Manager, Security Operations in Prague, Nebraska at Ataccama
Explore Related Opportunities
Job Description
As Manager, Security Operations you will lead the hands-on, defensive security of Ataccama's product and cloud environment. Reporting to the CISO, you will own detection and incident response, vulnerability management, and cloud security posture across all of our deployment models, and lead a small, highly autonomous team of security specialists. Beyond keeping operations running, you will identify, propose, and execute security improvement initiatives end to end — from new WAF deployment as our ingress evolves to plugging product audit logs into our SIEM. We are becoming an AI-native company, and you will be expected to adopt AI tooling in your own work and help the security function do the same. This is a delivery role in an environment that runs on shared ownership and influence, not just formal authority — you will land security outcomes primarily by building credibility and alignment across engineering, platform, and IT, not only by issuing mandates.
- Detection & Incident Response: Own security monitoring, detection, and incident handling end to end. Lead response across teams, turn incident learnings into preventive improvements, and manage the relationship with our external SOC partner.
- Vulnerability Management: Run vulnerability management across the product and environment — triage, risk-based prioritization, remediation orchestration, and customer-facing CVE response — and mature it into a sustainable, de-concentrated program.
- Cloud Security Posture: Own cloud-native security posture and runtime protection at scale (multi-cloud, Kubernetes), and monitor our external attack surface across multi-tenant SaaS, single-tenant, and customer-managed deployments.
Infrastructure & IT Security: Oversee the operational and corporate security surface — endpoint, infrastructure, and IT security operations. - Cross-Team Delivery: Drive security work through teams you don't own — engineering, platform, cloud/ops, and IT — sequencing and tracking multi-team initiatives to completion in an agile environment without formal project-management processes.
- Team Leadership: Lead and develop a small team of security specialists. Set clear, verifiable expectations, delegate effectively, and report upward on milestones and progress rather than low-level detail.
- Tooling & Program Maturity: Drive owned initiatives — SOC enablement, vulnerability-management maturity, detection engineering, and security tooling — into tangible, visible outcomes on committed timelines.
- Customer & Technical Assurance: Represent security on technical matters — vulnerabilities, pentest findings, CVE response, and the technical sections of customer security questionnaires and audits.
- 7+ years in technical security, with demonstrable depth in security operations and incident response; prior team leadership or management experience.
- Strong, hands-on background across the security stack (CISSP-level breadth), with incident response as a sharp specialist edge. Relevant certifications (e.g. GCIH, GCIA, cloud-security certifications) are useful evidence but not required.
- Cloud security experience across major providers and container orchestration (Kubernetes) is welcome, along with familiarity across SaaS, single-tenant, and hybrid deployment models.
- A track record of driving security outcomes through teams you don't directly control, using influence and credibility rather than formal authority.
- Strong people-leadership skills — specifically at setting expectations, delegating and managing semi-formal projects, and developing autonomous senior specialists and junior talent.
- Comfort operating without heavy process or project-management scaffolding; you supply the structure — clear milestones, visible status, active dependency-chasing.
- Excellent communication skills and the emotional intelligence to thrive in a flat, low-deference, multicultural engineering culture.
- Fluent English; Czech or Slovak is an advantage.