UPSTARS is a product IT company where both people and brands take off 🚀 Our main focus is tech solutions and B2B services for international clients. We launch award-winning iGaming projects that shine bright in industry rankings ✨
And yes — supporting a transparent, legal Ukrainian market is a must. That’s why we became the third company in Ukraine to receive a B2B license for providing iGaming services.
In 2026, we’re scaling fast — both projects and our dream team. So now we’re looking for a Middle Office Manager to join our Workplace Experience crew and help make magic happen.
- build a centralized Security Operations operating model: define areas of responsibility, process owners, SLAs, and processes for alert handling, incident management, escalations, post-incident reviews, and reporting;
- design and implement the foundation for SIEM / Log Management: centralized log collection, logging requirements, log parsing and normalization, retention policies, access controls, log delivery monitoring, and audit-ready logging coverage;
- build a detection engineering process: develop, maintain, and regularly review detection rules for authentication, IAM, cloud infrastructure, Kubernetes, Git, CI/CD, databases, endpoints, and application-level events;
- develop the incident response process: create response playbooks for common security incidents, perform initial analysis, containment, eradication, recovery, evidence collection, timeline analysis, and implement post-incident improvements;
- automate routine SecOps processes: ticket creation, alert enrichment, context collection, stakeholder notifications, device isolation, account blocking, and other response actions;
- collaborate with Service Desk and IT teams to implement baseline endpoint security controls: MDM, disk encryption, firewalls, OS patching, device compliance, remote wipe, EDR / XDR or antivirus coverage, and controls for high-risk and unmanaged devices;
- collaborate with Engineering, Platform, IT, Access Management, Legal / Compliance, and management teams on logging, incident response, endpoint controls, vulnerability management, policies, procedures, and audit evidence preparation.
- 5+ years of hands-on experience in Security Operations / Security Engineering, with a focus on building or developing SecOps processes in production environments;
- hands-on experience implementing or administering SIEM and log management solutions: log collection, normalization, parsing, retention management, event correlation, alerting, and dashboarding; experience with Elastic Security, Wazuh, Splunk, Datadog Security, or similar solutions;
- experience working with cloud and infrastructure activity logs: AWS CloudTrail, GuardDuty, Security Hub, EKS Audit Logs, VPC Flow Logs, WAF logs, VPN logs, and authentication logs;
- experience developing detection rules, correlation rules, and alerting logic for real-world security scenarios rather than relying solely on predefined templates; practical understanding of MITRE ATT&CK, common attack techniques, detection coverage, and the difference between noisy alerts and actionable alerts;
- understanding of the incident response lifecycle: preparation, detection, initial analysis, containment, eradication, recovery, and post-incident review;
- experience with EDR / XDR / antivirus solutions such as Bitdefender, CrowdStrike, Microsoft Defender, SentinelOne, or similar tools;
- experience with MDM and endpoint security across macOS, Windows, or Linux: disk encryption, firewalls, OS patching, device compliance, and remote wipe;
- practical understanding of authentication, authorization, IAM events, network security, and common attacker behavior patterns;
- strong automation and scripting skills in Python, Bash, or Go for log processing, alert enrichment, API integrations, reporting, and incident response workflows;
- ability to work independently, build processes from scratch, prioritize effectively, collaborate across teams, and communicate incidents or logging requirements clearly to engineers, management, and compliance teams.
- experience in gambling, fintech, or other regulated industries;
- hands-on experience with PCI DSS, particularly Requirements 10 and 12, audit logging, and incident response evidence preparation;
- experience building SecOps / SOC processes from scratch or significantly improving existing processes;
- experience with SOAR solutions or security automation platforms;
- experience with Cloudflare Access, Zero Trust approaches, VPN security, or device posture checks;
- experience with basic digital forensics, phishing response, endpoint timeline analysis, evidence preservation, email security logs, and investigation of user-reported security incidents.
- team spirit – we work, celebrate, and make an impact together.
- positivity – we enjoy what we do and love feedback, great vibes, and cool challenges.
- opportunities – clear career paths, performance reviews, mentoring, and personal growth programs.
- courage – we take on star-level challenges and ambitious goals.
- openness – we talk straight, value feedback, and encourage proactivity.
- innovation – we build tech solutions from scratch and automate routine stuff to focus on growth.
- freedom over bureaucracy – less red tape, more action.
- work wherever you feel comfortable and safe — from our hubs in Kyiv and Warsaw or remotely;
- 20 paid days off, public holidays, and sick leave — we’re all about work-life balance;
- health insurance at top clinics and coverage for psychologist sessions through the Pleso platform;
- Benefit Café — get a monthly allowance to spend on your interests, hobbies, sports, and more;
- events — join workshops, team-building activities, and company events;
- learning tailored to your needs — an individual budget for courses, corporate English classes, workshops, and access to an online library.
❗️We don’t work with clients who operate in Ukraine.❗️We don’t cooperate with any clients from the aggressor country or russian-language markets.
If our values vibe with you — let’s meet!