (Sigma — vendor-agnostic format — write once, convert к Splunk SPL / Sentinel KQL / Elastic; native SPL / KQL для platform-specific). 2) Tune false-positive rates (badly-tuned rules → alert fatigue → real threats missed — Detection Engineer's core mandate: high signal-to-noise). 3) Detection coverage analysis (map detections к MITRE ATT&CK matrix → identify coverage gaps → prioritize new detections). 4) Detection-as-code (treat detection rules как code — version control в Git + CI/CD pipeline + testing + peer review — modern practice). 5) Adversary emulation (Atomic Red Team + Caldera + MITRE Caldera — simulate attacks → validate detections fire correctly). 6) Threat intelligence integration (convert threat intel reports → actionable detection rules). 7) Detection metrics (rule efficacy + false-positive rate + true-positive rate + coverage %). Skills: programming (Python — must), SIEM query languages mastery (SPL / KQL), MITRE ATT&CK deep, understanding attacker TTPs, Git / CI-CD (detection-as-code). Why rising 2024+: orgs realized — buying more SIEM / EDR tools не помогает если detection rules плохие. Quality of detections > quantity of tools. Detection Engineering — recognized discipline (SANS course SEC555, dedicated conferences). Career-flow: SOC L2 / L3 + programming skills + detection rule authoring interest → Detection Engineer — 6-12 месяцев. Detection Engineering — один из лучших career paths из SOC (избегает SOC burnout + leverages engineering skills + higher ceiling).
С чего начинать в SOC в 2026?
Roadmap (SOC — самый доступный entry в кибербезопасность, можно войти без commercial experience): 1) IT fundamentals — networking (TCP / IP / DNS / HTTP / TLS — must), operating systems (Windows internals + Linux basics — где живут логи + что атакуют), basic system administration. CompTIA Network+ helpful baseline. 2) Security fundamentals — CompTIA Security+ (industry-standard entry cert — must для SOC L1 applications). CIA Triad, common attacks (phishing / malware / lateral movement / privilege escalation), security concepts. 3) SOC-specific cert — CompTIA CySA+ (Cybersecurity Analyst — SOC-focused — behavioral analytics + incident response) или Blue Team Level 1 (BTL1) (Security Blue Team — practical hands-on SOC cert — rising 2024+, highly respected — incident response + SIEM + threat intel + digital forensics). 4) SIEM hands-on — самый важный SOC skill. Splunk Fundamentals (free training — SPL query language) или Microsoft Sentinel (Azure free tier — KQL). Build home lab: ingest logs → write queries → create alerts. 5) MITRE ATT&CK fluency — изучить ATT&CK matrix (tactics + techniques), understand how alerts map к techniques. ATT&CK Navigator hands-on. 6) Home lab — set up SOC home lab: Security Onion (free SOC platform — Suricata + Zeek + Elastic) или Wazuh SIEM + simulate attacks (Atomic Red Team) + practice detection. 7) Hands-on practice platforms: TryHackMe SOC Level 1 + SOC Level 2 paths (best practical SOC training 2026 — affordable), Blue Team Labs Online (BTLO — investigation challenges), LetsDefend (SOC simulation platform — realistic alert triage practice), CyberDefenders (blue team CTF challenges). 8) Analysis tools — Wireshark (packet analysis) + VirusTotal + CyberChef (data decoding) + any.run (malware sandbox — free tier). Practice на real malware samples (malware-traffic-analysis.net). 9) Incident response basics — investigation methodology, the SANS PICERL model (Preparation / Identification / Containment / Eradication / Recovery / Lessons Learned). 10) Detection engineering basics (для L3 path) — Sigma rules + YARA + SPL / KQL rule authoring. 11) Python for SOC — alert enrichment scripts + SOAR playbook basics + automation. 12) Pet-проект portfolio: a) home SOC lab (Security Onion / Wazuh + simulated attacks + custom detections); b) TryHackMe SOC paths completion + writeups; c) LetsDefend / CyberDefenders investigation writeups (blog). International (eng): TryHackMe SOC Level 1 / 2 paths (best practical 2026), LetsDefend (SOC simulation), Blue Team Labs Online, SANS SEC450 Blue Team Fundamentals + SEC555 SIEM with Tactical Analytics (premium), «Blue Team Handbook» Don Murdoch (canonical SOC reference), «The Practice of Network Security Monitoring» Richard Bejtlich. Books-must: «Blue Team Handbook: SOC, SIEM, and Threat Hunting» Don Murdoch, «Applied Network Security Monitoring» Sanders / Smith, «Intelligence-Driven Incident Response» Roberts / Brown. SOC — entry-level accessible: certs (Security+ + CySA+ / BTL1) + home lab + TryHackMe portfolio → SOC L1 (без commercial experience возможно).
