Skip To Main Content
backBack to Search

Area Lead - Security Engineering

Hybrid in Czech Republic: Prague
Security.Operations
Looking for something else?

Find a vacancy that works for you. Send us your CV to receive a personalized offer.

Find me a job

Area Lead owns the security operations, vulnerability management, identity governance, and NIS2 compliance posture for the managed infrastructure estate.

Responsibilities
  • Own end-to-end security service delivery: SIEM monitoring, alert triage, vulnerability scanning, patch compliance tracking, endpoint protection, and identity/access governance
  • Hold EPAM's NIS2 compliance sign-off chain for managed infrastructure — own audit evidence and regulatory reporting
  • Lead security transition-in: tooling onboarding, runbook authorship, current-state risk assessment, and knowledge transfer from incumbent vendors
  • Govern a team of 6 offshore security engineers across operations, incident response, and change security reviews
  • Interface directly with the client's CISO team and retained SOC function
  • Drive security posture improvement — KPIs, metrics, and continuous improvement cycles
  • Manage security incidents through the escalation chain to the client
Requirements
  • 7+ years in security engineering or SOC operations
  • Microsoft Sentinel — SIEM administration, detection rule authoring, alert triage
  • Microsoft Defender — EDR management and policy governance
  • Tanium — endpoint visibility and remediation
  • Tenable — vulnerability scanning, prioritisation, and reporting
  • Microsoft Entra ID — PIM, conditional access, identity governance
  • CyberArk — PAM vault operations and onboarding
  • CyberArk EPM — shadow IT and endpoint privilege management
  • Palo Alto Cortex / Prisma — cloud security posture (migration from Prisma to Cortex in progress)
  • NIS2 Directive — working knowledge of compliance requirements and evidence chains
  • MSP or outsourcing background — experience governing remote delivery teams
  • English — fluent; German or Czech — strong asset
Nice to have
  • CISSP, CISM, or equivalent
  • Microsoft SC-200 (Security Operations Analyst)