Cybersecurity Manager

Moscow

About the vacancy

In this role, you will be responsible for building and leading the Information Security function within the organization.

Key responsibilities:

Key responsibilities:

  • Build and lead the Information Security (IS) function, manage the IS development strategy, and implement the security roadmap
  • Develop, defend, and oversee the execution of the information security budget
  • Coordinate projects related to the implementation, development, and modernization of information security solutions in collaboration with internal IT teams and external contractors
  • Manage relationships with information security service and solution providers, ensuring quality and timely delivery
  • Organize the implementation and operation of key information security services and systems, including:
    • Monitoring and Incident Response: SOC, SIEM, EDR/XDR, IRP/SOAR
    • Infrastructure Protection: Firewalls, IDS/IPS, Web Filtering, DDoS Protection
    • Data Protection: DLP, encryption solutions for storage media and communication channels
    • Access Management: Strong authentication, MDM, secure remote access
    • Vulnerability Management: Security assessment and configuration monitoring services
  • Manage and develop antivirus protection processes (Kaspersky Security Center)
  • Establish incident response processes and conduct security investigations
  • Develop, update, and implement internal information security policies, standards, procedures, and guidelines
  • Prepare the company for compliance with Russian regulatory requirements (Federal Law No. 187-FZ, Federal Law No. 152-FZ), FSTEC regulations, ISO 27001 standards, and Critical Information Infrastructure (CII) protection requirements
  • Conduct CII asset categorization and oversee compliance-related activities
  • Organize and support internal and external information security audits and interact with regulatory authorities
  • Develop and manage employee security awareness programs, including:
    • Regular information security training
    • Simulated phishing campaigns
    • Training completion monitoring
  • Conduct regular information security risk assessments and develop mitigation plans
  • Participate in Business Continuity Planning (BCP) and Disaster Recovery Planning (DRP) from an information security perspective
  • Prepare regular management reports on project status, risk levels, security incidents, and IS process maturity

Successful candidate profile:

  • Higher education in Information Security, Information Technology, or a related field
  • 3–5+ years of experience in information security (experience in pharmaceutical, manufacturing, or international companies is an advantage)
  • Hands-on experience implementing or supporting enterprise security solutions (SIEM, DLP, EDR/XDR, SOC)
  • Strong understanding of a risk-based approach to information security
  • Knowledge of modern SOC, SIEM, EDR/XDR architectures and Incident Response processes
  • Good understanding of network technologies (TCP/IP), Windows infrastructure (Active Directory), authentication mechanisms (SSO, MFA), and enterprise IT architecture
  • Experience with cloud platforms (Azure, AWS, Yandex Cloud) and understanding of cloud security principles
  • Experience in project management (Agile, Scrum, Kanban) and coordination of integrators, vendors, and service providers
  • Experience developing information security policies, procedures, and internal documentation
  • Deep knowledge of Russian information security legislation and regulations, including: Federal Law No. 187-FZ “On the Security of Critical Information Infrastructure”, Federal Law No. 152-FZ “On Personal Data”, FSTEC and FSB requirements, Experience with CII categorization projects is an advantage
  • Understanding of information security management systems aligned with ISO 27001
  • Ability to build effective relationships with stakeholders at all levels of the organization, from technical specialists to senior executives, with varying levels of technical expertise
  • Proactive approach and high degree of autonomy in decision-making
  • Structured mindset, results orientation, and focus on achieving measurable outcomes

 

To the successful candidate we will be pleased to offer:

  • Competitive salary
  • Participation in quarterly bonus scheme
  • Attractive social package: VHI, accident and critical illness insurance, employee support services
  • Opportunities for growth and professional development

Our mission

We help people take care of their health and bring knowledge to the medical community.

 

Our vision

Alcea is a modern, dynamic pharmaceutical company, a recognized expert in women’s and men’s health.

We serve the interests of patients, medical society, partners and investors following high standards of quality and ethics.

We are actively growing thanks to our agility. Our team goes beyond general approach, driving development of the company.

 

Our values

Development. We are moving forward on constant basis with high energy and growth dynamic, achieving top results.

Responsibility. We are honest, reliable, ethical we respect our commitments and follow high quality standards.

Courage. We set ambitious goals and move steadily towards them. We are not afraid of change, make bold decisions and respond to market challenges.

Creativity. We go beyond the familiar and constantly introduce innovations.

 

pic

apply for a job

Events 25 February
    We use cookies

    By using this website, you consent to the collection and processing of your personal data, including through the use of third-party services, cookies and web analytics, on the terms and conditions set out in the Policy on personal data processing for websites and hotlinePersonal Data Processing Policy. You also accept the terms and conditions of our Пользовательского соглашенияUser Agreement.

    en_USEnglish