Technical project manager (Security)

KeepitKraków, Lesser PolandOn-siteFull-timeStaff, 8–12 yearsListed 3 hours ago

Apply now

About this role

About the role

The security operations center (SOC) at Keepit needs someone who can turn operational priorities into planned, tracked, and delivered work. This role sits at the intersection of project management and security operations — keeping daily operations, the annual security roadmap, coverage scheduling, and incident response coordinated and moving forward. The role has no direct reports. You will, however, lead the team's on-shift rotation and its operating cadence, so it carries real coordination authority across the SOC.

You will:

Project delivery

- Support daily security operations in deploying and implementing operational security priorities.
- Own the security roadmap: ensure the team stays on track to complete annual roadmap commitments.
- Lead communication, planning, and coordination with other teams and stakeholders.
- Run the SOC's recurring cadence: backlog refinement, sprint and roadmap reviews, shift handover syncs, and stakeholder check-ins.
- Maintain and prioritize the SOC's project backlog in coordination with security engineering and detection engineering leads.
- Track project risks, dependencies, and blockers; escalate when needed.
- Manage vendor and tool procurement timelines, including renewals, proofs of concept (PoCs), and onboarding of new security tools. You own the process and the vendor relationships; the security budget stays with SOC leadership.
- Own documentation of processes, standard operating procedures, and runbooks, keeping them current rather than created once and left stale.
- Report roadmap and project status to leadership.
- Manage change requests and change management for production security tooling changes.

Measuring team maturity

- Define and track a maturity model, for example mapped to the NIST Cybersecurity Framework (CSF), MITRE ATT&CK coverage, or a custom capability matrix.
- Own operational KPIs and metrics: mean time to detect (MTTD), mean time to respond (MTTR), alert-to-incident ratio, false positive rate, and detection coverage by use case.
- Run periodic gap assessments against the maturity model and turn findings into roadmap items.
- Coordinate tabletop exercises and purple team engagements, and track remediation of findings.
- Benchmark against industry peers or frameworks annually.

Scheduling
- Ensure schedule coverage for phishing triage and security information and event management (SIEM) monitoring.
- Manage the on-shift rotation for incident response.
- Plan for PTO and holiday coverage gaps well in advance.
- Maintain a documented shift handover process between shifts.
- Extend scheduling oversight to other monitoring duties as needed, such as vulnerability scanning cadence and threat intel review.

Incident management
- Participate in incident response and coordination.
- Own and maintain incident response playbooks and runbooks.
- Facilitate post-incident reviews (blameless retrospectives) and track remediation actions to closure.
- Track incident metrics and produce leadership-facing incident reports.
- Manage escalation paths and ensure the right people and teams are looped in during major incidents.
- Coordinate with legal, compliance, and communications teams on incidents with regulatory or public exposure.

Stakeholder and vendor management

- Serve as the single point of contact for cross-functional teams needing SOC engagement, including IT, legal, compliance, and engineering.
- Manage relationships with security tool vendors and external partners, from evaluation and proof of concept through onboarding and renewal.

What success looks like

By the end of your first 90 days:

- The SOC backlog is prioritized, current, and reviewed on a predictable cadence with the security engineering and detection engineering leads.
- Annual roadmap commitments are broken into tracked work with owners, dependencies, and dates, and leadership has a status view it trusts.
- Coverage for phishing triage and SIEM monitoring is planned ahead, including PTO and holiday gaps, with a documented handover between shifts.
- You have facilitated at least one post-incident review and tracked its actions to closure.

Tools you'll work with

- You will not administer the security platforms — engineering owns those. You do need to be a power user of the delivery and documentation tooling, and comfortable enough in the security stack to read what it tells you.

Delivery and documentation

- Jira for the backlog, sprints, and roadmap tracking, including boards, workflows, and dashboards. Power-user level expected.
- Confluence for processes, standard operating procedures (SOPs), runbooks, and decision records. Power-user level expected.
- Figma for process diagrams and workflow mapping.

Ticketing and case management

- Two IT service management platforms are in use across the company today, and part of this role is helping decide which one the SOC standardizes on. We are also standing up a dedicated case management tool for security investigations. Experience running work through a service management platform matters more than experience with any specific product.

Security monitoring and detection

- Wazuh for SIEM, Microsoft Defender XDR for endpoint detection and response, and Tenable One for attack surface management and vulnerability management.
- Working familiarity is enough here: you should be able to follow detection coverage, alert volumes, and scan cadence, and hold a credible conversation with the engineers who run these tools. Operator-level depth is not expected.

Reporting, communication, and vendor tracking

- Jira dashboards for delivery status, and PowerPoint for leadership decks.
- Microsoft Teams for day-to-day coordination, and email for external vendors and partners.
- Confluence and spreadsheets for renewal timelines, PoC tracking, and vendor contacts.

About you

Must-haves:

- 5+ years managing technical projects or programs, ideally in security, infrastructure, or IT operations.
- Proven ownership of a backlog and a roadmap end to end: prioritization, dependency tracking, and delivery against dated commitments.
- A working understanding of security operations — how detection, alert triage, incident response, and vulnerability management fit together. You do not need to have run a SOC yourself, but you do need enough fluency to hold a credible conversation with the engineers who do.
- Power-user fluency in Jira and Confluence, or the ability to get there fast.
- Experience coordinating coverage schedules or on-call rotations, including planning around absence and handover.
- Strong written English, and the ability to write documentation people can follow and will keep using.

Nice-to-haves:

- Exposure to a security maturity or coverage framework such as the NIST CSF or MITRE ATT&CK.
- Experience facilitating post-incident reviews, tabletop exercises, or purple team engagements.
- Experience selecting or rolling out an IT service management platform.
- Familiarity with change management for production systems.
- Vendor management or procurement coordination experience.

About us

At Keepit, we're on a mission to make cloud data protection simple, reliable, and built to last. Our platform provides customers with an immutable, historical archive of their data in systems such as Microsoft 365, Google Workspace, Salesforce, Entra ID, Dynamics 365, and Zendesk. We protect our customers against everything, from ransomware to simple accidents — and we pride ourselves on backing up hundreds of petabytes of data in a performant, reliable, and predictable way.

As we collaborate across locations, English is our primary language. Please submit your CV in English to support the review process.

We offer:

- Official employment (Umowa o pracę).
- 4 additional working days of vacation per full calendar year.
- 3 days of internal sick leave without a doctor's note.
- Health and life insurance.
- Employee Capital Plan (PPK).
- Multisport card compensation.
- Coverage of professional training, meetups, and conferences.
- English-speaking club with native speakers and Polish language classes.
- Internet and glasses reimbursement.
- Office in Krakow city centre (Dluga 72) with beverages, fruit, and snacks.
- Regular team-building events, winter and summer parties.

We kindly ask you not to provide us with any sensitive categories of personal data when applying for a job with us.   When applying for the vacancy, Keepit will process your personal data, and therefore we recommend that you also read our privacy policy , which describes our processing of personal data and your rights as a data subject.

If you notice any misconduct or irregularities that fall within the scope of our whistleblowing procedure, please click here to report them.