Senior Security Engineer
Tech Stack / Keywords
Wymagania
- Several years of hands-on security engineering experience in a modern, cloud-native software company.
- Deep comfort with at least one major cloud provider (preferably AWS), Kubernetes, infrastructure as code, and CI/CD pipelines.
- Ability to read and write code with preference for automating controls.
- Practical knowledge of identity federation, Single Sign-On (SSO), secrets and key management, logging, monitoring, vulnerability management, backups, and disaster recovery.
- Experience translating ISO 27001, NIS2, or SOC 2 frameworks into technical controls and audit evidence.
- Experience running threat modelling and security assessments collaboratively with product teams.
- Clear communication skills across legal, engineering, and leadership teams; comfortable hosting workshops and debugging IAM policies.
- High degree of autonomy, initiative-driven; proactive in improving security practices.
- Curiosity and commitment to staying informed about threat landscapes and industry trends.
Nice to have:
- Experience with security in energy, IoT, or hardware-connected environments.
- Familiarity with the EU AI Act, GDPR engineering requirements, or physical security across multiple locations.
- Experience with detection engineering or operating a SOC-style capability.
- Relevant certifications such as CISSP, CCSP, OSCP, or cloud security specialties.
Obowiązki
- Own the security posture of cloud infrastructure and Kubernetes platform, including identity and access, network segmentation, secrets management, encryption, workload hardening, logging, alerting, and detection.
- Build guardrails to make security the default path for engineers.
- Partner with product teams on threat modelling, secure design reviews, and pragmatic secure SDLC.
- Run and tune code, dependency, and container scanning; triage findings; coordinate external penetration tests and bug reports through remediation.
- Implement and evidence technical controls for ISO/IEC 27001, NIS2, and NIST CSF compliance.
- Automate evidence collection and support audits with factual system data.
- Work with IT to strengthen security configuration of identity provider, endpoint management, SaaS integrations, and office networks.
- Maintain and exercise incident response runbooks; lead technical investigation and containment.
- Conduct security risk assessments of new systems, integrations, and vendors; provide clear, balanced recommendations.
- Share knowledge, run workshops, and promote a culture where security is everyone's responsibility.
Inne informacje
Informujemy, że administratorem danych jest emagine z siedzibą w Warszawie, ul.Domaniewskiej 39A (dalej jako "administrator"). Masz prawo do żądania dostępu do swoich danych osobowych, ich sprostowania, usunięcia lub ograniczenia przetwarzania, prawo do wniesienia sprzeciwu wobec przetwarzania, a także prawo do przenoszenia danych oraz wniesienia skargi do organu nadzorczego. Dane osobowe przetwarzane będą w celu realizacji procesu rekrutacji. Podanie danych w zakresie wynikającym z ustawy z dnia 26 czerwca 1974 r. Kodeks pracy jest obowiązkowe. W pozostałym zakresie podanie danych jest dobrowolne. Odmowa podania danych obowiązkowych może skutkować brakiem możliwości przeprowadzenia procesu rekrutacji. Administrator przetwarza dane obowiązkowe na podstawie ciążącego na nim obowiązku prawnego, zaś w zakresie danych dodatkowych podstawą przetwarzania jest zgoda. Dane osobowe będą przetwarzane do czasu zakończenia postępowania rekrutacyjnego i przez okres możliwości dochodzenia ewentualnych roszczeń, a w przypadku wyrażenia zgody na udział w przyszłych postępowaniach rekrutacyjnych - do czasu wycofania tej zgody. Zgoda na przetwarzanie danych osobowych może zostać wycofana w dowolnym momencie. Odbiorcą danych jest serwis Just Join IT oraz inne podmioty, którym powierzyliśmy przetwarzanie danych w związku z rekrutacją.
emagine
467 aktywnych ofert