Security Engineer (DevSecOps)
Tech Stack / Keywords
Firma i stanowisko
co.brick is recruiting for a Security Engineer to work on cloud security with hands-on remediation for a commerce platform. The position involves technical security audit and ongoing fixes of GCP infrastructure, GKE clusters, Apigee API gateway, and MongoDB Atlas deployments. The role supports a hybrid work model with a modern office in Gliwice, Poland.
Wymagania
- 4+ years of experience in security engineering, cloud security, or DevSecOps
- Degree in Computer Science, Computer Engineering, or related technical field (or equivalent practical experience)
- Hands-on experience working with Cloud Providers and audited managed Kubernetes environments
- Solid knowledge of Kubernetes security: RBAC, Pod Security Standards, network policies, and OPA/Gatekeeper
- Deep understanding of API security, preferably with Apigee or comparable gateway
- Experience securing Cloud Managed NoSQL databases: access controls, encryption, and audit logging
- Ability to write and review Terraform or Helm charts
- Strong grasp of OAuth 2.0, JWT, mTLS, and secret lifecycle management
- Effective communication skills in both Polish and English (minimum B2 level)
- Self-starter with ownership mindset to see findings through to resolution
Nice to have:
- GCP Professional Security Engineer or CKS (Certified Kubernetes Security Specialist) certification
- Experience with SAST/DAST tools such as Semgrep, Trivy, or OWASP ZAP
- Familiarity with headless commerce architectures
- Knowledge of ISO27001 or SOC 2 compliance requirements
- Bug bounty or penetration testing background
Obowiązki
Security Audit & Assessment:
- Conduct a comprehensive internal security audit of our GCP infrastructure, GKE clusters, Apigee API gateway, and MongoDB Atlas deployments
- Review network architecture, IAM policies, secrets management, and workload isolation across all environments
- Assess API security: authentication flows, rate limiting, token scoping, and gateway policies in Apigee
- Audit GKE hardening: RBAC, pod security standards, node pool configuration, admission controllers, and container image supply chain
- Identify and prioritise vulnerabilities, misconfigurations, and compliance gaps with clear severity ratings
Remediation & Hands-On Fixes:
- Implement fixes directly, including Infrastructure as Code changes (Terraform / Helm), policy updates, and pipeline security gates
- Analyse root causes of security gaps and implement long-term structural improvements
Benefity
- Meaningful impact on the security posture of a global commerce platform
- Hands-on ownership of audit and remediation tasks
- Collaborative culture with experienced engineers valuing practical solutions
- Flexible remote/hybrid work setup with monthly office visits in Gliwice
Inne informacje
Informujemy, że administratorem danych jest co.brick Sp. z o.o. z siedzibą w Gliwicach, ul. Kaczyniec 9 (dalej jako "administrator"). Masz prawo do żądania dostępu do swoich danych osobowych, ich sprostowania, usunięcia lub ograniczenia przetwarzania, prawo do wniesienia sprzeciwu wobec przetwarzania, a także prawo do przeniesienia danych oraz wniesienia skargi do organu nadzorczego. Dane osobowe przetwarzane będą w celu realizacji procesu rekrutacji. Podanie danych w zakresie wynikającym z ustawy z dnia 26 czerwca 1974 r. Kodeks pracy jest obowiązkowe. W pozostałym zakresie podanie danych jest dobrowolne. Odmowa podania danych obowiązkowych może skutkować brakiem możliwości przeprowadzenia procesu rekrutacji. Administrator przetwarza dane obowiązkowe na podstawie ciążącego na nim obowiązku prawnego, zaś w zakresie danych dodatkowych podstawą przetwarzania jest zgoda. Dane osobowe będą przetwarzane do czasu zakończenia postępowania rekrutacyjnego i przez okres możliwości dochodzenia ewentualnych roszczeń, a w przypadku wyrażenia zgody na udział w przyszłych postępowaniach rekrutacyjnych - do czasu wycofania tej zgody. Zgoda na przetwarzanie danych osobowych może zostać wycofana w dowolnym momencie. Odbiorcą danych jest serwis Just Join IT oraz inne podmioty, którym powierzyliśmy przetwarzanie danych w związku z rekrutacją.
co.brick
6 aktywnych ofert