Senior Security Engineer
1 мес. назад
PolandEuropeSeniorRemote
securityapplication securityinfrastructure securitycompliance
Senior Security Engineer responsible for end-to-end security across application, infrastructure, supply chain, endpoints, operations, and compliance.
Обязанности
- We're looking for a Senior Security Engineer who thinks about security end to end — not one domain deep, but the whole posture: application, infrastructure, supply chain, endpoints, operations, and the compliance surface behind them.
- You will co-own the company security roadmap together with our Security Leader, balancing domains by risk — while staying a hands-on technical contributor.
- You will own security programs end-to-end: from roadmap shaping and stakeholder alignment through implementation and adoption.
- This role carries a realistic growth path to DevSec Team Lead — a player-coach role: leading the team's delivery and growth while remaining deeply hands-on, with career progression on the engineering IC track.
Требования
- Credible hands-on experience in at least two security domains (e.g. AppSec + cloud/infra) and literacy across the rest — you think in overall posture and risk, not tools
- You have built or scaled a security program end-to-end (process, tooling, adoption), ideally in a low-structure environment
- Coding and automation ability (Python preferred) and cloud security depth (AWS)
- Experience with AI-assisted development, and with securing it: LLM tooling (e.g. MCP), AI governance awareness
- Leadership appetite with evidence — mentoring, deputising for a lead, or formal lead experience — and the ambition to own a team's delivery while staying technical
- An educator and multiplier, not a gatekeeper: you enjoy high-empathy collaboration with developers
- Located in Europe
Будет плюсом
- Framework-based posture assessment experience (CIS Controls, NIST CSF, or similar) — you can run an assessment and turn it into a prioritised roadmap
- Pentest, audit, and compliance exposure (SOC 2, PCI-DSS, ISO 42001)
- Terraform/Kubernetes; endpoint/MDM and IdP experience
Условия
- Professional development support (trainings, courses, conferences, books, etc)
- Transparent career development system
- Different options for your working preferences (office, remote, flexible)
- Access to all the latest tools and equipment you'll need
- Team events: annual employee awards, internal hackathons, and a dozen cool events from cooking to the olympic games :)
- Generous referral bonuses
- is an equal-opportunity employer. does not discriminate against any employee or applicant because of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), or any other basis protected by law.
- The Talent Acquisition team uses @ .com and @ email addresses for coordinating interviews, providing updates, and sending documents.
- Our hiring process involves an introduction, practical and team interviews, and a decision and offer. For more information, visit our Recruitment Privacy Notice page or contact our talent team via talent@.com
Другое
- is the #1 Banking AI platform, empowering community and regional financial institutions to create efficiencies, accelerate loan growth, drive deposits, and deliver experiences that win against megabanks and fintechs.
- 's Banking AI Operating System is a central intelligence layer on top of existing tech stacks, activating an AI workforce of specialized agents that draw from banking data, interaction history, and integrated systems of record. These banking-trained agents automate workflows across voice and digital–from front office to back office–resulting in decreased operational costs and the Universal Banker model.
- Trusted by 700+ banks and credit unions for its ironclad security and reliability, delivers the industry’s first contractual no-hallucination guarantee. It’s why customers quickly and confidently put Banking AI to work with measurable results from day one. More information about can be found at .com .
- The DevSec team owns developer-facing and platform security at — building guardrails and paved paths that let product teams move fast, safely. There is a saying in : security is not just a feature, it's a part of our service.
- The role spans the whole security surface, prioritising by risk rather than by specialty:
- Application & product security — threat modelling, secure SDLC, design/code review, supply chain security
- Infrastructure & cloud security — AWS posture, runtime security, IAM; close collaboration with the Infrastructure team
- Security automation & AI — develop and own automation and AI tooling supporting company security goals; secure our AI-assisted development practices and LLM tooling
- Endpoint & corporate security — developer endpoint security (MDM, privilege, software governance), secrets hygiene
- Whole-posture assessment — run framework-based assessments (CIS Controls), identify where attention bears most value, and turn findings into prioritised, engineering-consumable plans
- Compliance interface — connect technical work to SOC 2 / PCI-DSS / ISO 42001 needs
- Mentor engineers, lead blameless post-mortems for security incidents, and present to and align senior management
- DevSec is part of the Platform group and works closely with Infrastructure, Developer Acceleration, and Observability. The team is remote-first with fully remote rituals — we have team members in Estonia and Poland today, and for this role we hire anywhere in Europe .
- Infrastructure: AWS (Terraform, Kubernetes)
- CI/CD: GitHub Actions
- Vulnerability detection & runtime security: Snyk, Sysdig/Falco
- SSO & MDM: Okta, Jamf
- Coding: Python preferred; our product stack includes Elixir, Ruby, and Golang
- AI-assisted development: Claude Code and agentic tooling are part of everyday engineering at