953,927open jobs
57,674companies
156,942added this week
Browse all
Salary
≈ $69k – $148k per year (Estimated)
Location
In office (Kraków)
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 29, 2026. First seen by Alion on Sep 28, 2026. Keepit scores A on the Alion truth index.

Overview
Company
Impact
Profile match
The Keepit Cloud is the most cost-effective solution on the market with 20+ years of experience. Learn more about our next-level SaaS data protection services.

About the role

The security operations center (SOC) at Keepit needs someone who can turn operational priorities into planned, tracked, and delivered work. This role sits at the intersection of project management and security operations - keeping daily operations, the annual security roadmap, coverage scheduling, and incident response coordinated and moving forward. The role has no direct reports. You will, however, lead the team's on-shift rotation and its operating cadence, so it carries real coordination authority across the SOC.

You will:

Project delivery

  • Support daily security operations in deploying and implementing operational security priorities.

  • Own the security roadmap: ensure the team stays on track to complete annual roadmap commitments.

  • Lead communication, planning, and coordination with other teams and stakeholders.

  • Run the SOC's recurring cadence: backlog refinement, sprint and roadmap reviews, shift handover syncs, and stakeholder check-ins.

  • Maintain and prioritize the SOC's project backlog in coordination with security engineering and detection engineering leads.

  • Track project risks, dependencies, and blockers; escalate when needed.

  • Manage vendor and tool procurement timelines, including renewals, proofs of concept (PoCs), and onboarding of new security tools. You own the process and the vendor relationships; the security budget stays with SOC leadership.

  • Own documentation of processes, standard operating procedures, and runbooks, keeping them current rather than created once and left stale.

  • Report roadmap and project status to leadership.

  • Manage change requests and change management for production security tooling changes.

Measuring team maturity

  • Define and track a maturity model, for example mapped to the NIST Cybersecurity Framework (CSF), MITRE ATT&CK coverage, or a custom capability matrix.

  • Own operational KPIs and metrics: mean time to detect (MTTD), mean time to respond (MTTR), alert-to-incident ratio, false positive rate, and detection coverage by use case.

  • Run periodic gap assessments against the maturity model and turn findings into roadmap items.

  • Coordinate tabletop exercises and purple team engagements, and track remediation of findings.

  • Benchmark against industry peers or frameworks annually.

    Scheduling

  • Ensure schedule coverage for phishing triage and security information and event management (SIEM) monitoring.

  • Manage the on-shift rotation for incident response.

  • Plan for PTO and holiday coverage gaps well in advance.

  • Maintain a documented shift handover process between shifts.

  • Extend scheduling oversight to other monitoring duties as needed, such as vulnerability scanning cadence and threat intel review.

    Incident management

  • Participate in incident response and coordination.

  • Own and maintain incident response playbooks and runbooks.

  • Facilitate post-incident reviews (blameless retrospectives) and track remediation actions to closure.

  • Track incident metrics and produce leadership-facing incident reports.

  • Manage escalation paths and ensure the right people and teams are looped in during major incidents.

  • Coordinate with legal, compliance, and communications teams on incidents with regulatory or public exposure.

Stakeholder and vendor management

  • Serve as the single point of contact for cross-functional teams needing SOC engagement, including IT, legal, compliance, and engineering.

  • Manage relationships with security tool vendors and external partners, from evaluation and proof of concept through onboarding and renewal.

What success looks like

By the end of your first 90 days:

  • The SOC backlog is prioritized, current, and reviewed on a predictable cadence with the security engineering and detection engineering leads.

  • Annual roadmap commitments are broken into tracked work with owners, dependencies, and dates, and leadership has a status view it trusts.

  • Coverage for phishing triage and SIEM monitoring is planned ahead, including PTO and holiday gaps, with a documented handover between shifts.

  • You have facilitated at least one post-incident review and tracked its actions to closure.

Tools you'll work with

  • You will not administer the security platforms - engineering owns those. You do need to be a power user of the delivery and documentation tooling, and comfortable enough in the security stack to read what it tells you.

Delivery and documentation

  • Jira for the backlog, sprints, and roadmap tracking, including boards, workflows, and dashboards. Power-user level expected.

