IAM / Identity Security Analyst

Walk into a client's environment, map what's there, design what should be — and build it. That's the job. Presales activities and technical consultations are part of the role.

Prague-based, remote-friendly, permanent contract — freelance possible.

75 000–110 000 CZK/month + 20 % annual bonus.

I'm interested

Job Type

Permanent
Contract

Job type

Full time

Salary

75.000 - 110.000 CZK

Location

Hlavní město Praha
Hybrid

ID

STQ_525_JOB


About our client

International technology group with 30+ years in the market, 800+ professionals, and offices across Central and Eastern Europe. They deliver projects in IT infrastructure, data centres, cloud solutions, and cybersecurity.
The company is growing — clients are expanding their demand, new projects are coming in, and there's space for new competencies. The Cyber Security / IAM division currently works heavily with the IdStory platform, but the environment includes other IAM/IDM solutions too. They need someone who can handle the full cycle from analysis to implementation.

Why This Role Exists Now:
Client demand for identity security is growing. The IAM division is expanding its project portfolio and needs someone who can own the full delivery cycle — from analysis through architecture to go-live.
There's space for new competencies and platforms beyond IdStory. The right person can shape what the IAM practice looks like going forward.

Job description

Role / Mission:
You own the full cycle — from the first client workshop through architecture to go-live. You walk into a client's environment, map what's actually there, ask the right questions, pull the data together into a document, and design a new architecture. Then you implement it.
You're an analyst and implementer in one — not someone who waits for a spec.
After 12 months, this is what good looks like: completed projects, clients who trust you, and working identity integrations in real environments.

Key Responsibilities:
— You analyse customer requirements and design IAM/IDM architecture
— You implement and integrate identity solutions into client environments
— You handle incidents and operational support within SLA — not as the core of your work, but as part of it
— You create technical documentation — actually useful materials, not formal paperwork
— You provide technical consultations to clients
— You contribute to presales — solution proposals, presentations, technical input for bids
— You work with sales, presales, support, and delivery teams

What This Role Is NOT:
— Not AD administration — you won't be resetting passwords and creating accounts
— Not a pure operations role — SLA tickets are part of the job, but not the core
— Not an isolated position — client and team communication is key

Operating Model:
Prague-based, remote-friendly. More time in the office during onboarding. After that, remote is possible — but you're expected at the office or client sites as needed. Most of the business is in and around Prague, so a reasonable commute matters. No 24/7 on-call. Permanent contract preferred, freelance possible. Czech or Slovak proficiency required. Direct report: Head of Network & Security division.

Requirements

What Matters Most:
— IAM/IDM experience — minimum 3–5 years in IT security / IAM. Real implementation experience, not just operations
— IAM platforms — IdStory, SailPoint, One Identity, Entra ID, Okta, or similar. Knowing one superficially isn't enough
— Client-facing communication — analysis, consultations, presenting solutions. This is non-negotiable
— Integration and APIs — REST, SOAP, GraphQL. You know how to connect systems
Fluent Czech or Slovak required. English at a level where you can handle a normal working discussion.

Nice to Have:
— SQL and databases — you work with data, not just look at GUIs
— Scripting (Groovy, PowerShell, Python)
— Basic Linux knowledge
— Identity governance concepts and identity lifecycle management
— Experience with HR systems and their integration with IAM
These are nice to have — not hard filters.

Offer & Terms

Offer & Terms:
— 75 000–110 000 CZK/month + 20 % annual bonus. Freelance possible
— Company laptop + phone
— Multisport card · Employer pension contribution (DDS) · HW/SW purchase allowance · Language courses · Financial bonuses for life events (birth of a child, wedding) · Company events, team buildings, sports activities · Extra days off
— Certification support — IAM/security certifications, vendor training budget

More information

More Information:
Interested? Apply or get in touch:
| linkedin.com/in/jirisoljak

No CV needed — a LinkedIn profile and a few sentences about yourself is enough.

You'll speak directly with a senior IT recruiter with hands-on IT background — 450+ hires. A relevant conversation without the HR fluff.

