Vacancy catalog
EPAM
Open role

Area Lead - Security Engineering

EPAMPrague, Czechia
Work model
Hybrid
Experience
7+ years
Employment
Not specified
Compensation
Not disclosed
Technology signal
3 tags

Technology context

3

Parsed from the vacancy text; ordered by relevance to this role.

Full listing

Role description

Area Lead owns the security operations, vulnerability management, identity governance, and NIS2 compliance posture for the managed infrastructure estate.

Responsibilities

  • Own end-to-end security service delivery: SIEM monitoring, alert triage, vulnerability scanning, patch compliance tracking, endpoint protection, and identity/access governance
  • Hold EPAM's NIS2 compliance sign-off chain for managed infrastructure - own audit evidence and regulatory reporting
  • Lead security transition-in: tooling onboarding, runbook authorship, current-state risk assessment, and knowledge transfer from incumbent vendors
  • Govern a team of 6 offshore security engineers across operations, incident response, and change security reviews
  • Interface directly with the client's CISO team and retained SOC function
  • Drive security posture improvement - KPIs, metrics, and continuous improvement cycles
  • Manage security incidents through the escalation chain to the client

Requirements

  • 7+ years in security engineering or SOC operations
  • Microsoft Sentinel - SIEM administration, detection rule authoring, alert triage
  • Microsoft Defender - EDR management and policy governance
  • Tanium - endpoint visibility and remediation
  • Tenable - vulnerability scanning, prioritisation, and reporting
  • Microsoft Entra ID - PIM, conditional access, identity governance
  • CyberArk - PAM vault operations and onboarding
  • CyberArk EPM - shadow IT and endpoint privilege management
  • Palo Alto Cortex / Prisma - cloud security posture (migration from Prisma to Cortex in progress)
  • NIS2 Directive - working knowledge of compliance requirements and evidence chains
  • MSP or outsourcing background - experience governing remote delivery teams
  • English - fluent; German or Czech - strong asset

Nice to have

  • CISSP, CISM, or equivalent
  • Microsoft SC-200 (Security Operations Analyst)