Сколько вакансий SOC Analyst в СНГ и Европе?
8 активных открытых SOC Analyst-вакансий с явной SOC-спецификой в нашей выборке. Реальный рынок значительно шире — many SOC roles classified как general «Security Analyst» / «Аналитик информационной безопасности» / «Specialist SOC» / «Информационная безопасность». SOC — один из самых ёмких security-сегментов by headcount (24×7 coverage требует много analysts — typical enterprise SOC 10-50+ analysts, MSSP — сотни). True SOC jobs в СНГ + Европе оценочно 500–2000+ позиций активных любой момент 2026 (SOC — high-volume hiring за счёт L1 turnover + 24×7 staffing). География: 🇷🇺 Россия / 🇵🇱 Польша / remote. Реальный рынок шире за счёт международного remote-сегмента (MSSP business model — inherently remote — Arctic Wolf / eSentire / Expel / Red Canary serve clients globally). Время закрытия SOC L1 — 2-6 недель (high-volume entry-level hiring), Senior L3 / Detection Engineer — 6-12 недель (rare-skill). SOC — самый ликвидный entry-level security job market — лучший способ войти в кибербезопасность 2026.
Какие навыки нужны Senior SOC Analyst (L3) / Detection Engineer?
Senior SOC Analyst L3 / Detection Engineer владеет полным циклом security operations + detection engineering. SIEM mastery deep: Splunk Enterprise Security advanced (SPL mastery — complex correlation searches + macros + lookup tables + data models) или Microsoft Sentinel (KQL mastery — advanced queries + analytics rules + workbooks). Custom detection rule authoring + tuning false-positive rates (core mandate — high signal-to-noise). MITRE ATT&CK mastery: deep fluency со всеми tactics + techniques + sub-techniques, ATT&CK Navigator для detection coverage gap analysis, map every detection к ATT&CK. Detection engineering: Sigma rule authoring (vendor-agnostic — convert к Splunk / Sentinel / Elastic), YARA rules (malware pattern matching), detection-as-code practices (Git version control + CI/CD + peer review + testing), adversary emulation (Atomic Red Team + Caldera — validate detections fire). Threat hunting mastery: hypothesis-driven hunting methodology (не wait for alerts — proactively hunt), behavioral analysis, hunting using ATT&CK + threat intelligence, anomaly detection. Incident response: investigation methodology (SANS PICERL), incident scoping + timeline reconstruction, containment strategy, lead L1 / L2 during major incidents. Malware analysis: static analysis basics (strings + PE headers + jadx / Ghidra basics), dynamic analysis (sandbox detonation — any.run / Joe Sandbox / Cuckoo — interpret results), basic reverse engineering. Forensics: memory forensics (Volatility), disk forensics basics, network forensics (Wireshark + Zeek), log analysis depth. Threat Intelligence: IoC workflows, STIX / TAXII, MISP, threat actor profiling, convert intel reports → detection rules. EDR / XDR mastery: CrowdStrike Falcon / SentinelOne / Microsoft Defender advanced — threat hunting queries, custom IOA rules, response actions. SOAR mastery: Cortex XSOAR / Splunk SOAR / Tines — playbook authoring в Python (automate L1 toil — typical mandate automate 50%+ repetitive triage). Programming: Python deep (alert enrichment + SOAR playbooks + detection automation + custom tooling), bash + PowerShell. Cloud security monitoring: AWS CloudTrail / GuardDuty + GCP Security Command Center + Azure Sentinel — cloud-specific detection. SOC metrics: MTTD / MTTR / dwell time / false-positive rate / detection coverage — measure + improve. Soft: clear incident documentation + technical writing, mentor L1 / L2 analysts, calm under pressure (incident handling), shift handover discipline, communication during incidents (stakeholder updates). Английский для Senior+ MUST — SIEM / EDR vendor docs + threat intel reports + security community англоязычные. Certifications: CompTIA CySA+ / BTL1 / GIAC GCIH (Certified Incident Handler) / GCFA (Forensic Analyst) / GCDA (Detection Analyst) / Splunk Core Certified / Microsoft SC-200. Optional bonus: detection engineering open-source contributions (Sigma rules repository / Atomic Red Team), threat hunting writeups / blog, conference talks (Blue Team Village DEF CON / SANS Blue Team Summit) — резко повышают market value для frontier-MSSP (Red Canary / Expel — detection engineering culture) hiring.
Оставить заявку
Опишите задачу и оставьте контакт — заявка попадёт в CRM, ответим на указанный контакт.