  • Confluence for processes, standard operating procedures (SOPs), runbooks, and decision records. Power-user level expected.

  • Figma for process diagrams and workflow mapping.

Ticketing and case management

  • Two IT service management platforms are in use across the company today, and part of this role is helping decide which one the SOC standardizes on. We are also standing up a dedicated case management tool for security investigations. Experience running work through a service management platform matters more than experience with any specific product.

Security monitoring and detection

  • Wazuh for SIEM, Microsoft Defender XDR for endpoint detection and response, and Tenable One for attack surface management and vulnerability management.

  • Working familiarity is enough here: you should be able to follow detection coverage, alert volumes, and scan cadence, and hold a credible conversation with the engineers who run these tools. Operator-level depth is not expected.

Reporting, communication, and vendor tracking

  • Jira dashboards for delivery status, and PowerPoint for leadership decks.

  • Microsoft Teams for day-to-day coordination, and email for external vendors and partners.

  • Confluence and spreadsheets for renewal timelines, PoC tracking, and vendor contacts.

About you

Must-haves:

  • 5+ years managing technical projects or programs, ideally in security, infrastructure, or IT operations.

  • Proven ownership of a backlog and a roadmap end to end: prioritization, dependency tracking, and delivery against dated commitments.

  • A working understanding of security operations - how detection, alert triage, incident response, and vulnerability management fit together. You do not need to have run a SOC yourself, but you do need enough fluency to hold a credible conversation with the engineers who do.

  • Power-user fluency in Jira and Confluence, or the ability to get there fast.

  • Experience coordinating coverage schedules or on-call rotations, including planning around absence and handover.

  • Strong written English, and the ability to write documentation people can follow and will keep using.

Nice-to-haves:

  • Exposure to a security maturity or coverage framework such as the NIST CSF or MITRE ATT&CK.

  • Experience facilitating post-incident reviews, tabletop exercises, or purple team engagements.

  • Experience selecting or rolling out an IT service management platform.

  • Familiarity with change management for production systems.

  • Vendor management or procurement coordination experience.

About us

At Keepit, we're on a mission to make cloud data protection simple, reliable, and built to last. Our platform provides customers with an immutable, historical archive of their data in systems such as Microsoft 365, Google Workspace, Salesforce, Entra ID, Dynamics 365, and Zendesk. We protect our customers against everything, from ransomware to simple accidents - and we pride ourselves on backing up hundreds of petabytes of data in a performant, reliable, and predictable way.

As we collaborate across locations, English is our primary language. Please submit your CV in English to support the review process.

We offer:

  • Official employment (Umowa o pracę).

  • 4 additional working days of vacation per full calendar year.

  • 3 days of internal sick leave without a doctor's note.

  • Health and life insurance.

  • Employee Capital Plan (PPK).

  • Multisport card compensation.

  • Coverage of professional training, meetups, and conferences.

  • English-speaking club with native speakers and Polish language classes.

  • Internet and glasses reimbursement.

  • Office in Krakow city centre (Dluga 72) with beverages, fruit, and snacks.

  • Regular team-building events, winter and summer parties.

We kindly ask you not to provide us with any sensitive categories of personal data when applying for a job with us. When applying for the vacancy, Keepit will process your personal data, and therefore we recommend that you also read our privacy policy, which describes our processing of personal data and your rights as a data subject.

