23. července

Senior SecOps Engineer, Pangea Digital - Radio Free Europe/Radio Liberty - Rádio Svobodná Evropa, Inc.

The mission Of Radio Free Europe/Radio Liberty (RFE/RL) is to promote democratic values by providing accurate, uncensored news and open debate in countries where a free press is threatened and disinformation is pervasive. RFE/RL reports the facts, undaunted by pressure.

Are you passionate about defending critical digital platforms against sophisticated cyber threats? We are looking for an experienced Senior Security Ops Engineer to lead threat detection, incident response, and security operations across RFE/RL and Pangea-affiliated websites, edge infrastructure, and cloud-native environments. This role focuses on protecting the systems where scraping, malicious bot activity, DDoS attacks, and application-layer threats occur.

Working closely with DevOps, the engineer supports bot management by analyzing how automated threats operate and translating that knowledge into effective detections, controls, and automated response measures.

Key Responsibilities:

  • Lead detection and incident response for web and edge threats across Pangea properties, from triage through resolution and post-incident analysis.
  • Own bot and scraper defense: analyze automated attack campaigns, tune bot management policies, and continuously counter evasion techniques as adversaries adapt.
  • Tune and operate CDN/edge protections in response to evolving attack patterns and automate recurring responses via edge-compute and orchestration.
  • Develop, deploy, and continuously refine SIEM detection rules, alerts, and response playbooks for web and cloud-native threats.
  • Own container security monitoring and response and integrate CI/CD and Kubernetes telemetry into detection pipelines.
  • Build and maintain AI-assisted detection and response automations that enrich alerts, summarize incidents, and speed triage — keeping consequential response actions under human control.
  • Convert incident findings and threat-hunt results into durable detection content.
  • Collaborate with Vulnerability Ops on container and application findings, and with DevOps and Network engineers on edge and gateway threat signals.
  • Support FISMA compliance with primary focus on Incident Response (IR) and Audit (AU) controls.
  • Maintain awareness of threats specifically targeting independent media, and prioritize detection work accordingly.

Required Education:

  • Information technology, (BA – bachelor’s degree)
  • Combination of education and experience

Professional Experience:

  • Relevant industry experience with a responsibility for security analysis, design, architecture, and development. 4-6 years (desirable)
  • Team management experience 2-3 years (desirable)
  • Previous experience working in a multicultural or multinational environment; or experience living and working abroad, preferably in relevant RFE/RL target regions (desirable)

Qualifications:

  • Hands-on experience operating a CDN/edge security stack (Akamai or Cloudflare), including WAF tuning, rate limiting, and incident response during active attacks.
  • Deep, practical understanding of bot and scraper behavior: how automated clients are built and evade defenses, headless browsers and automation frameworks, residential/rotating proxy networks, credential-stuffing and content-scraping patterns, and audience-metric inflation.
  • Experience operating and tuning bot management systems — distinguishing malicious automation from legitimate traffic, and countering evasion as adversaries adapt.
  • Traffic fingerprinting and analysis for bot detection and log analysis at scale (ELK/Kibana or similar).
  • Experience with edge-compute (EdgeWorkers or equivalent) for security automation and custom logic at the CDN layer.
  • Detection engineering experience: developing and tuning SIEM rules, reducing false positives, and mapping coverage to MITRE ATT&CK®.
  • Practical container security experience — image and runtime protection, admission/policy controls, and investigating containerized workload incidents — with familiarity with CI/CD pipelines and Kubernetes.
  • Coding proficiency (Python, Go, or similar) for detection automation, enrichment, and response tooling; familiarity with SOAR playbook development.
  • Practical use of AI/LLM tooling to accelerate detection and response — e.g. summarizing incidents, drafting and refining detection logic, clustering and characterizing anomalous traffic, and accelerating triage — with the judgment to validate AI output before it informs a response action.
  • Experience (or clear aptitude) integrating AI into detection and response workflows: AI-assisted alert enrichment, playbook steps, and agentic automations that keep a human in the loop for consequential actions.

Language Requierements:

  • English language (proficient), mandatory.
  • Broadcast region language (working knowledge), desirable.

Key Qualities:

  • Rigorous, manifests integrity, inspires confidence
  • Uses threat models instead of assumptions
  • Brings well-researched, clear information to guide decision-making
  • Understands how individual security issues are leveraged in an attack
  • Dissects and resolves complex security challenges with a structured approach
  • Coordinates effectively when working with incomplete information.
  • Communicates clearly and decisively under active-incident pressure.

Culture and Collaboration Values:

  • Fosters a blameless culture where mistakes are learning opportunities.
  • Practices inclusivity by guiding and supporting colleagues.
  • Paves the safe way for others by building guardrails rather than gates.
  • Breaks down barriers by sharing the technical practices.
  • Demystifies security concepts and simplifies the complex for others.
  • Makes an effort to learn others' workflows before providing input.

Why Join Us?

This is a unique opportunity to protect mission-critical digital platforms that support independent journalism and access to trustworthy information worldwide. You will work at the forefront of web security, bot mitigation, cloud-native defense, and AI-assisted security operations while collaborating with highly skilled international teams in a fast-evolving threat landscape.

Benefity

Vzdělávací kurzy, školení, Příspěvek na dovolenou, Stravenky/příspěvek na stravování, Dovolená 5 týdnů, Zdravotní volno/sickdays, Příspěvek na dopravu, Možnost občasné práce z domova, Příspěvek na penzijní/životní připojištění

O pozici

Typ úvazku:
Práce na plný úvazek
Délka úvazku:
Na dobu určitou
Pracovní vztah:
Pracovní smlouva
Doporučené vzdělání:
Bakalářské
Doporučené jazyky:
Angličtina (Pokročilá)