{"id":1426888,"url":"https://alion.io/job/keepit-technical-project-manager-security","title":"Technical Project Manager (Security)","company":{"id":8333,"name":"Keepit","domain":"keepit.com","url":"https://alion.io/company/keepit","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Teamtailor","truth_index":{"grade":"A","score":90,"open_postings":5,"ghost_share":0,"stale_share":0.2,"repost_share":0,"time_to_fill_p50_days":84,"computed_at":"2026-09-30T05:45:00Z"}},"role":"Leadership","role_family":"Leadership","seniority":null,"employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Kraków, Poland"],"countries":["PL"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":69000,"max_usd":148000,"period":"year","method":"role_country_seniority_unknown","sample_n":45},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Confluence","optional":false},{"name":"Figma","optional":false},{"name":"Incident Management","optional":false},{"name":"Jira","optional":false},{"name":"Microsoft Defender","optional":false},{"name":"Microsoft Teams","optional":false},{"name":"SIEM","optional":false},{"name":"Wazuh","optional":false},{"name":"Google Workspace","optional":true},{"name":"Microsoft Entra ID","optional":true},{"name":"NIST CSF","optional":true}],"status":"live","first_seen_at":"2026-09-28T07:57:04Z","employer_posted_date":"2026-09-28","last_verified_at":"2026-09-29T07:55:17Z","board_verified":true,"closed_at":null,"days_open":1,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":1},"description":"About the role\nThe security operations center (SOC) at Keepit needs someone who can turn operational priorities into planned, tracked, and delivered work. This role sits at the intersection of project management and security operations - keeping daily operations, the annual security roadmap, coverage scheduling, and incident response coordinated and moving forward. The role has no direct reports. You will, however, lead the team's on-shift rotation and its operating cadence, so it carries real coordination authority across the SOC.\nYou will:\nProject delivery\nSupport daily security operations in deploying and implementing operational security priorities.\n\nOwn the security roadmap: ensure the team stays on track to complete annual roadmap commitments.\n\nLead communication, planning, and coordination with other teams and stakeholders.\n\nRun the SOC's recurring cadence: backlog refinement, sprint and roadmap reviews, shift handover syncs, and stakeholder check-ins.\n\nMaintain and prioritize the SOC's project backlog in coordination with security engineering and detection engineering leads.\n\nTrack project risks, dependencies, and blockers; escalate when needed.\n\nManage vendor and tool procurement timelines, including renewals, proofs of concept (PoCs), and onboarding of new security tools. You own the process and the vendor relationships; the security budget stays with SOC leadership.\n\nOwn documentation of processes, standard operating procedures, and runbooks, keeping them current rather than created once and left stale.\n\nReport roadmap and project status to leadership.\n\nManage change requests and change management for production security tooling changes.\n\nMeasuring team maturity\nDefine and track a maturity model, for example mapped to the NIST Cybersecurity Framework (CSF), MITRE ATT&CK coverage, or a custom capability matrix.\n\nOwn operational KPIs and metrics: mean time to detect (MTTD), mean time to respond (MTTR), alert-to-incident ratio, false positive rate, and detection coverage by use case.\n\nRun periodic gap assessments against the maturity model and turn findings into roadmap items.\n\nCoordinate tabletop exercises and purple team engagements, and track remediation of findings.\n\nBenchmark against industry peers or frameworks annually.\nScheduling\n\nEnsure schedule coverage for phishing triage and security information and event management (SIEM) monitoring.\n\nManage the on-shift rotation for incident response.\n\nPlan for PTO and holiday coverage gaps well in advance.\n\nMaintain a documented shift handover process between shifts.\n\nExtend scheduling oversight to other monitoring duties as needed, such as vulnerability scanning cadence and threat intel review.\nIncident management\n\nParticipate in incident response and coordination.\n\nOwn and maintain incident response playbooks and runbooks.\n\nFacilitate post-incident reviews (blameless retrospectives) and track remediation actions to closure.\n\nTrack incident metrics and produce leadership-facing incident reports.\n\nManage escalation paths and ensure the right people and teams are looped in during major incidents.\n\nCoordinate with legal, compliance, and communications teams on incidents with regulatory or public exposure.\n\nStakeholder and vendor management\nServe as the single point of contact for cross-functional teams needing SOC engagement, including IT, legal, compliance, and engineering.\n\nManage relationships with security tool vendors and external partners, from evaluation and proof of concept through onboarding and renewal.\n\nWhat success looks like\nBy the end of your first 90 days:\nThe SOC backlog is prioritized, current, and reviewed on a predictable cadence with the security engineering and detection engineering leads.\n\nAnnual roadmap commitments are broken into tracked work with owners, dependencies, and dates, and leadership has a status view it trusts.\n\nCoverage for phishing triage and SIEM monitoring is planned ahead, including PTO and holiday gaps, with a documented handover between shifts.