If you notice any misconduct or irregularities that fall within the scope of our whistleblowing procedure, please click here to report them.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
953,927 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Leadership
Similar stack
Same company
Kraków
≈ $263k – $493k per year (Estimated) • In office • Full-Time • San Jose
Python
Go
Java
C++
Apply
≈ $76k – $152k per year (Estimated) • In office • Full-Time • 3+ years exp • Greensboro
Analytics
Microsoft Excel
Management
Outlook
Agile
Waterfall
Microsoft Office
Apply
≈ $54k – $132k per year (Estimated) • Hybrid • Full-Time • 10+ years exp • Pune
AI/ML
AI Agents
Management
Agile
Apply
$120k per year • Remote (United States) • 5+ years exp
Databases
Databricks
Analytics
ETL/ELT
Management
Jira
Agile
Apply
≈ $167k – $335k per year (Estimated) • In office • 8+ years exp • Bachelor's Degree • Sunnyvale
C++
DevOps
GCP
Apply
≈ $16k – $33k per year (Estimated) • Remote (likely EAEU) • Novosibirsk
JavaScript
Java
SQL
Java
Spring Boot
Databases
PostgreSQL
Redis
RabbitMQ
Apache Kafka
Frontend
React.js
DevOps
Rest API
Prometheus
CI/CD
Grafana
GitLab
SOAP
Management
Confluence
Jira
QA
Swagger
Postman
Apply
≈ $52k – $102k per year (Estimated) • In office • 2+ years exp • Bachelor's Degree • Naples
Management
Confluence
Jira
Agile
ITIL
Apply
≈ $67k – $154k per year (Estimated) • In office • Chattanooga
Management
Confluence
Jira
Apply
≈ $19k – $41k per year (Estimated) • In office • Full-Time • India
DevOps
Terraform
Azure
Kubernetes
Cybersecurity
Prisma Cloud
Microsoft Defender
Wiz
Zero Trust
Microsoft Defender for Cloud
Microsoft Entra ID
Apply
$85k – $105k per year • Hybrid • 3+ years exp • Bachelor's Degree • Tarrytown
Design
Adobe Photoshop
Figma
Sketch
Adobe After Effects
Apply
≈ $80k – $170k per year (Estimated) • In office • Full-Time • 5+ years exp • Sydney
Cybersecurity
Microsoft Entra ID
Management
Google Workspace
Marketing
Salesforce
Zendesk
Apply
≈ $52k – $107k per year (Estimated) • In office • Full-Time • Kraków
Python
JavaScript
TypeScript
Databases
PostgreSQL
Weaviate
Chroma
pgvector
Pinecone
AI/ML
Claude
Model Context Protocol
Embeddings
Function Calling
AI Agents
LLM
RAG
LLM Guardrails
Tool Use
DevOps
GCP
Azure
CI/CD
AWS
Docker
Cybersecurity
Microsoft Entra ID
Management
Google Workspace
Apply
≈ $50k – $129k per year (Estimated) • In office • Full-Time • 3+ years exp • Paris
DevOps
Azure
Cybersecurity
Okta
Microsoft Entra ID
Management
Jira
Google Workspace
Apply
SMB Account Executive 26 days ago
Remote (likely Brazil) • Full-Time
Apply
In office • Full-Time • Bachelor's Degree • Paris
Cybersecurity
Microsoft Entra ID
Management
Google Workspace
Apply
Talent Growth Lead 1 day ago
≈ $50k – $128k per year (Estimated) • Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Kraków
Apply
≈ $27k – $69k per year (Estimated) • Remote (likely Poland) • Full-Time • 2+ years exp • Bachelor's Degree • Kraków
Python
JavaScript
TypeScript
SQL
Databases
PostgreSQL
MinIO
AI/ML
Airflow
Prefect
NumPy
Frontend
Angular
React.js
CesiumJS
OpenLayers
DevOps
Rest API
Terraform
Ansible
GCP
GitLab CI
Azure
CI/CD
AWS
Docker
Kubernetes
Argo Workflows
GitLab
Amazon S3
Linux
QA
Selenium
Cypress
SpaceTech
GDAL
PySTAC
Apply
$94k – $112k per year • In office • Full-Time • 7+ years exp • Kraków
JavaScript
TypeScript
Node JS
Frontend
React.js
Apply
≈ $29k – $61k per year (Estimated) • Equity • Hybrid • Full-Time • Bachelor's Degree • Kraków
DevOps
Windows Server
Linux
Windows
TCP/IP
Cybersecurity
Wireshark
Management
Agile
Scrum
Apply
≈ $41k – $78k per year (Estimated) • In office • Full-Time • Kraków
Design
Figma
Management
Confluence
Jira
Agile
Scrum
Kanban
Apply
See all jobs
This is one of many
953,927 more open roles from verified company boards, updated every day.