Apply

Security Engineer

Posted 1 day agoViewed

View full description

📍 Location: Poland

💸 Salary: 13200.0 - 20400.0 PLN per month

🏢 Company: Netguru👥 501-1000Product DesignUX DesignWeb DevelopmentAppsMobileSoftware

🪄 Skills: AWSCloud ComputingCybersecurityGCPAzureMobile testingCI/CDDevOpsRisk Management

Requirements:
  • Can communicate complex technical concepts clearly to both technical and non-technical audiences.
  • Are a proactive problem-solver, able to analyze issues and develop effective solutions.
  • Are highly independent and self-managing, able to prioritize tasks and work with minimal supervision.
  • Are adaptable and flexible, able to quickly learn and adjust to new technologies and threats.
  • Possess a meticulous attention to detail, ensuring accuracy and identifying subtle vulnerabilities.
  • Are a collaborative team player, willing to share knowledge and work effectively with diverse teams.
Responsibilities:
  • Analyze client needs (secure architecture, data flows, user stories, infrastructure) and recommend solutions in client/team meetings.
  • Ensure robust protection across different providers (AWS, Azure, GCP) by leveraging your expertise in network and IT system security
  • Secure networks and systems: configure firewalls, IDS/IPS, VPNs, and secure communication.
  • Perform tests and vulnerability analysis using static/dynamic code analysis and security scanners.
  • Ensure compliance with standards (ISO 27001, PCI DSS, GDPR) and implement aligned security policies.
  • Secure applications: implement "security by design" and apply OWASP Top 10 best practices.
  • Integrate security into DevSecOps: automate security testing and embed controls in CI/CD pipelines.
  • Manage security incidents: monitor, analyze, and respond using log analysis and SIEM tools.
  • Communicate and collaborate with teams, document processes, and explain technical information.
  • Design and conduct risk assessments, identify threats, evaluate impact, and implement mitigation. Integrate risk assessment into the project lifecycle.
Apply

Related Jobs

Apply

📍 Poland

🔍 Entertainment

🏢 Company: Netflix👥 10000-100000

  • 5+ years of experience as a Security Engineer with hands on experience in Digital Forensics and Incident Response (MacOS and Cloud)
  • 2+ years of demonstrated experience in Incident Management as a Security Incident Commander responding to large scale security incidents
  • Hands-on experience analyzing disparate log sources as part of security investigations
  • Python experience and familiarity with deploying code in a continuous integration and continuous delivery, cloud-based environment
  • Actively lead security incident response as an Incident Commander and investigator
  • Apply lessons learned as part of the post-incident review process in order to improve incident handling and resolution

PythonSQLCloud ComputingCybersecurity*NixCI/CDRESTful APIs

Posted 2 days ago
Apply
Apply

📍 Poland

🧭 Full-Time

🔍 Software Development

  • At least 5 years of experience related with security
  • Vast experience with container orchestration platforms like Kubernetes and how to secure them (must-have).
  • You know how to maintain, develop policy for security-focused CNI/Service Mesh (eg. Calico, Cilium).
  • You know how to scan for and manage vulnerabilities at scale.
  • You have experience with Hashicorp Vault.
  • You know why and how to use Terraform and popular CI/CD tools.
  • You know about building scalable and secure production HA environments using AWS.
  • You know your ways around network security services eg. AWS WAF/Cloudflare.
  • You are not afraid of developing tools or scripts in Bash or GO to automate work.
  • Developing and maintaining tools for Global Security in order to deliver vulnerability management platforms for application triaging and continuous compliance
  • Optimize system scalability and cost efficiency
  • Development, monitoring, and maintenance of Kubernetes clusters on several continents.
  • CI / CD development and maintenance.
  • Make sure that all of our services are deployed in a way that makes them highly available.
  • Fixing urgent issues and optimizing performance.
  • Support other team members in their daily work.

