
Security Engineer
Posted Sep 15

Posted Sep 15
This is a fully remote position, open to applicants in Poland, +1 more country.
• Establish and confirm application and platform security measures throughout all delivery stages.
• Conduct architecture and threat-model evaluations during the design phase and as the platform progresses.
• Assess authentication, authorization, and privileged-access controls across CMS, APIs, and integrated services.
• Verify API and integration security within a composable, multi-vendor platform framework.
• Examine secrets, credentials, and token-management practices throughout the entire stack.
• Assist with vulnerability scanning and penetration-testing efforts by organizing findings and remediation actions.
• Ensure encryption and secure data management throughout storage, transit, and third-party integrations.
• Analyze security logging, monitoring, and incident response necessities.
• Aid in GDPR compliance and privacy engineering requirements during the delivery process.
• Execute third-party security evaluations for integrated services and vendors.
• Offer remediation advice and generate security acceptance documentation prior to launch.
• Act as the security expert during a full-lifecycle engagement for a new digital news platform.
• Confirm controls across a composable CMS, video pipeline, advertising integrations, personalization services, and public-facing APIs.
• Support a platform built to handle extreme traffic during breaking news situations.
• Over 5 years of experience in application security, security engineering, or a related field.
• Proven experience in threat modeling and conducting architecture security reviews on complex, multi-component platforms.
• Extensive knowledge of authentication and authorization frameworks, including OAuth, OIDC, RBAC, and privileged access management.
• Practical experience in validating API security and assessing integration approaches with third-party services.
• Strong understanding of secrets management, credential processing, and token lifecycle best practices.
• Experience in supporting or managing vulnerability scanning and penetration testing initiatives.
• Familiarity with encryption standards and secure data handling practices for both storage and transit.
• Knowledge of GDPR and privacy-by-design engineering principles.
• Ability to create clear remediation guidance and security acceptance documentation for engineering and delivery teams.
• Experience securing composable CMS or media platform architectures such as AEM, Amplience, or similar.
• Background in managing high-traffic, public-facing platforms where availability and security are critical.
• Experience with security logging and monitoring tools, including SIEM, alerting systems, and incident response playbooks.
• Understanding of third-party vendor security assessment procedures.
• Relevant certifications such as CISSP, OSCP, CEH, or an equivalent.
• Experience working within a phased, full-lifecycle delivery program alongside engineering and architecture teams.
• Legal authorization to work in the country where the position is located.
• Proficiency in English at levels A1-A2, B1-B2, C1-C2, or Native.
• Equal opportunity employer.
• Opportunities to engage in real-world AI-driven projects across major industries.
• Collaboration with a diverse global team spanning different continents and cultures.
• An inclusive environment that emphasizes continuous learning, innovation, and ethical AI standards.
Intelance
OX Security
Cloudiax
Cisco
Get handpicked remote jobs straight to your inbox weekly.