Remote job
Staff Security Engineer
Job details
About this role
Role overview A senior individual-contributor position focused on strengthening security across large-scale distributed systems, infrastructure, and software development practices. The role spans cross-functional collaboration with engineering, platform, infrastructure, DevOps, cloud, and security operations teams to surface systemic risks, shape technical standards, and embed security into how systems are designed and built. It sits as a bridge between operational security and engineering, turning incident and threat insights into durable architectural and process improvements.
Responsibilities - Identify systemic security risks spanning applications, cloud and on-premises infrastructure, internal platforms, and software development processes. - Conduct security architecture reviews for existing systems and new designs, producing actionable recommendations without blocking delivery. - Partner with engineering teams early in the development lifecycle to design practical mitigations for security weaknesses. - Collaborate with security operations to improve detection, analyze attack patterns, and translate findings into controls, automation, and architectural changes. - Build reusable security tools, automation, and services that engineering teams can adopt directly. - Define and evolve technical security standards, reference architectures, engineering guidelines, and best practices.
Requirements - Eight or more years of professional experience in security engineering, software engineering, infrastructure security, product security, or closely related technical roles. - Demonstrated hands-on work designing security controls for production environments at scale and in high-throughput distributed systems. - Practical experience with security architecture reviews, threat modeling, or technical security assessments. - Strong understanding of application, infrastructure, and network security, including authentication, authorization, and common attack techniques. - Working knowledge of Linux, containers, Kubernetes, networking, and modern distributed systems, plus securing both cloud and on-premises environments. - Programming or scripting ability in at least one general-purpose language such as Python, Go, Java, or C++. - Professional working proficiency in both Polish and English, minimum B2/C1.
Nice to have - Familiarity with Google Cloud Platform alongside on-prem solutions, Kubernetes serverless patterns, Argo CD and Argo Workflows, PostgreSQL, Terraform and Terragrunt, and CI/CD tooling such as GitHub Actions and Jenkins.
Benefits and work setup - Highly flexible, fully remote working arrangements based in Poland, with the ability to set your own schedule. - Engagement with large-scale, high-throughput engineering projects and modern security tooling. - Direct visibility into business outcomes, with a central role in shaping how security decisions are made across the engineering organization.