AWSBashCloud ComputingKubernetesGoCI/CDRESTful APIsLinuxDevOpsTerraformMicroservicesComplianceFluency in EnglishJSONEnglish communication

Posted 3 days ago
Apply
Apply

📍 Poland

🧭 Full-Time

💸 71635.95 - 107453.92 USD per year

🔍 Software Development

  • Solid understanding and demonstrated expertise managing cloud security controls
  • Experience securing Kubernetes and containersed workloads
  • Experience with Infrastructure-as-Code and associated security validations
  • Experience working with API integrations and developing custom security automation (e.g. Python, Golang, Bash)
  • Strong Linux security experience (hardening, vulnerability management, security alerting, etc.)
  • Experience handling security incidents and performing associated investigative activities in a Linux and cloud-based environment
NOT STATED

AWSPythonBashCloud ComputingCybersecurityGCPKubernetesAPI testingAzureServerlessCI/CDLinuxTerraformAnsible

Posted 6 days ago
Apply
Apply

📍 AMER, EMEA, APAC

🧭 Full-Time

🔍 Security

🏢 Company: asymmetric.re

  • Familiarity and practical experience with Application Security Testing (AST) tools.
  • Proven experience as a consultant, engineer, or auditor, ideally working on/with web applications.
  • Prior experience working with open source development practices.
  • Willingness and aptitude to work with and write in multiple languages, mainly Go, Rust, Python, and JavaScript.
  • Experience with reverse engineering and/or fuzzing.
  • Experience with code reviews.
  • Design and implement security and defense-in-depth controls to prevent and limit vulnerabilities.
  • Develop security tooling and developer workflows to aid in the early detection of vulnerabilities.
  • Collaborate with core contributors to conduct internal security audits of off-chain infrastructure.
  • Harden CI/CD pipelines and constrain the attack surface of off-chain components.
  • Collaborate with core contributors to reduce supply-chain risk.
  • Triage and respond to potential security incidents across all parts of the stack.
  • Work in a diverse decentralized team environment with web3 professionals.
  • Clearly communicate security risks and solutions.
  • Adhere to the highest standards of integrity, trust, and professionalism.

DockerPythonBlockchainCybersecurityJavascriptGoRustWeb3.jsCI/CDRESTful APIsLinuxDevOps

Posted 8 days ago
Apply
Apply

📍 Poland

🧭 Full-Time

💸 24000.0 - 28000.0 PLN per month

🔍 Software Development

🏢 Company: Appfire Technologies, LLC.

  • Degree in Computer Science, Information Security, Engineering, or equivalent experience.
  • 5+ years of experience working in cyber security engineering and/or architecture at a software company.
  • Experience performing security work in a multi-cloud environment is preferred.
  • Experience with at least one vulnerability scanning tool (e.g. Qualys, Rapid7, Wiz, etc.).
  • Experience as a pen tester for web-based applications and familiarity with the OWASP top ten vulnerability categories.
  • Working knowledge of at least one scripting language, Python preferred, and Linux concepts/command-line familiarity.
  • Experience with basic SQL and manipulating large data files preferred.
  • Understanding of key cryptography concepts such as symmetric/asymmetric keys, algorithms, and protocols (PKI, GPG, RSA, x509 certificates, and TLS/SSL).
  • Knowledge of common information security frameworks such as CIS, NIST, ISO 27001 & SOC 2 a plus.
  • Ability to work effectively within a fast-paced, changing environment with high growth.
  • A self-starter with a demonstrated ability to take initiative, who can proactively identify issues/opportunities and recommend actions.
  • Strategic analysis, creative problem-solving, and business judgment are required.
  • Excellent interpersonal and communication skills, including writing skills.
  • Collaborate with Engineering, IT Operations, and DevOps to design, engineer, and support security within our cloud environments, products, and vendor solutions, while promoting DevSecOps.
  • Perform security assessments and penetration testing (manage and perform) on web applications, mobile clients, etc.
  • Enforce continuous security compliance for our Cloud apps and cloud infrastructure.
  • Review and approve controls needed to protect data and technology assets in compliance with policies, regulations, and legal requirements.
  • Support incident response and security operations.
  • Ensure compliance with and support our vulnerability management program, including SCA, SAST, DAST, penetration testing, and bug bounty programs.
  • Provide expertise in the integration efforts of Appfire acquisitions and alignment to information security standards and policies.
  • Implement and maintain information security systems and services to support the Information Security team.

