remotely.living

Lead SecOps Engineer

EPAM Systems · Remote - Ukraine · 2026-09-29

Apply for this job

Job description

We are looking for a Lead SecOps Engineer to help protect our systems, applications, and data from evolving threats. You'll work at the intersection of security monitoring, incident response, and automation — building the detection and response capabilities that keep our environment secure.

Responsibilities

- Monitor security alerts and logs across endpoints, network, cloud, and applications (SIEM/SOAR platforms)

- Investigate and respond to security incidents, performing triage, containment, and root-cause analysis

- Develop and tune detection rules, correlation logic, and alerting to reduce false positives and close coverage gaps

- Build and maintain automation/playbooks for incident response (SOAR)

- Conduct vulnerability management, including scanning, prioritization, and coordinating remediation with engineering teams

- Perform threat hunting to proactively identify malicious activity

- Support security tooling deployment and integration (EDR, SIEM, cloud security posture tools, IAM)

- Participate in on-call rotation for security incidents

- Contribute to post-incident reviews and documentation (runbooks, RCAs)

- Collaborate with IT, DevOps, and engineering to harden infrastructure and enforce security best practices

- Assist with compliance/audit activities (SOC 2, ISO 27001, etc.) as needed

Requirements

- 5+ years of experience in security operations, incident response, or a related field

- At least 1 year of relevant leadership experience

- Hands-on expertise in SIEM (Splunk, Sentinel, Elastic, QRadar) and EDR tools

- Solid understanding of networking, operating systems (Linux/Windows), and cloud environments (AWS, Azure, GCP)

- Familiarity with common attack techniques and frameworks (MITRE ATT&CK, NIST Cybersecurity Framework)

- Scripting proficiency in Python, Bash, or PowerShell for automation and tooling

- Background in vulnerability management and remediation workflows

- Strong analytical and problem-solving skills; calm under pressure during incidents

- Clear written and verbal communication for documentation and cross-team collaboration (B2 English proficiency)

Nice to have

- Experience with SOAR platforms (Palo Alto XSOAR, Tines)

- Security certifications (Security+, GCIH, GCIA, CISSP, OSCP)

- Background in threat intelligence or purple/red team collaboration

- Familiarity with container/Kubernetes security

- Experience in a regulated industry (finance)