Senior Security Engineer
XTB is a global company from the financial industry, focusing on online trading of financial instruments. We are the largest FinTech in Poland and a leader in Central and Eastern Europe, and the range of our operations covers several countries, including Asia and South America. At XTB, we focus on the development of our employees, giving them opportunities to gain knowledge and skills in various fields, as well as offering a number of training and development programs. If you are looking for challenges and want to gain valuable experience in an international business environment, XTB is the right place for you.
We are a certified Great Place to Work company.
We are looking for a candidate to join our team as a Senior Security Engineer. In this role, you will serve as a key technical expert, combining deep competencies in both defensive and offensive security. Your primary goal will be to ensure the security of ICT processes and assets. You will also collaborate regularly with IT teams, DevOps, and Product Managers.
Responsibilities
-
Detection & Security Incident Response: Responding to and handling ICT security incidents, alongside operational support for the monitoring process.
-
Security Tools & Solutions: Maintaining, evaluating, and implementing new cybersecurity tools and solutions.
-
Vulnerability Management: Managing vulnerability scans, as well as executing the vulnerability assessment and mitigation process for networks, web & mobile environments, on-premises, and cloud infrastructure in cooperation with technology teams.
-
Threat Modeling & Assessment: Supporting the threat modeling process from an attacker’s perspective, including reviewing and testing IT systems for secure configuration.
-
Best Practices & Training: Establishing and promoting security best practices, including preparing and conducting cybersecurity training sessions.
Requirements
-
Minimum 5 years of technical experience in the IT security domain (e.g., Security Engineer, Pentester, L3 SOC Analyst).
-
Practical technical knowledge and experience in either Blue Teaming (monitoring, incident handling and analysis, security tool maintenance) or Red Teaming (penetration testing, vulnerability assessment).
-
Experience conducting vulnerability scans, risk assessments, and creating technical documentation, procedures, and security guidelines.
-
Practical knowledge of security controls for operating systems, computer networks, web/mobile applications, and cloud environments.
-
Strong skills and experience in conducting training sessions and collaborating with development teams, DevOps, and business stakeholders.
-
Good command of English enabling effective communication.
Nice to have
-
Knowledge of industry standards, regulations, and best practices supported by training, courses, or certifications (e.g., OSCP, CEH, CISSP, ISO/IEC 27001, etc.).
-
Practical experience in managing the ICT incident response process and security tool architecture.
-
Practical scripting and automation skills (e.g., Python, Bash) and familiarity with CI/CD processes.
What we offer
- Real influence on the development of the company and the product.
- Work in an experienced team that is happy to share its knowledge.
- A clear vision of development thanks to regular feedback and clear career paths.
- Regular team-building meetings.
Benefits
- A training budget for courses and conferences that interest you.
- An extra day off on your birthday.
- An extra day off for parents.
- Equipment tailored to your needs.
- Private medical care and group insurance.
- Access to an e-learning platform for learning English and a benefits platform.
- Access to a wellbeing platform and the opportunity to take advantage of workshops and private therapy sessions.
- Remote work, from the office in Warsaw or from a coworking space in your city.