AWSPythonSQLCloud ComputingCybersecurityREST APICI/CDLinuxDevOpsComplianceJSONRisk ManagementScriptingSoftware Engineering

Posted 19 days ago
Apply
Apply

📍 Global

🧭 Full-Time

🔍 Software Development

🏢 Company: OP Labs👥 11-50Developer ToolsIT InfrastructureEthereumSoftware

  • Hands-on technical experience with cloud platforms (e.g., GCP), Kubernetes, Infrastructure-as-Code tools (e.g., Terraform, Ansible) and scripting and automation (e.g., Go, Python)
  • Strong cloud security fundamentals, including secure cloud design, IAM, threat detection & incident response and application & API security
  • Excellent collaboration and communication skills, able to collaborate effectively with a diverse set of stakeholders to drive DevSecOps culture and best practices
  • Exhibit high agency and ownership, you’re someone who likes to get stuff done and drive impactful results
  • Design and implement security controls for our GCP-based cloud environment
  • Automate security in CI/CD pipelines and Infrastructure-as-Code (IaC)
  • Collaborate with the Platforms team and wider engineering organization to drive a security-first culture and embed security best practices throughout the SDLC
  • Stay up-to-date with emerging threats and cloud security trends

PythonCloud ComputingCybersecurityGCPKubernetesAPI testingGoCI/CDDevOpsTerraformAnsibleScripting

Posted 21 days ago
Apply
Apply

📍 AMER/EMEA/APAC

🧭 Full-Time

🔍 Security

🏢 Company: asymmetric.re

  • Strong desire to understand how things work, and the ability to quickly absorb new information.
  • Familiarity with at least one or more Rust-based smart contract platforms, including Solana, Cosmwasm, NEAR (strong preference to pre-existing Solana experience).
  • Proven experience as either a consultant, engineer, bug bounty hunter or auditor.
  • Prior experience working with open source development practices.
  • Willingness and aptitude to learn multiple Rust-based runtimes.
  • Understanding of blockchain infrastructure technologies, such as bridging or oracles.
  • Prior experience with reverse engineering and/or fuzzing.
  • Prior experience with code reviews
  • Prior leaderboard ranking on bug bounty, code contest, or CTF competitions.
  • Design and implement security and defense-in-depth controls to prevent and limit vulnerabilities.
  • Perform cutting edge security research in Solana and other Rust-based smart contract platforms.
  • Develop security tooling and developer workflows to aid in the early detection of vulnerabilities.
  • Collaborate with core contributors to conduct internal security audits.
  • Shepherd external security audits with the help of leading 3rd party audit firms.
  • Operate leading bug bounty programs on Immunefi.
  • Work in a diverse decentralized team environment with web3 professionals.
  • Clearly communicate security risks and solutions.
  • Adhere to the highest standards of integrity, trust, and professionalism.

