Principal Security Engineer
Tech Stack / Keywords
Firma i stanowisko
SimCorp is a leading provider of integrated investment management solutions with over 3,000 employees worldwide. It is an independent subsidiary of Deutsche Börse Group, serving prestigious financial clients in fintech. The company emphasizes skills development, collaboration, and client success within a diverse and inclusive work environment.
Wymagania
- 8+ years of experience in security engineering, cloud security, application security, cyber defense, or incident response.
- Experience with modern cloud environments, ideally including Microsoft Azure.
- Knowledge of cloud security technologies such as Microsoft Defender, Microsoft Sentinel, Entra ID, and related security monitoring tools.
- Familiarity with Identity and Access Management concepts and security best practices.
- Understanding of application security principles including threat modeling, secure development practices, SAST, DAST, and software composition analysis.
- Experience with detection engineering, SIEM technologies, threat hunting, and operational security monitoring.
- Knowledge of incident response processes and recovery activities.
- Experience with vulnerability management, infrastructure hardening, and security risk mitigation.
- Familiarity with Infrastructure as Code tools such as Terraform or Bicep.
- Experience with cloud-native technologies, containers, Kubernetes, or similar architectures.
- Understanding of DevSecOps principles and integrating security into software delivery pipelines.
- Knowledge of security frameworks and adversary techniques such as MITRE ATT&CK.
- Ability to collaborate across multiple stakeholder groups to influence security outcomes.
- Motivation for continuous learning and adapting to evolving security landscapes.
- Relevant certifications such as Microsoft Security Engineer Associate, Security Operations Analyst, Cybersecurity Architect Expert are welcomed.
Obowiązki
- Lead security engineering initiatives across cloud, application, infrastructure, and operational security domains.
- Conduct security assessments, architecture reviews, threat modeling, and risk evaluations.
- Analyze security challenges and design sustainable solutions with platform teams.
- Develop and tune detection capabilities using Microsoft Sentinel, Microsoft Defender, and KQL analytics.
- Support logging, monitoring, and event collection standards implementation.
- Participate in incident response activities, including investigation, containment, recovery, and post-incident reviews.
- Conduct proactive threat hunting activities.
- Develop incident response playbooks, security runbooks, and operational security processes.
- Translate threat intelligence and incident findings into security control improvements.
- Identify security risks proactively and define mitigation strategies.
- Lead or contribute to secure software development lifecycle initiatives, security task forces, architecture discussions, and cross-functional security programs.
- Embed security into CI/CD pipelines, development workflows, infrastructure platforms, and cloud architectures.
- Serve as a trusted security advisor for engineers, architects, and product teams.
- Communicate technical risks and security recommendations to technical and non-technical stakeholders, including senior leadership.
Benefity
- Flexible working hours and hybrid work model (2 days office, 3 days remote).
- Modern office near Wilanowska metro station with quiet zones and ergonomic workstations.
- Base salary with annual bonus structure.
- Holiday allowance upon a 2-week vacation.
- Remote work options across Poland and internationally (up to 24 days domestic, 20 days international per year).
- Employer-paid Medicover Platinum healthcare package (employee-paid family upgrade available).
- MyBenefit Cafeteria with monthly budget usable for Multisport card (25% employee contribution) or other lifestyle options.
- Unum group life insurance (employee-paid upgrade available).
- Medicover travel insurance for private trips and business travel.
- Eligibility for Deutsche Börse Group Share Plan after 1 year.
- Copyrights program for certain roles.
- Career development opportunities in an international environment.
- Professional training and courses.
- Language classes in Polish for foreigners; German and English classes based on business needs.
- Integration events, volunteering initiatives, and employee-led clubs.
Inne informacje
Informujemy, że administratorem danych jest SimCorp Sp. z o.o. z siedzibą w Warszawie, ul. Puławska 182 (dalej jako "administrator"). Masz prawo do żądania dostępu do swoich danych osobowych, ich sprostowania, usunięcia lub ograniczenia przetwarzania, prawo do wniesienia sprzeciwu wobec przetwarzania, a także prawo do przenoszenia danych oraz wniesienia skargi do organu nadzorczego. Dane osobowe przetwarzane będą w celu realizacji procesu rekrutacji. Podanie danych w zakresie wynikającym z ustawy z dnia 26 czerwca 1974 r. Kodeks pracy jest obowiązkowe. W pozostałym zakresie podanie danych jest dobrowolne. Odmowa podania danych obowiązkowych może skutkować brakiem możliwości przeprowadzenia procesu rekrutacji. Administrator przetwarza dane obowiązkowe na podstawie ciążącego na nim obowiązku prawnego, zaś w zakresie danych dodatkowych podstawą przetwarzania jest zgoda. Dane osobowe będą przetwarzane do czasu zakończenia postępowania rekrutacyjnego i przez okres możliwości dochodzenia ewentualnych roszczeń, a w przypadku wyrażenia zgody na udział w przyszłych postępowaniach rekrutacyjnych - do czasu wycofania tej zgody. Zgoda na przetwarzanie danych osobowych może zostać wycofana w dowolnym momencie. Odbiorcą danych jest serwis Just Join IT oraz inne podmioty, którym powierzyliśmy przetwarzanie danych w związku z rekrutacją.
SimCorp
55 aktywnych ofert