Описание: Keepit provides a cloud data protection platform that gives customers an immutable, historical archive of data across services such as Microsoft 365, Google Workspace, Salesforce, Entra ID, Dynamics 365, and Zendesk. It protects data from ransomware and accidental loss.
Задачи
- Support daily security operations by deploying and implementing operational security priorities
- Own the security roadmap and keep annual commitments on track
- Lead communication, planning, and coordination with other teams and stakeholders
- Run the SOC’s recurring cadence, including backlog refinement, sprint and roadmap reviews, shift handovers, and stakeholder check-ins
- Maintain and prioritize the SOC project backlog with security engineering and detection engineering leads
- Track project risks, dependencies, and blockers, and escal…?
- Manage vendor and tool procurement timelines, renewals, proofs of concept, and onboarding; own vendor relationships while the security budget remains with SOC leadership
- Maintain current process documentation, standard operating procedures, and runbooks
- Report roadmap and project status to leadership
- Manage change requests and change management for production security tooling
- Define and track a maturity model, such as one mapped to NIST CSF, MITRE ATT&CK coverage, or a custom capability matrix
- Own operational KPIs and metrics, including MTTD, MTTR, alert-to-incident ratio, false positive rate, and detection coverage by use case
- Run periodic maturity gap assessments and turn findings into roadmap items
- Coordinate tabletop exercises and purple team engagements, and track remediation of findings
- Benchmark against industry peers or frameworks annually
- Ensure schedule coverage for phishing triage and SIEM monitoring
- Manage the on-shift incident response rotation
- Plan for PTO and holiday coverage gaps in advance
- Maintain a documented shift handover process
- Extend scheduling oversight to other monitoring duties as needed, such as vulnerability scanning cadence and threat intel review
- Participate in incident response and coordination
- Own and maintain incident response playbooks and runbooks
- Facilitate blameless post-incident reviews and track remediation actions to closure
- Track incident metrics and produce leadership-facing incident reports
- Manage escalation paths and ensure the right people and teams are involved in major incidents
- Coordinate with legal, compliance, and communications teams on incidents with regulatory or public exposure
- Serve as the single point of contact for cross-functional teams needing SOC engagement, including IT, legal, compliance, and engineering
- Manage relationships with security tool vendors and external partners, from evaluation and proof of concept through onboarding and renewal
Требования
- 5+ Years managing technical projects or programs, ideally in security, infrastructure, or IT operations
- Proven end-to-end ownership of a backlog and roadmap, including prioritization, dependency tracking, and delivery against dated commitments
- Working understanding of security operations, including detection, alert triage, incident response, and vulnerability management
- Ability to hold credible conversations with security operations engineers; prior experience running a SOC is not required
- Power-user fluency in Jira and Confluence, or ability to reach that level quickly
- Experience coordinating coverage schedules or on-call rotations, including absence planning and handovers
- Strong written English and ability to write clear, maintainable documentation
- Будет плюсом: exposure to a security maturity or coverage framework such as NIST CSF or MITRE ATT&CK
- Будет плюсом: experience facilitating post-incident reviews, tabletop exercises, or purple team engagements
- Будет плюсом: experience selecting or rolling out an IT service management platform
- Будет плюсом: familiarity with change management for production systems
- Будет плюсом: vendor management or procurement coordination experience
Условия
- Official employment (Umowa o pracę)
- 4 Additional working days of vacation per full calendar year
- 3 Days of internal sick leave without a doctor's note
- Health and life insurance
- Employee Capital Plan (PPK)
- Multisport card
- compensation
- Coverage of professional training, meetups, and conferences
- English-speaking club with native speakers and Polish language classes
- Internet and glasses reimbursement
- Office in Krakow city centre (Dluga 72) with beverages, fruit, and snacks
- Regular team-building events, winter and summer parties