Unlock Full Resume Report

New offer - be the first one to apply!

September 3, 2026

Security Engineer (DevSecOps)

Senior • Remote

18,000 - 25,000 PLN/yr

Gliwice, SL, Poland

What You'll Be Doing

Security Audit & Assessment

  • Conduct a comprehensive internal security audit of GCP infrastructure, GKE clusters, Apigee API gateway, and MongoDB Atlas deployments.
  • Review network architecture, IAM policies, secrets management, and workload isolation across all environments.
  • Assess API security, including authentication flows, rate limiting, token scoping, and gateway policies in Apigee.
  • Audit GKE hardening, including RBAC, Pod Security Standards, node pool configuration, admission controllers, and container image supply chain.
  • Identify and prioritise vulnerabilities, misconfigurations, and compliance gaps with clear severity ratings.

Remediation & Hands-On Fixes

  • Implement fixes directly—not just reports—including Infrastructure as Code changes (Terraform / Helm), policy updates, and pipeline security gates.
  • Analyse root causes of security gaps and implement long-term structural improvements.

About You

  • 4+ years of experience in security engineering, cloud security, or DevSecOps.
  • Degree in Computer Science, Computer Engineering, or a related technical field, or equivalent practical experience.
  • Comfortable working hands-on with cloud providers and auditing managed Kubernetes environments.
  • Solid knowledge of Kubernetes security: RBAC, Pod Security Standards, network policies, and OPA/Gatekeeper.
  • Deep understanding of API security, preferably with Apigee or a comparable gateway.
  • Knowledge of securing cloud-managed NoSQL databases, including access controls, encryption, and audit logging.
  • Ability to write and review Terraform or Helm charts to implement fixes.
  • Strong grasp of OAuth 2.0, JWT, mTLS, and secret lifecycle management.
  • Effective communication in Polish and English, minimum B2 level.
  • Self-starter who takes ownership of findings and sees them through to resolution.

Bonus Points

  • GCP Professional Security Engineer or CKS (Certified Kubernetes Security Specialist) certification.
  • Experience with SAST/DAST tools such as Semgrep, Trivy, or OWASP ZAP.
  • Familiarity with headless commerce architectures.
  • Knowledge of ISO27001 or SOC 2 compliance requirements.
  • Bug bounty or penetration testing background.

Why You'll Love It Here

  • Meaningful Impact: Directly shape the security posture of a cutting-edge commerce platform used by global enterprises, from finding the first issue to shipping the fix.
  • Hands-On Ownership: Audit, fix, and monitor security issues, with direct visibility into the results of your work.
  • Collaborative Culture: Work with experienced engineers in a supportive environment that values knowledge sharing and practical solutions over bureaucracy.
  • Flexible Work Setup: Remote/hybrid work model that supports flexibility and personal well-being while encouraging meaningful team connections. Meet in the Gliwice office at least once a month.
  • Come as you are: A collaborative spirit, communication, and a pragmatic approach to problem-solving are valued. Candidates of all genders and backgrounds are encouraged to apply, including those who may not meet every listed qualification but are passionate about security and making systems safer.

Similar jobs you might like