Are you passionate about defending critical digital platforms against sophisticated cyber threats? We are looking for an experienced Senior Security Ops Engineer to lead threat detection, incident response, and security operations across RFE/RL and Pangea-affiliated websites, edge infrastructure, and cloud-native environments. This role focuses on protecting the systems where scraping, malicious bot activity, DDoS attacks, and application-layer threats occur.
Working closely with DevOps, the engineer supports bot management by analyzing how automated threats operate and translating that knowledge into effective detections, controls, and automated response measures.
Key Responsibilities:
- Lead detection and incident response for web and edge threats across Pangea properties, from triage through resolution and post-incident analysis.
- Own bot and scraper defense: analyze automated attack campaigns, tune bot management policies, and continuously counter evasion techniques as adversaries adapt.
- Tune and operate CDN/edge protections in response to evolving attack patterns and automate recurring responses via edge-compute and orchestration.
- Develop, deploy, and continuously refine SIEM detection rules, alerts, and response playbooks for web and cloud-native threats.
- Own container security monitoring and response and integrate CI/CD and Kubernetes telemetry into detection pipelines.
- Build and maintain AI-assisted detection and response automations that enrich alerts, summarize incidents, and speed triage — keeping consequential response actions under human control.
- Convert incident findings and threat-hunt results into durable detection content.
- Collaborate with Vulnerability Ops on container and application findings, and with DevOps and Network engineers on edge and gateway threat signals.
- Support FISMA compliance with primary focus on Incident Response (IR) and Audit (AU) controls.
- Maintain awareness of threats specifically targeting independent media, and prioritize detection work accordingly.
Required Education:
- Information technology, (BA – bachelor’s degree)
- Combination of education and experience
Professional Experience:
- Relevant industry experience with a responsibility for security analysis, design, architecture, and development. 4-6 years (desirable)
- Team management experience 2-3 years (desirable)
- Previous experience working in a multicultural or multinational environment; or experience living and working abroad, preferably in relevant RFE/RL target regions (desirable)
Qualifications:
- Hands-on experience operating a CDN/edge security stack (Akamai or Cloudflare), including WAF tuning, rate limiting, and incident response during active attacks.
- Deep, practical understanding of bot and scraper behavior: how automated clients are built and evade defenses, headless browsers and automation frameworks, residential/rotating proxy networks, credential-stuffing and content-scraping patterns, and audience-metric inflation.
- Experience operating and tuning bot management systems — distinguishing malicious automation from legitimate traffic, and countering evasion as adversaries adapt.
- Traffic fingerprinting and analysis for bot detection and log analysis at scale (ELK/Kibana or similar).
- Experience with edge-compute (EdgeWorkers or equivalent) for security automation and custom logic at the CDN layer.
- Detection engineering experience: developing and tuning SIEM rules, reducing false positives, and mapping coverage to MITRE ATT&CK®.
- Practical container security experience — image and runtime protection, admission/policy controls, and investigating containerized workload incidents — with familiarity with CI/CD pipelines and Kubernetes.
- Coding proficiency (Python, Go, or similar) for detection automation, enrichment, and response tooling; familiarity with SOAR playbook development.
- Practical use of AI/LLM tooling to accelerate detection and response — e.g. summarizing incidents, drafting and refining detection logic, clustering and characterizing anomalous traffic, and accelerating triage — with the judgment to validate AI output before it informs a response action.
- Experience (or clear aptitude) integrating AI into detection and response workflows: AI-assisted alert enrichment, playbook steps, and agentic automations that keep a human in the loop for consequential actions.
Language Requierements:
- English language (proficient), mandatory.
- Broadcast region language (working knowledge), desirable.
Key Qualities:
- Rigorous, manifests integrity, inspires confidence
- Uses threat models instead of assumptions
- Brings well-researched, clear information to guide decision-making
- Understands how individual security issues are leveraged in an attack
- Dissects and resolves complex security challenges with a structured approach
- Coordinates effectively when working with incomplete information.
- Communicates clearly and decisively under active-incident pressure.
Culture and Collaboration Values:
- Fosters a blameless culture where mistakes are learning opportunities.
- Practices inclusivity by guiding and supporting colleagues.
- Paves the safe way for others by building guardrails rather than gates.
- Breaks down barriers by sharing the technical practices.
- Demystifies security concepts and simplifies the complex for others.
- Makes an effort to learn others' workflows before providing input.
Why Join Us?
This is a unique opportunity to protect mission-critical digital platforms that support independent journalism and access to trustworthy information worldwide. You will work at the forefront of web security, bot mitigation, cloud-native defense, and AI-assisted security operations while collaborating with highly skilled international teams in a fast-evolving threat landscape.
Should you be interested in this position please apply by submitting your CV and a cover letter in English.
Appointment against this post is on a local basis only. Please note that for the locally advertised positions preference will be given to those with a work permit and/or a valid residence status in the Czech Republic. Locally recruited employees should reside within commuting distance of Prague, Czech Republic, or be willing to move to take up work. They are not eligible for allowances applicable to candidates who are internationally recruited. Rather, they receive statutory benefits as per Czech labor law. Salary scales for locally recruited employees are based on the best prevailing local conditions. RFE/RL does, however, cover the costs of interview travel and, upon appointment, some relocation costs.
Note: In response to changing operational requirements, RFE/RL retains the discretion not to make an appointment, or to modify the job specifications for a particular vacancy.
By replying to this advertisement or sending your CV and/or other personal data to RadioFreeEurope/RadioLiberty, you are agreeing to having your data saved and managed by employees of the HR department of the company for possible future reference in full accordance with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) GDPR and Act No 110/2019 Coll., on personal data processing. This agreement may only be withdrawn by a written revocation and remains valid until that date. However no longer than 5 years.
Odpovědí na tento inzerát či zasláním Vašeho životopisu a případných dalších osobních materiálů do společnosti RadioFreeEurope/RadioLiberty dáváte souhlas ke zpracování a uchování Vašich osobních údajů dle Nařízení Evropského parlamentu a Rady (EU) 2016/679 ze dne 27. dubna 2016 o ochraně fyzických osob v souvislosti se zpracováním osobních údajů a o volném pohybu těchto údajů a o zrušení směrnice 95/46/ES (obecné nařízení o ochraně osobních údajů), dále jen GDPR a zákona č. 110/2019 Sb., o zpracování osobních údajů. Tento souhlas platí až do jeho odvolání písemnou formou, maximálně však po dobu 5 let.
Privacy Notice for RFE/RL Job Applicants
RFE/RL, Inc. is a private, nonprofit corporation funded by a grant from the U.S. Congress through the U.S. Agency for Global Media (USAGM). Due to RFE/RL’s special character, the countries in which RFE/RL operates, and the type of work RFE/RL performs, it is RFE/RL's obligation to verify the accuracy of information provided by each applicant in order to ensure the safety and security of our employees and workplace. RFE/RL must ensure that everybody who advances to the final stage of the selection process for a position at RFE/RL and who wishes to enter into an employment relationship with RFE/RL must undergo pre-employment background check.
With respect to the above, RFE/RL informs you, as an applicant, that your employment at RFE/RL is contingent on the successful completion of pre-employment check.
Therefore after your acceptance of RFE/RL‘s offer letter, you will be subject of pre-employment check (performed by external Czech entity). Detailed information about collection and processing of your personal data in this matter will be provided to you together with the offer letter.
Privacy Notice for RFE/RL Internship or Fellowship Applicants
The process described above largely applies to applicants for internships and fellowships as well – simply replace the word “employment” with “internship” or “fellowship” as applicable.