Lead SecOps Engineer

EPAM·Ukraine·Удалённо·вчера

We are looking for a Lead SecOps Engineer to help protect our systems, applications, and data from evolving threats. You'll work at the intersection of security monitoring, incident response, and automation — building the detection and response capabilities that keep our environment secure.

Responsibilities

  • Monitor security alerts and logs across endpoints, network, cloud, and applications (SIEM/SOAR platforms)
  • Investigate and respond to security incidents, performing triage, containment, and root-cause analysis
  • Develop and tune detection rules, correlation logic, and alerting to reduce false positives and close coverage gaps
  • Build and maintain automation/playbooks for incident response (SOAR)
  • Conduct vulnerability management, including scanning, prioritization, and coordinating remediation with engineering teams
  • Perform threat hunting to proactively identify malicious activity
  • Support security tooling deployment and integration (EDR, SIEM, cloud security posture tools, IAM)
  • Participate in on-call rotation for security incidents
  • Contribute to post-incident reviews and documentation (runbooks, RCAs)
  • Collaborate with IT, DevOps, and engineering to harden infrastructure and enforce security best practices
  • Assist with compliance/audit activities (SOC 2, ISO 27001, etc.) as needed

Requirements

  • 5+ years of experience in security operations, incident response, or a related field
  • At least 1 year of relevant leadership experience
  • Hands-on expertise in SIEM (Splunk, Sentinel, Elastic, QRadar) and EDR tools
  • Solid understanding of networking, operating systems (Linux/Windows), and cloud environments (AWS, Azure, GCP)
  • Familiarity with common attack techniques and frameworks (MITRE ATT&CK, NIST Cybersecurity Framework)
  • Scripting proficiency in Python, Bash, or PowerShell for automation and tooling
  • Background in vulnerability management and remediation workflows
  • Strong analytical and problem-solving skills; calm under pressure during incidents
  • Clear written and verbal communication for documentation and cross-team collaboration (B2 English proficiency)

Nice to have

  • Experience with SOAR platforms (Palo Alto XSOAR, Tines)
  • Security certifications (Security+, GCIH, GCIA, CISSP, OSCP)
  • Background in threat intelligence or purple/red team collaboration
  • Familiarity with container/Kubernetes security
  • Experience in a regulated industry (finance)

Похожие вакансии

Другие вакансии EPAM