BlockchainCybersecurityAPI testingRustWeb3.jsCI/CD

Posted 21 days ago
Apply
Apply

📍 AMER, EMEA

🧭 Full-Time

🔍 Security Engineering

🏢 Company: asymmetric.re

  • Strong desire to understand how things work, and the ability to quickly absorb new information.
  • Strong familiarity with multi-chain messaging protocols and asset bridging.
  • Proven experience as a consultant, engineer, bug bounty hunter or auditor.
  • Prior experience working with open source development practices.
  • Willingness and aptitude to work with multiple runtimes including EVM, SVM, NEAR, Cosmos & Move.
  • Experience with reverse engineering and/or fuzzing.
  • Experience with code reviews.
  • Prior leaderboard ranking on bug bounty platforms or strong performance in code contests or CTF competitions.
  • Design and implement security and defense-in-depth controls to prevent and limit vulnerabilities.
  • Develop security tooling and developer workflows to aid in the early detection of vulnerabilities.
  • Collaborate with core contributors to conduct internal security audits.
  • Shepherd external security audits with the help of leading 3rd party audit firms.
  • Operate a leading bug bounty program on Immunefi.
  • Develop monitoring software and custom detectors to ensure the integrity of on-chain protocols.
  • Conduct on-chain investigations to determine the root cause of potential incidents.
  • Collaborate with core contributors to reduce supply-chain risk.
  • Work in a diverse decentralized team environment with web3 professionals.
  • Clearly communicate security risks and solutions.
  • Adhere to the highest standards of integrity, trust, and professionalism.

BlockchainCybersecurityEthereumWeb3.jsScripting

Posted 21 days ago
Apply
Apply

📍 Poland, Georgia, Uzbekistan, Bulgaria, Romania

🔍 Technology

🏢 Company: Intetics👥 501-1000IT Services and IT Consulting

  • BSc/MSc in Information Security or a related field.
  • At least 5 years of experience in the DevOps field.
  • Minimum of 2 years of experience in Information Security with a focus on Cloud Security.
  • Strong knowledge of AWS services such as IAM, CloudTrail, KMS, Organizations, S3, EC2, RDS, and more.
  • Proficiency in AWS security measures, including monitoring, configuration, and implementation.
  • Hands-on experience with DevSecOps methodologies.
  • Expertise in securing cloud resources, networks, and databases.
  • Strong skills in monitoring tools like Grafana, Prometheus, and EFK.
  • Proven experience with security audits, resilient infrastructure design, and vulnerability assessments.
  • English proficiency at Upper-Intermediate (B2).
  • Design and build resilient cloud infrastructures that prevent security threats.
  • Implement and assess cloud security solutions to protect systems, databases, and networks.
  • Monitor and analyze logs, conduct vulnerability assessments, and respond to security incidents.
  • Shape security policies, procedures, and standards for cloud environments.
  • Develop technical and managerial security reports for cloud-based applications.
  • Test and implement disaster recovery procedures to ensure business continuity.
  • Monitor sensitive data usage and regulate access to safeguard information.
  • Collaborate on solutions for network and cloud infrastructure security.

AWSCybersecurityGrafanaPrometheusTerraform

Posted 3 months ago
Apply
Apply

📍 Poland

🔍 Cloud Computing

🏢 Company: Ocado SANDBOX

  • Passion for security.
  • Strong interest in cloud computing.
  • Desire to broaden skills.
  • Degree in Information Security, Computer Science, or equivalent experience.
  • Broad technical background covering operating systems, networks, cloud, and software development.
  • Programming experience in Python or Java.
  • Detailed knowledge of at least one operating system: Linux, Windows, or Mac OS.
  • Help building cloud security awareness among engineers.
  • Work closely with software developers on designing secure GCP solutions.
  • Maintain and update existing threat models and risk registries.
  • Conduct security risk assessments and address top cloud security risks.
  • Design and implement central controls to enforce essential security policies.
  • Perform security audits on evolving infrastructure.
  • Evaluate security features from cloud providers and create adoption plans.
  • Develop tools and policies to detect security vulnerabilities.
  • Investigate security alerts and respond to incidents.
  • Participate in incident response calls and security post mortems.
  • Integrate logging pipelines with the central SIEM system.
  • Create new policies and document them.
  • Provide guidance on best cloud security practices.
  • Keep up to date with the current security and threat landscape.

PythonSoftware DevelopmentCloud ComputingGCPJava

Posted 5 months ago
Apply