Tellent
Tellent
New

Principal Product Security Engineer

~322 - 410 PLN/ godz.B2B
~322 - 410 PLN/ godz.UoP
SeniorFull-time·B2B·Umowa o pracę
#442255·Dodano 6 dni temu·6
Źródło: justjoin.it
Aplikuj teraz

Tech Stack / Keywords

Analytical ThinkingAISecurity

Firma i stanowisko

Tellent is a Talent Management Suite that helps organizations attract, hire, manage, and grow their people. Their platform combines Applicant Tracking, HRIS, and Performance Management solutions used by over 7,000 companies across more than 100 countries. The company has 250+ employees across Europe and focuses on building intuitive and scalable HR technology that handles sensitive information securely, especially as AI-powered functionality is integrated into their products.

Wymagania

  • Deep hands-on application or product security experience across engineering and security roles.
  • Strong examples of personally identified vulnerabilities with full lifecycle experience from hypothesis to remediation.
  • Strong understanding of access control, multi-tenancy, authentication, authorization, session management, injection vulnerabilities, SSRF, deserialization, business logic abuse, and supply-chain risk.
  • Hands-on engineering skills; comfortable reading and writing production code and reasoning about unfamiliar systems.
  • Experience threat modeling real systems and translating results into practical engineering work.
  • Working knowledge of cloud security, containers, CI/CD, and infrastructure as code.
  • Technology-agnostic mindset; comfortable working across different languages and stacks.
  • Excellent communication skills for explaining vulnerabilities and discussing trade-offs with engineers and senior stakeholders.
  • Collaborative and low-ego approach, focusing on enabling teams to involve product security early.
  • Experience with AI and LLM application security including prompt injection, excessive agency, and data leakage is particularly valuable.
  • Additional pluses: privacy engineering, identity systems such as OAuth 2.0, OIDC, and SAML, offensive security, platform integrations, and building early-stage product security practices.
  • Certifications like OSCP, CISSP, CISM, or CSSLP are welcome but not required.

Obowiązki

  • Perform deep manual security reviews and offensive testing across services, APIs, and clients, focusing on authorization, multi-tenancy, business logic, and other high-risk areas.
  • Threat model highest-risk product surfaces, including AI functionality, and help teams develop these skills.
  • Own the technical strategy for application security tooling, focusing on developer experience and low false positives.
  • Triage vulnerabilities from tooling, penetration tests, and external researchers; make defensible severity calls; partner with teams to verify fixes.
  • Identify patterns and root causes across findings; build systemic fixes, secure-by-default libraries, and paved paths to prevent recurring vulnerabilities.
  • Develop secure development standards for engineers' daily work.
  • Partner with Security team on bug bounty program, pentest remediation, security champions network, and training based on real findings.
  • Act as a senior technical partner for product security incidents and engineering controls required for security or privacy commitments.
  • Shape and own the product security roadmap, collaborating across Backend, Frontend, QA, DevOps, Product, and Security teams.

Benefity

  • Primarily remote working with flexibility and opportunities to connect with the team.
  • Diverse and international team environment.
  • Annual compensation range: 322,380-410,000 PLN/year (+ VAT where applicable).
  • Time off for employment contract (UoP): 26 paid holiday days + 2 wellbeing days.
  • €1500 annual learning budget.
  • Wellness perks including Multisport and private healthcare (LuxMed).
  • Work from anywhere for up to 4 weeks per year.
  • Apple MacBook, displays, and necessary tools.
  • €200 home office budget + work-from-home allowance.
Elastyczne godziny
Opieka zdrowotna
Karta sportowa
Płatny urlop
Płatne święta
Dofinansowanie szkoleń

Inne informacje

Informujemy, że administratorem danych jest Recruitee Sp. z o.o. z siedzibą w Poznaniu, pl. Wiosny Ludów 2 61-831 (dalej jako "administrator"). Masz prawo do żądania dostępu do swoich danych osobowych, ich sprostowania, usunięcia lub ograniczenia przetwarzania, prawo do wniesienia sprzeciwu wobec przetwarzania, a także prawo do przenoszenia danych oraz wniesienia skargi do organu nadzorczego. Dane osobowe przetwarzane będą w celu realizacji procesu rekrutacji. Podanie danych w zakresie wynikającym z ustawy z dnia 26 czerwca 1974 r. Kodeks pracy jest obowiązkowe. W pozostałym zakresie podanie danych jest dobrowolne. Odmowa podania danych obowiązkowych może skutkować brakiem możliwości przeprowadzenia procesu rekrutacji. Administrator przetwarza dane obowiązkowe na podstawie ciążącego na nim obowiązku prawnego, zaś w zakresie danych dodatkowych podstawą przetwarzania jest zgoda. Dane osobowe będą przetwarzane do czasu zakończenia postępowania rekrutacyjnego i przez okres możliwości dochodzenia ewentualnych roszczeń, a w przypadku wyrażenia zgody na udział w przyszłych postępowaniach rekrutacyjnych - do czasu wycofania tej zgody. Zgoda na przetwarzanie danych osobowych może zostać wycofana w dowolnym momencie. Odbiorcą danych jest serwis Just Join IT oraz inne podmioty, którym powierzyliśmy przetwarzanie danych w związku z rekrutacją.

Tellent

Tellent

2 aktywne oferty

Zobacz wszystkie oferty
Aplikuj teraz