Mid Cybersecurity Engineer
1 giorno fa
italy
Allegro
Tempo pieno
Gratuito con email o Google
Salva questo lavoro e mantieni la tua ricerca organizzata
Crea un account gratuito per salvare lavori, creare avvisi e tornare a questa inserzione dalla tua dashboard.
Gratuito con email o Google
Continuando accetti i nostri Termini & Informativa sulla privacy.
Mid Cybersecurity Engineer - AppSec/SecDev
Azienda : Allegro Tipo Lavoro : Full Time Italy
Descrizione Lavoro - Mid Cybersecurity Engineer - AppSec/SecDev
Important things for you
- Flexible working hours in the hybrid model (4/1) - working hours start between 7:00 a.m. and 9:00 a.m. We also have 30 days of occasional remote work.
- Annual bonus based on your annual performance and company results.
- Our team is based in Warsaw and Poznań.
About the job
- Massive Scale & Security Challenges: Secure, test and optimize a world-class, cloud and on-prem environment handling thousands of requests per minute. This is high-availability, high-performance security engineering in practice.
- Modern Tech Stack: Work within an advanced ecosystem where core technologies include specialized offensive and defensive security tools, automated SAST/DAST pipelines, C2 frameworks and cutting-edge cryptography. We are also pioneering the security of production-used AI models.
- True Ownership & Autonomy: We live by a \"you build it, you run it\" philosophy. You'll join an autonomous team with full ownership of your security services - from threat modeling and attack simulation to deploying protective guardrails.
- Complex Architectural Puzzles: From securing distributed systems to tackling novel AI vulnerabilities, you'll solve complex engineering problems that directly protect a massive, real-time marketplace.
Skills required
- Proven track record in deep-dive manual penetration testing of web/mobile applications, APIs and AI-driven features, alongside strong secure code review skills.
- Solid understanding of financial tech security standards and regulations, including PCI-DSS, PSD3/DORA, OWASP Top 10 (and API Top 10), and secure data handling (PII/banking data protection).
- Practical experience embedding security into the SDLC. Ability to analyze software architectures, review new feature proposals, and lead threat modeling sessions to ensure security controls are integrated from day one.
- Hands-on experience designing, tuning, and deploying SAST, DAST, and SCA solutions inside fast-paced CI/CD pipelines without blocking deployment velocity.
- Strong ability to independently triage, risk-score, and manage vulnerabilities across APIs, microservices, and financial infrastructure.
- Familiarity with microservices architectures, cloud environment security, containerization, and secure system configuration.
- A self-starter mindset with the ability to take full ownership of tasks, estimate effort, and clearly communicate actionable security guidance to engineering and product teams.
Your main responsibilities
- Design, execute, and report manual and automated security tests across APIs, microservices, and fintech infrastructure, identifying vulnerabilities and assessing business risks.
- Manage the vulnerability lifecycle from identification and risk-scoring (tailored to financial impact) to tracking remediation with engineering teams.
- Review architectural designs and new financial feature proposals, serving as the main security liaison for engineering teams and driving collaborative threat modeling sessions.
- Support DevSecOps practices by integrating and fine-tuning automated security mechanisms (SAST/DAST/SCA) into the CI/CD pipeline, reducing technical debt while maintaining release velocity.
- Support the development of the secure system configurations, monitor cloud applications, and preventive measures against emerging fintech threat vectors.
- Collaborate with product and tech teams, consulting on security-enhancing solutions and verifying their implementation.
- Partner closely with product and tech teams during ceremonies (design, grooming) to consult on security-enhancing solutions and verify their successful implementation.
- Take ownership of impactful security initiatives from design through delivery, providing clear estimates, prioritization, and independent problem resolution.
- Contribute to raising the team’s security maturity by creating documentation, hosting knowledge-sharing sessions, mentoring newcomers and supporting the technical hiring process.
What's in it for you:
- Well-located offices (with e.g. fully equipped kitchens, bicycle parking, terraces full of greenery) and excellent work tools (e.g., raised desks, ergonomic chairs, interactive conference rooms).
- A 16\" or 14\" MacBook Pro or corresponding Dell with Windows (if you don't like Macs) and all the necessary accessories.
- A wide selection of fringe benefits in a cafeteria plan - you choose what you like (e.g., medical, sports or lunch packages, insurance, purchase vouchers).