Process:
— Short intro call (15–30 min)
— Maximum 2 rounds — if there's a fit, a decision can come after the first one
— In-person meeting before the final decision
— You'll know where you stand at every step

EU work authorization required. No visa sponsorship.

I'm interested

Similar jobs


Senior Middleware Engineer

Location

Hlavní město Praha
Hybrid

Job Type

Permanent

Field

Networks / Security

Salary

90.000 - 105.000 Kč

This is the global IT arm of one of the world's largest logistics companies — over 5,600 IT professionals across continents, keeping the technology backbone running behind a business that moves shipments through hundreds of countries. The Prague office is one of the group's key IT hubs, and along with locations in Malaysia, India, Germany and the Americas, it holds Great Place to Work certification. The philosophy here is simple: digitalisation should work quietly in the background. The messaging and middleware layer is exactly what keeps communication between hundreds of internal systems running — and this team is still growing.— Middleware background — hands-on IBM MQ experience, or a strong generic middleware background (JBoss, Apache, WebLogic/WebSphere) with willingness to grow into IBM MQ — Linux — RedHat experience in a production environment — Independence under pressure — ability to work independently and prioritise when handling incidents — English — advanced, spoken and written, for daily cross-region communication No IBM MQ experience yet? If the middleware fundamentals and Linux are solid, we still want to talk. Nice to Have: — Kafka — Windows Server, OpenShift — Basic Microsoft Azure — Experience with SFTP and related transfer processes — Experience escalating to vendors (IBM, Oracle, Red Hat)You're part of an expert team for the middleware and messaging layer — IBM MQ, Kafka, WebLogic, WebSphere Application Server, Tomcat, JBoss, Apache, IIS — plus the virtualisation and infrastructure layer underneath. You handle what didn't get fixed one level down: a stuck queue in IBM MQ, a crashed application server, a bug that needs escalating straight to the vendor. It's hands-on technical work with real impact — without you, communication between dozens of internal systems simply doesn't run. Key Responsibilities: — You diagnose and resolve non-trivial problems across middleware platforms — the stuff lower-level support couldn't crack — You get into the virtualisation and infrastructure layer underneath the applications, not just the middleware itself — You work with other IT teams on harder troubleshooting that goes beyond middleware — You escalate to vendors (IBM, Oracle, Red Hat) for bugs and security fixes, and you see it through to resolution — You pass on what you learn — you know where the next problem will show up, before it does What This Role Is NOT: — The Prague office is part of the deal — this isn't a remote role — On-call rotates between colleagues and only covers weekends — nobody's chasing you on weekdays Operating Model: Follow-the-sun team across Asia, Europe and the US, with on-call on a rotation, weekends only. Based in Prague, hybrid — 2 days on-site, 3 days home office per week, with flexible hours. English is the working language for cross-region collaboration. The team manager has the same technical background — started out as a middleware/Unix engineer, now runs the global messaging team.Interested? Apply or reach out — no CV needed, your LinkedIn and a few lines about your experience are enough. We reply to everyone within two business days. | linkedin.com/in/jirisoljak You'll speak directly with a senior IT recruiter with hands-on technical background — a relevant conversation, no HR fluff, no ghosting. Open only to candidates eligible to work in the EU without visa sponsorship, residing long-term in the Czech Republic, with proficiency in Czech or Slovak.

Network Security Engineer / Architect (NDR)

