Перейти к содержимому

Азат Жакубаев

IAM / PAM Security Engineer (Privileged Access, MFA, Email Security)

Middle Удалённо Astana, Казахстан
2 г. 3 мес. опыта 29 навыка

О себе

Information Security Engineer with over 2 years of hands-on experience in a corporate environment at Beeline Kazakhstan. Worked in the SOC—monitoring, triage, and incident response. Transitioned to an engineering focus: IAM, PAM, Email Security, and DevOps Security. I am skilled at both identifying threats and building infrastructure to prevent them. I aim to grow in the direction of security architecture.

Опыт работы

Beeline, ТМ

05.2025 — по н.в. 1 г. 1 мес.

IAM Engineer — PAM / MFA / Email Security

Middle Гибрид Almaty

Identity and Access Management / Privileged Access Management Implemented and developed the company’s IAM infrastructure: from deploying PAM from scratch to securing email and container environments. PAM (Delinea Secret Server) Deployed the platform from pilot to production. Developed launchers for web, RDP, and DBeaver with the implementation of a credential store—eliminating the need to share passwords with users. Blocked direct access to mission-critical and SOX-compliant systems by transferring control to PAM. Conducted privileged access audits and SOX compliance checks. Email Security (FortiMail) Deployed a high-availability cluster from scratch: configured MX, SPF, DKIM, and filtering policies for incoming/outgoing traffic. Reduced the number of phishing and malicious emails by approximately 70–80%. MFA / 2FA Provided support for Microsoft MFA and LinOTP: diagnosed and resolved OTP delivery failures, investigated authentication incidents. DevOps Security (Kubernetes / Docker) Implemented RBAC in Kubernetes: configured roles, role bindings, service accounts, and namespaces. Restricted access to Kubernetes APIs and Docker hosts using the principle of least privilege. Coordinated and implemented firewall rules taking into account network segmentation (VLAN, DMZ).

  • Reduced the number of phishing and malicious emails by approximately 70–80%

Beeline, ТМ

03.2024 — 05.2025 1 г. 2 мес.

SOC Аналитик L1

Junior Офис Almaty

Provided 24/7 monitoring and response to cybersecurity incidents within the infrastructure of a major telecommunications operator. SIEM / Monitoring Detected and classified security events in IBM QRadar, ArcSight ESM, Splunk, and Wazuh. Integrated log sources, configured correlation rules, and resolved issues with data quality and ingestion delays. Analyzed network and endpoint incidents via Fidelis, Microsoft Defender, DLP, and Suricata IDS/IPS. Verified IOCs via VirusTotal, IBM X-Force, and Cisco Talos. WAF / Response Analyzed F5 WAF alerts: identified anomalies, classified events, and blocked IP addresses. Escalated incidents to the L2 and network teams with prepared context for rapid decision-making. Developed playbooks and automated response scenarios via SOAR—reduced response time and lowered the false positive rate. Automation (Python / PowerShell) Automated routine operations: log parsing, report generation, and integration via REST API. Developed a Telegram bot for push notifications to SOC analysts—reducing the time it took to alert the team about incidents. Vulnerability Management Conducted security audits, identified vulnerabilities and architectural weaknesses. Managed patch management: tracked update installations and verified vulnerability remediation. Collaborated with responsible teams on prioritization and SLAs.

  • Reduced response time and lowered the false positive rate through SOAR automation
  • Reduced the time it took to alert the team about incidents via Telegram bot

Otbasy Bank

05.2026 — по н.в. 0 мес.

Специалист 1 категорий

Образование

Международный университет информационных технологий

2022 — 2025

Система информационной безопасности

Бакалавр

Автономная некоммерческая организация высшего образования «Университет Иннополис»

2022 — 2025

Система информационной безопасности

Бакалавр

Курсы

Cloud Computing Law: Data Protection and Cybersecurity

Django for Everybody

Ethical Hacking Foundations

IT Fundamentals for Cybersecurity

Incident Response and Digital Forensics

Managing Cybersecurity

Managing Cybersecurity Incidents and Disasters

Road to the CISO – Culminating Project Course

Open Source Software Development, Linux and Git

Навыки

Linux Bash Организаторские навыки Информационные технологии PowerShell Администрирование VMware SIEM SOAR DLP XDR EDR Python Java Script Unix СУБД Qualys Grafana Аудиторские проверки ITSM IAM (Identity and Access Management) PAM (Privileged Access Management) MFA / 2FA RBAC (Role-Based Access Control) Patch Management Vulnerability Management Email Security ISO 27001 PCI DSS

Языки

Kazakh Родной
English B2 — Выше среднего
Russian C1 — Продвинутый

Личные данные

Возраст 22 года
Гражданство Казахстан
Ссылка скопирована