Skip to content
Apply now

This job is listed on several sites

Mindbox Sp. z o.o.

Security Engineer

Mindbox Sp. z o.o. Show all offers
26000 - 33000 PLN
B2B
Hybrid
Senior
Kraków
Expires Oct 5, 2026
13 days ago

In short

Security Engineer (PL, Kraków, Hybrid) - Design & implement IAM security controls, Zero Trust, PKI, GCP & Kubernetes security. Requires experience in InfoSec Engineering, IAM, cloud security, and DevSecOps. B2B/Employment contract, flexible hours, benefits.

AI-written summary based on the listing content.

Technologies we use

About the project

This is how we organize our work

This is how we work

Your responsibilities

  • Design and implement security controls for IAM services and platforms.
  • Apply Zero Trust and Secure by Design principles across solution delivery.
  • Configure secure authentication and authorization mechanisms.
  • Implement service-to-service security using mTLS and manage secrets, PKI, and key rotation.
  • Define and enforce Policy-as-Code solutions (OPA or related tools).
  • Perform comprehensive threat modelling, security reviews of designs and code, and vulnerability assessments.
  • Integrate robust cloud security for GCP and Kubernetes environments.
  • Support cryptographic processes, certificate lifecycle, and privileged access controls.
  • Conduct security risk assessments and assist with penetration testing and remediation.
  • Implement monitoring, logging, and alerting for compliance and operational readiness.
  • Contribute to DevSecOps practices and automated security testing pipelines.
  • Produce clear standards, hardening guides, and operational security documentation.
  • Provide guidance during security events in collaboration with Security Operations and Incident Response teams.
  • Note: Detailed project information will be shared during the recruitment process.

Our requirements

  • Proven experience in Information Security Engineering and Identity & Access Management.
  • Strong knowledge of Zero Trust Architecture, authentication/authorization mechanisms, and Policy-as-Code (OPA).
  • Expertise in PKI, certificate management, cryptography, and secrets management solutions.
  • Hands-on experience securing cloud platforms (GCP) and Kubernetes workloads.
  • Familiarity with Service Mesh Security, API Security, and DevSecOps tooling.
  • Ability to conduct SSDLC activities, threat modelling, and vulnerability management.
  • Understanding of security monitoring, SIEM, security compliance, and governance frameworks.
  • Experience supporting incident response and risk management activities.

What we offer

  • Flexible cooperation model – choose the form that suits you best (B2B, employment contract, etc.).
  • Hybrid work setup – 6 days a month from the office in Kraków
  • Collaborative team culture – work alongside experienced professionals eager to share knowledge.
  • Continuous development – access to training platforms and growth opportunities.
  • Comprehensive benefits – including Interpolska Health Care, Multisport card, Warta Insurance, and more.
  • High quality equipment – laptop and essential software provided.

This is how we work on a project

Benefits

Published 2026-09-05
Source