ES
Area Lead - Security Engineering
EPAM Systems
๐จ๐ฟ Czechia
Hybrid
Staff / Principal
8 hours ago
- Vulnerability Management
- SIEM
- triage
- Incident Response
- Microsoft Sentinel
- Microsoft Defender
- EDR
- Tenable
- Conditional Access
- CyberArk
- Vault
- Cortex
- Prisma
- CISSP
- CISM
8 hours ago
Area Lead owns the security operations, vulnerability management, identity governance, and NIS2 compliance posture for the managed infrastructure estate.
Responsibilities
- Own end-to-end security service delivery: SIEM monitoring, alert triage, vulnerability scanning, patch compliance tracking, endpoint protection, and identity/access governance
- Hold EPAM's NIS2 compliance sign-off chain for managed infrastructure โ own audit evidence and regulatory reporting
- Lead security transition-in: tooling onboarding, runbook authorship, current-state risk assessment, and knowledge transfer from incumbent vendors
- Govern a team of 6 offshore security engineers across operations, incident response, and change security reviews
- Interface directly with the client's CISO team and retained SOC function
- Drive security posture improvement โ KPIs, metrics, and continuous improvement cycles
- Manage security incidents through the escalation chain to the client
Requirements
- 7+ years in security engineering or SOC operations
- Microsoft Sentinel โ SIEM administration, detection rule authoring, alert triage
- Microsoft Defender โ EDR management and policy governance
- Tanium โ endpoint visibility and remediation
- Tenable โ vulnerability scanning, prioritisation, and reporting
- Microsoft Entra ID โ PIM, conditional access, identity governance
- CyberArk โ PAM vault operations and onboarding
- CyberArk EPM โ shadow IT and endpoint privilege management
- Palo Alto Cortex / Prisma โ cloud security posture (migration from Prisma to Cortex in progress)
- NIS2 Directive โ working knowledge of compliance requirements and evidence chains
- MSP or outsourcing background โ experience governing remote delivery teams
- English โ fluent; German or Czech โ strong asset
Nice to have
- CISSP, CISM, or equivalent
- Microsoft SC-200 (Security Operations Analyst)
Area Lead - Security Engineering ยท EPAM Systems