← к выдаче
проджект

Technical Project Manager (Security)

Krakówвчера

Описание от работодателя

About us At Keepit, we're on a mission to make cloud data protection simple, reliable, and built to last. Our platform provides customers with an immutable, historical archive of their data in systems such as Microsoft 365, Google Workspace, Salesforce, Entra ID, Dynamics 365, and Zendesk. We protect our customers against everything, from ransomware to simple accidents — and we pride ourselves on backing up hundreds of petabytes of data in a performant, reliable, and predictable way. As we collaborate across locations, English is our primary language. Please submit your CV in English to support the review process. We offer: Official employment (Umowa o pracę). 4 additional working days of vacation per full calendar year. 3 days of internal sick leave without a doctor's note. Health and life insurance. Employee Capital Plan (PPK). Multisport card compensation. Coverage of professional training, meetups, and conferences. English-speaking club with native speakers and Polish language classes. Internet and glasses reimbursement. Office in Krakow city centre (Dluga 72) with beverages, fruit, and snacks. Regular team-building events, winter and summer parties. We kindly ask you not to provide us with any sensitive categories of personal data when applying for a job with us.   When applying for the vacancy, Keepit will process your personal data, and therefore we recommend that you also read our privacy policy , which describes our processing of personal data and your rights as a data subject. If you notice any misconduct or irregularities that fall within the scope of our whistleblowing procedure, please click here to report them. Daily tasks: - Support daily security operations in deploying and implementing operational security priorities. - Own the security roadmap: ensure the team stays on track to complete annual roadmap commitments. - Lead communication, planning, and coordination with other teams and stakeholders. - Run the SOC's recurring cadence: backlog refinement, sprint and roadmap reviews, shift handover syncs, and stakeholder check-ins. - Maintain and prioritize the SOC's project backlog in coordination with security engineering and detection engineering leads. - Track project risks, dependencies, and blockers; escalate when needed. - Manage vendor and tool procurement timelines, including renewals, proofs of concept (PoCs), and onboarding of new security tools. You own the process and the vendor relationships; the security budget stays with SOC leadership. - Own documentation of processes, standard operating procedures, and runbooks, keeping them current rather than created once and left stale. - Report roadmap and project status to leadership. - Manage change requests and change management for production security tooling changes. - Define and track a maturity model, for example mapped to the NIST Cybersecurity Framework (CSF), MITRE ATT&CK coverage, or a custom capability matrix. - Own operational KPIs and metrics: mean time to detect (MTTD), mean time to respond (MTTR), alert-to-incident ratio, false positive rate, and detection coverage by use case. - Run periodic gap assessments against the maturity model and turn findings into roadmap items. - Coordinate tabletop exercises and purple team engagements, and track remediation of findings. - Benchmark against industry peers or frameworks annually. - Ensure schedule coverage for phishing triage and security information and event management (SIEM) monitoring. - Manage the on-shift rotation for incident response. - Plan for PTO and holiday coverage gaps well in advance. - Maintain a documented shift handover 5+ years managing technical projects or programs, ideally in security, infrastructure, or IT operations. Proven ownership of a backlog and a roadmap end to end: prioritization, dependency tracking, and delivery against dated commitments. A working understanding of security operations — how detection, alert triage, incident response, and vulnerability management fit together. You do not need to have run a SOC yourself, but you do need enough fluency to hold a credible conversation with the engineers who do. Power-user fluency in Jira and Confluence, or the ability to get there fast. Experience coordinating coverage schedules or on-call rotations, including planning around absence and handover. Strong written English, and the ability to write documentation people can follow and will keep using. Nice-to-haves: Exposure to a security maturity or coverage framework such as the NIST CSF or MITRE ATT&CK. Experience facilitating post-incident reviews, tabletop exercises, or purple team engagements. Experience selecting or rolling out an IT service management platform. Familiarity with change management for production systems. Vendor management or procurement coordination experience. Must have: Security, Jira, Confluence