\n\nYou have facilitated at least one post-incident review and tracked its actions to closure.\n\nTools you'll work with\nYou will not administer the security platforms - engineering owns those. You do need to be a power user of the delivery and documentation tooling, and comfortable enough in the security stack to read what it tells you.\n\nDelivery and documentation\nJira for the backlog, sprints, and roadmap tracking, including boards, workflows, and dashboards. Power-user level expected.\n\nConfluence for processes, standard operating procedures (SOPs), runbooks, and decision records. Power-user level expected.\n\nFigma for process diagrams and workflow mapping.\n\nTicketing and case management\nTwo IT service management platforms are in use across the company today, and part of this role is helping decide which one the SOC standardizes on. We are also standing up a dedicated case management tool for security investigations. Experience running work through a service management platform matters more than experience with any specific product.\n\nSecurity monitoring and detection\nWazuh for SIEM, Microsoft Defender XDR for endpoint detection and response, and Tenable One for attack surface management and vulnerability management.\n\nWorking familiarity is enough here: you should be able to follow detection coverage, alert volumes, and scan cadence, and hold a credible conversation with the engineers who run these tools. Operator-level depth is not expected.\n\nReporting, communication, and vendor tracking\nJira dashboards for delivery status, and PowerPoint for leadership decks.\n\nMicrosoft Teams for day-to-day coordination, and email for external vendors and partners.\n\nConfluence and spreadsheets for renewal timelines, PoC tracking, and vendor contacts.\n\nAbout you\nMust-haves:\n5+ years managing technical projects or programs, ideally in security, infrastructure, or IT operations.\n\nProven ownership of a backlog and a roadmap end to end: prioritization, dependency tracking, and delivery against dated commitments.\n\nA working understanding of security operations - how detection, alert triage, incident response, and vulnerability management fit together. You do not need to have run a SOC yourself, but you do need enough fluency to hold a credible conversation with the engineers who do.\n\nPower-user fluency in Jira and Confluence, or the ability to get there fast.\n\nExperience coordinating coverage schedules or on-call rotations, including planning around absence and handover.\n\nStrong written English, and the ability to write documentation people can follow and will keep using.\n\nNice-to-haves:\nExposure to a security maturity or coverage framework such as the NIST CSF or MITRE ATT&CK.\n\nExperience facilitating post-incident reviews, tabletop exercises, or purple team engagements.\n\nExperience selecting or rolling out an IT service management platform.\n\nFamiliarity with change management for production systems.\n\nVendor management or procurement coordination experience.\n\nAbout us\nAt Keepit, we're on a mission to make cloud data protection simple, reliable, and built to last. Our platform provides customers with an immutable, historical archive of their data in systems such as Microsoft 365, Google Workspace, Salesforce, Entra ID, Dynamics 365, and Zendesk. We protect our customers against everything, from ransomware to simple accidents - and we pride ourselves on backing up hundreds of petabytes of data in a performant, reliable, and predictable way.\nAs we collaborate across locations, English is our primary language. Please submit your CV in English to support the review process.\nWe offer:\nOfficial employment (Umowa o pracę).\n\n4 additional working days of vacation per full calendar year.\n\n3 days of internal sick leave without a doctor's note.\n\nHealth and life insurance.\n\nEmployee Capital Plan (PPK).\n\nMultisport card compensation.\n\nCoverage of professional training, meetups, and conferences.\n\nEnglish-speaking club with native speakers and Polish language classes.\n\nInternet and glasses reimbursement.\n\nOffice in Krakow city centre (Dluga 72) with beverages, fruit, and snacks.\n\nRegular team-building events, winter and summer parties.\n\nWe kindly ask you not to provide us with any sensitive categories of personal data when applying for a job with us. When applying for the vacancy, Keepit will process your personal data, and therefore we recommend that you also read our privacy policy, which describes our processing of personal data and your rights as a data subject.\nIf you notice any misconduct or irregularities that fall within the scope of our whistleblowing procedure, please click here to report them.","description_format":"text","description_chars":8664,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[{"language":"Polish","level":"All levels","optional":false},{"language":"English","level":"All levels","optional":false}]},"benefits":["Life insurance"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Backup & Disaster Recovery"],"lifecycle":[{"event":"open","at":"2026-09-28T23:59:55Z"}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":1,"expected_fill_days":84,"reasons":["conf:21","velocity","win:early"],"computed_at":"2026-09-30T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/keepit-technical-project-manager-security","json_url":"https://alion.io/job/keepit-technical-project-manager-security.json","meta":{"generated_at":"2026-09-30T06:11:29Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4250,"day_limit":5000,"remaining_today":750,"minute_limit":60,"resets_at":"2026-10-01T00:00:00Z"}}}