UPSTARS is a product IT company where both people and brands take off 🚀 Our main focus is tech solutions and B2B services for international clients. We launch award-winning iGaming projects that shine bright in industry rankings ✨
And yes — supporting a transparent, legal Ukrainian market is a must. That’s why we became the third company in Ukraine to receive a B2B license for providing iGaming services.
In 2026, we’re scaling fast — both projects and our dream team. So now we’re looking for a Middle Office Manager to join our Workplace Experience crew and help make magic happen.
- build a centralized Security Operations operating model: define areas of responsibility, process owners, SLAs, and processes for alert handling, incident management, escalations, post-incident reviews, and reporting;
- design and implement the foundation for SIEM / Log Management: centralized log collection, logging requirements, log parsing and normalization, retention policies, access controls, log delivery monitoring, and audit-ready logging coverage;
- build a detection engineering process: develop, maintain, and regularly review detection rules for authentication, IAM, cloud infrastructure, Kubernetes, Git, CI/CD, databases, endpoints, and application-level events;
- develop the incident response process: create response playbooks for common security incidents, perform initial analysis, containment, eradication, recovery, evidence collection, timeline analysis, and implement post-incident improvements;
- automate routine SecOps processes: ticket creation, alert enrichment, context collection, stakeholder notifications, device isolation, account blocking, and other response actions;
- collaborate with Service Desk and IT teams to implement baseline endpoint security controls: MDM, disk encryption, firewalls, OS patching, device compliance, remote wipe, EDR / XDR or antivirus coverage, and controls for high-risk and unmanaged devices;
- collaborate with Engineering, Platform, IT, Access Management, Legal / Compliance, and management teams on logging, incident response, endpoint controls, vulnerability management, policies, procedures, and audit evidence preparation.
- 5+ years of hands-on experience in Security Operations / Security Engineering, with a focus on building or developing SecOps processes in production environments;
- hands-on experience implementing or administering SIEM and log management solutions: log collection, normalization, parsing, retention management, event correlation, alerting, and dashboarding; experience with Elastic Security, Wazuh, Splunk, Datadog Security, or similar solutions;
- experience working with cloud and infrastructure activity logs: AWS CloudTrail, GuardDuty, Security Hub, EKS Audit Logs, VPC Flow Logs, WAF logs, VPN logs, and authentication logs;
- experience developing detection rules, correlation rules, and alerting logic for real-world security scenarios rather than relying solely on predefined templates; practical understanding of MITRE ATT&CK, common attack techniques, detection coverage, and the difference between noisy alerts and actionable alerts;
- understanding of the incident response lifecycle: preparation, detection, initial analysis, containment, eradication, recovery, and post-incident review;
- experience with EDR / XDR / antivirus solutions such as Bitdefender, CrowdStrike, Microsoft Defender, SentinelOne, or similar tools;
- experience with MDM and endpoint security across macOS, Windows, or Linux: disk encryption, firewalls, OS patching, device compliance, and remote wipe;
- practical understanding of authentication, authorization, IAM events, network security, and common attacker behavior patterns;
- strong automation and scripting skills in Python, Bash, or Go for log processing, alert enrichment, API integrations, reporting, and incident response workflows;
- ability to work independently, build processes from scratch, prioritize effectively, collaborate across teams, and communicate incidents or logging requirements clearly to engineers, management, and compliance teams.
- experience in gambling, fintech, or other regulated industries;
- hands-on experience with PCI DSS, particularly Requirements 10 and 12, audit logging, and incident response evidence preparation;
- experience building SecOps / SOC processes from scratch or significantly improving existing processes;
- experience with SOAR solutions or security automation platforms;
- experience with Cloudflare Access, Zero Trust approaches, VPN security, or device posture checks;
- experience with basic digital forensics, phishing response, endpoint timeline analysis, evidence preservation, email security logs, and investigation of user-reported security incidents.
- Team spirit – we work, celebrate, and make an impact together.
- Positivity – we enjoy what we do and love feedback, great vibes, and cool challenges.
- Opportunities – clear career paths, performance reviews, mentoring, and personal growth programs.
- Courage – we take on star-level challenges and ambitious goals.
- Openness – we talk straight, value feedback, and encourage proactivity.
- Innovation – we build tech solutions from scratch and automate routine stuff to focus on growth.
- Freedom over bureaucracy – less red tape, more action.
- Work where you feel safe and comfortable — in our offices or remotely.
- Official employment in Ukraine or Poland — we’ll help with all the paperwork.
- 20 paid vacation days, national holidays, and sick leaves — we believe in work-life balance.
- Medical insurance at top clinics and psychologist coverage via Pleso.
- Benefit Café – spend your monthly allowance on hobbies, sports, or anything you love.
- Fun events, workshops, team buildings, and corporate parties.
- Learning budget, corporate English, workshops, and online library access.
❗️We don’t work with clients who operate in Ukraine.❗️We don’t cooperate with any clients from the aggressor country or russian-language markets.
If our values vibe with you — let’s meet!