- Work model
- Hybrid
- Experience
- 7+ years
- Employment
- Not specified
- Compensation
- Not disclosed
- Technology signal
- 3 tags
Technology context
3Parsed from the vacancy text; ordered by relevance to this role.
Full listing
Role description
Area Lead owns the security operations, vulnerability management, identity governance, and NIS2 compliance posture for the managed infrastructure estate.
Responsibilities
- Own end-to-end security service delivery: SIEM monitoring, alert triage, vulnerability scanning, patch compliance tracking, endpoint protection, and identity/access governance
- Hold EPAM's NIS2 compliance sign-off chain for managed infrastructure - own audit evidence and regulatory reporting
- Lead security transition-in: tooling onboarding, runbook authorship, current-state risk assessment, and knowledge transfer from incumbent vendors
- Govern a team of 6 offshore security engineers across operations, incident response, and change security reviews
- Interface directly with the client's CISO team and retained SOC function
- Drive security posture improvement - KPIs, metrics, and continuous improvement cycles
- Manage security incidents through the escalation chain to the client
Requirements
- 7+ years in security engineering or SOC operations
- Microsoft Sentinel - SIEM administration, detection rule authoring, alert triage
- Microsoft Defender - EDR management and policy governance
- Tanium - endpoint visibility and remediation
- Tenable - vulnerability scanning, prioritisation, and reporting
- Microsoft Entra ID - PIM, conditional access, identity governance
- CyberArk - PAM vault operations and onboarding
- CyberArk EPM - shadow IT and endpoint privilege management
- Palo Alto Cortex / Prisma - cloud security posture (migration from Prisma to Cortex in progress)
- NIS2 Directive - working knowledge of compliance requirements and evidence chains
- MSP or outsourcing background - experience governing remote delivery teams
- English - fluent; German or Czech - strong asset
Nice to have
- CISSP, CISM, or equivalent
- Microsoft SC-200 (Security Operations Analyst)