22 hours ago
Warsaw, PolandStaff+
Responsibilities
- Lead security engineering initiatives from planning through implementation across cloud, application, infrastructure, and operational security domains.
- Conduct security assessments, architecture reviews, threat modeling exercises, and risk evaluations.
- Develop and tune detection capabilities using Microsoft Sentinel, Microsoft Defender, KQL analytics, and related security tooling.
- Define and implement logging, monitoring, and event collection standards across the platform.
- Participate in incident investigations, containment, recovery, root cause analysis, and post-incident reviews.
- Conduct proactive threat hunting and improve incident response playbooks, security runbooks, and operational security processes.
- Translate threat intelligence, incident findings, and emerging risks into improvements to security controls and engineering practices.
- Lead or contribute to secure software development lifecycle initiatives, security taskforces, architecture discussions, and cross-functional security programs.
- Embed security into CI/CD pipelines, development workflows, infrastructure platforms, and cloud architectures.
- Advise engineers, architects, product teams, and senior leadership on security risks and secure decision-making.
Requirements
- 8+ years of experience in security engineering, cloud security, application security, cyber defense, incident response, or related fields.
- Experience working in modern cloud environments, ideally including Microsoft Azure.
- Knowledge of Microsoft Defender, Microsoft Sentinel, Entra ID, security monitoring tools, and related services.
- Familiarity with Identity and Access Management concepts and security best practices.
- Understanding of application security, threat modeling, secure development practices, SAST, DAST, and software composition analysis.
- Experience with detection engineering, SIEM technologies, threat hunting, and operational security monitoring.
- Knowledge of incident response processes, investigation techniques, and recovery activities.
- Experience with vulnerability management, infrastructure hardening, and security risk mitigation.
- Familiarity with Infrastructure as Code technologies such as Terraform or Bicep.
- Experience with cloud-native technologies, containers, Kubernetes, or similar platform architectures.
- Understanding of DevSecOps principles and integrating security into software delivery pipelines.
- Knowledge of security frameworks, attack methodologies, and adversary techniques such as MITRE ATT&CK.
- Ability to collaborate across stakeholder groups and influence security outcomes through technical expertise.
- Relevant certifications such as Microsoft Security Engineer Associate, Security Operations Analyst, Cybersecurity Architect Expert, or similar certifications are welcomed.
Benefits
- Flexible working hours and a hybrid model with two days in the office and three days remote.
- Modern office near Wilanowska metro station with quiet zones and ergonomic workstations.
- Annual bonus structure and holiday allowance upon a two-week vacation.
- Occasional remote work across Poland and internationally, subject to internal policy, including up to 24 domestic and 20 international days per year.
- Employer-paid Medicover Platinum healthcare package, with an employee-paid family upgrade available.
- MyBenefit Cafeteria with a monthly budget that can support a Multisport card or other lifestyle options.
- Unum group life insurance with an employee-paid upgrade available.
- Medicover travel insurance for private trips and global business travel insurance.
- Possibility to join the Deutsche Börse Group Share Plan after one year of eligibility.
- Professional training, courses, language classes, career development, integration events, volunteering initiatives, and employee-led clubs.
Tech Stack
Categories
About SimCorp
SimCorp builds SimCorp Dimension, a front-to-back investment management platform and managed services used by buy-side institutions such as asset managers, pension funds, and insurers. It sells software licenses and cloud-delivered operations (SaaS/managed services) covering portfolio management, trading, risk, accounting, and reporting. Founded in 1971 and headquartered in Copenhagen, it is a subsidiary of Deutsche Börse Group and reports serving 40 of the world’s top 100 financial companies.
