EPAM Systems logo
EPAM Systems

4,192 open roles

Lead SecOps Engineer

Remote (Ukraine)Full-timePosted Sep 29, 2026

Job description

We are looking for a Lead Sec. Ops Engineer to help protect our systems, applications, and data from evolving threats. You'll work at the intersection of security monitoring, incident response, and automation — building the detection and response capabilities that keep our environment secure.

Responsibilities

Monitor security alerts and logs across endpoints, network, cloud, and applications (SIEM/SOAR platforms) Investigate and respond to security incidents, performing triage, containment, and root-cause analysis Develop and tune detection rules, correlation logic, and alerting to reduce false positives and close coverage gaps Build and maintain automation/playbooks for incident response (SOAR) Conduct vulnerability management, including scanning, prioritization, and coordinating remediation with engineering teams Perform threat hunting to proactively identify malicious activity Support security tooling deployment and integration (EDR, SIEM, cloud security posture tools, IAM) Participate in on-call rotation for security incidents Contribute to post-incident reviews and documentation (runbooks, RCAs) Collaborate with IT, DevOps, and engineering to harden infrastructure and enforce security best practices Assist with compliance/audit activities (SOC 2, ISO 27001, etc.)

as needed Requirements 5+ years of experience in security operations, incident response, or a related field At least 1 year of relevant leadership experience Hands-on expertise in SIEM (Splunk, Sentinel, Elastic, QRadar) and EDR tools Solid understanding of networking, operating systems (Linux/Windows), and cloud environments (AWS, Azure, GCP) Familiarity with common attack techniques and frameworks (MITRE ATT&CK, NIST Cybersecurity Framework) Scripting proficiency in Python, Bash, or Power.

Shell for automation and tooling Background in vulnerability management and remediation workflows Strong analytical and problem-solving skills; calm under pressure during incidents Clear written and verbal communication for documentation and cross-team collaboration (B2 English proficiency) Nice to have Experience with SOAR platforms (Palo Alto XSOAR, Tines) Security certifications (Security+, GCIH, GCIA, CISSP, OSCP) Background in threat intelligence or purple/red team collaboration Familiarity with container/Kubernetes security Experience in a regulated industry (finance)

Description copied from EPAM Systems's careers page. Read the full posting before you apply.

More jobs at EPAM Systems

See all openings at EPAM Systems