Location

Hlavní město Praha
Hybrid

Job Type

Permanent
Contract

Field

Networks / Security

Salary

90.000-140.000 CZK

Česká technologická společnost specializovaná na kybernetickou bezpečnost, která více než deset let poskytuje služby v oblasti bezpečnostního monitoringu, detekce hrozeb a provozu SOC. Pokrývá celý cyklus bezpečnostních řešení – od architektonického návrhu a implementace, přes migrace a integrace, až po dlouhodobý provoz, konzultační podporu a rozvoj bezpečnostních služeb. Tým odborníků pracuje napříč doménami SIEM, SOAR, EDR/XDR, NDR, Data Security, network visibility, threat hunting a vulnerability & patch managementu. Technologicky staví na širokém portfoliu platforem, například IBM QRadar, Palo Alto XSIAM/XDR ekosystému, Fortinet SecOps, SentinelOne, Greycortex nebo Flowmon, doplněných o vlastní nástroje a interní know-how. Přístup společnosti je postavený na kombinaci Threat Intelligence, Purple Teamingu a proaktivního vyhledávání hrozeb. Projekty probíhají v prostředí velkých enterprise organizací i subjektů kritické infrastruktury, s důrazem na odbornou kvalitu, technologickou nezávislost a úzkou spolupráci se zákazníky.• Praktická zkušenost s návrhem, implementací nebo provozem řešení typu NDR / Network Detection & Response. • Silná orientace v síťových technologiích – TCP/IP, routing, switching, VLAN, VPN, firewalling, DNS, proxy, load balancers. • Schopnost analyzovat síťový provoz (PCAP, NetFlow/IPFIX, metadata, TLS handshake, DNS anomálie). • Zkušenost s některou z NDR platforem (např. Darktrace, Vectra, ExtraHop, Corelight, Cisco Secure Network Analytics nebo obdobné řešení). • Schopnost navrhovat architekturu sběru síťových dat (SPAN/TAP, flow export, cloud traffic mirroring). • Tvorba a ladění detekční logiky nad síťovou telemetrií (anomálie, laterální pohyb, C2 komunikace, exfiltrace dat). • Orientace v MITRE ATT&CK a schopnost mapovat síťové indikátory na konkrétní techniky útoku. • Zkušenost s integrací NDR do SIEM / XDR ekosystému a definice korelačních scénářů. • Schopnost vést technickou diskusi se zákazníkem – návrh detekční strategie, umístění senzorů, optimalizace viditelnosti. • Zkušenost s incident analysis na síťové vrstvě (threat hunting, forenzní analýza komunikace). • Přehled v oblasti šifrování a jeho dopadu na viditelnost (TLS inspection, JA3 fingerprinting, metadata-based detection). • Schopnost pracovat samostatně a nést odpovědnost za rozvoj NDR kompetence. • Angličtina pro technickou komunikaci.Náplň práce • Návrh a rozvoj řešení v oblasti Network Detection & Response (NDR) a network visibility, včetně posouzení vhodnosti technologií (např. Flowmon, Greycortex a další) a jejich integrace do širší bezpečnostní architektury. • Architektonický návrh monitoringu síťové komunikace – segmentace, sběr flow dat (NetFlow/IPFIX), analýza anomálií a laterálního pohybu. • Konzultační podpora zákazníků při návrhu síťové detekční strategie a optimalizaci stávajících bezpečnostních opatření. • Odborné vedení projektů zaměřených na implementaci NDR řešení, integraci do SIEM/XDR ekosystému a rozvoj detekčních use-case scénářů. • Tvorba a validace detekční logiky nad síťovými toky a metadaty, návrh korelačních scénářů napříč síťovou a aplikační vrstvou. • Zapojení do threat hunting aktivit zaměřených na síťové anomálie a pokročilé útoky. • Spolupráce s týmy infrastruktury (network, firewall, proxy, IDS/IPS) při návrhu bezpečnostní architektury. • Integrace NDR výstupů do SIEM a SOAR workflow pro automatizaci reakce. • Podíl na rozvoji Network Detection kompetence v rámci společnosti – technologický směr, metodika, přenos know-how.Pozice je vhodná pro technicky zaměřené specialisty, konzultanty i architekty. Otevřená je zkušeným mediorům i seniorům, kteří mají přehled napříč moderními bezpečnostními technologiemi. Pozice je nabraná přímo s vedením společnosti a technickými experty, takže dostanete přesné informace o reálném fungování týmu i používaných technologiích. Zaujalo? Ozvěte se! Výběrovým procesem vás provede seniorní IT recruiter s reálnou technickou a doménovou zkušeností – žádné obecné fráze, ale věcná a profesionální debata. This opportunity is open only to candidates based in the Czech Republic with valid EU work authorization and a registered EU freelance/business license (B2B). No visa sponsorship is available.

IT jobs