Security Engineering Lead
We are looking for an experienced Security Engineering Lead to take end-to-end ownership of the Security Engineering domain across a complex European IT estate.
You will be accountable for security engineering services, NIS2 compliance evidence and the associated sign-off chain for the managed infrastructure. The role combines hands-on security expertise, service governance, regulatory compliance and technical leadership of distributed engineering teams.
You will lead the transition of security services, govern BAU security engineering activities and work closely with the client’s CISO organisation and retained Security Operations Centre (SOC). Please note that SOC service delivery itself is not within EPAM’s scope.
Responsibilities
- Own the Security Engineering domain across the client’s IT estate
- Hold accountability for NIS2 compliance within the managed infrastructure scope
- Maintain the required NIS2 controls, audit evidence and sign-off chain
- Lead security transition-in activities, including security tooling onboarding, current-state security and risk assessments, operational documentation and runbook creation, and knowledge transfer and service-readiness validation
- Govern offshore security engineers in Hungary and Romania across BAU security operations, security alert triage, vulnerability assessment and remediation, security reviews of infrastructure and application changes, and IAM and PAM-related activities
- Act as the primary security engineering interface with the client’s CISO team
- Collaborate with the client’s retained SOC while maintaining clear accountability boundaries, as SOC delivery is outside EPAM’s scope
- Manage security incidents through the agreed investigation, communication and escalation chain
- Ensure timely escalation of material security risks and incidents to the client
- Define, monitor and report security posture, vulnerability and remediation metrics
- Drive SOAR adoption and automated remediation initiatives
- Identify opportunities to improve security controls, monitoring, response processes and operational efficiency
- Provide security design oversight for a strategic IAM migration programme
- Review identity architecture, access models, security controls and migration risks
- Ensure that security documentation, procedures and operational controls remain accurate and audit-ready
Requirements
- 7–10 years of professional experience in security engineering
- Strong hands-on experience with Privileged Access Management (PAM)
- Proven experience delivering IAM and PAM programmes
- Strong knowledge of Identity and Access Management (IAM) technologies and security principles
- Experience with Security Information and Event Management (SIEM) platforms
- Strong understanding of Security Operations Centre processes, operating models and escalation procedures
- Practical experience in vulnerability management, including assessment, prioritisation, remediation and reporting
- Strong working knowledge of NIS2 requirements and compliance controls
- Experience maintaining regulatory evidence and supporting security audits
- Previous experience working within an MSP, managed services or IT outsourcing environment
- Experience governing distributed or offshore security engineering teams
- Ability to manage security incidents and coordinate multiple technical and business stakeholders
- Strong risk assessment, stakeholder management and communication skills
- Ability to engage effectively with CISO-level stakeholders
- Fluent English communication skills (B2 level or higher)
Nice to have
- CISSP, CISM or Microsoft Certified: Security Operations Analyst Associate (SC-200) certification
- Experience with AWS Security Hub
- Strong understanding of cloud security concepts
- Experience with CyberArk Customer Identity or other CyberArk solutions
- Experience with Microsoft Entra ID
- Experience with Microsoft 365 Defender
- Experience with Microsoft Defender for Cloud
- Experience with Datadog
- Experience with the Tanium Platform
- Knowledge of Security Orchestration, Automation and Response (SOAR) technologies
- Knowledge of Information Technology Infrastructure Library (ITIL) practices
- German or Czech language skills
Benefits
- Opportunity to work in a fast-paced, agile, software engineering culture
- Comfortable modern office in Prague 7, with support of hybrid or fully remote mode
- Benefit program (5 weeks of vacation, paid sick days, paid days off for special occasions, meal vouchers, flexi pass, Prague city public transport annual coupon, multisport cards, optional contribution to pension fund, health insurance for family member)
- EPAM Employee Stock Purchase Plan (ESPP) (subject to certain eligibility requirements)
- English language courses
- Czech language courses upon request
- Referral bonuses for recommended candidates
- Mobile Phone Tariff’s program for managerial-level candidates
- Great learning and development opportunities, including in-house professional training, career advisory and coaching, sponsored professional certifications, well-being programs, LinkedIn Learning Solutions and much more
About the Company
More jobs at EPAM Systems
-
Senior Systems Engineer
Australia · remote · Sep 25, 2026
-
Lead JavaScript/TypeScript Full-Stack Engineer (GenAI-assisted development)
Ukraine · remote · Sep 24, 2026
-
AI Software Engineer
USA · remote · Sep 25, 2026
-
Lead AI Engineer
USA · remote · Sep 25, 2026
-
Senior Backend Developer, AI Pods
Argentina, Chile, Colombia · remote · Sep 24, 2026