Senior Security Engineer, Platform Security

4 tygodni temu


Kraków, Lesser Poland Qualtrics Pełny etat

At Qualtrics, we create software the world's best brands use to deliver exceptional frontline experiences, build high-performing teams, and design products people love. But we are more than a platform—we are the creators and stewards of the Experience Management category serving over 18K clients globally. Building a category takes grit, determination, and a disdain for convention—but most of all it requires close-knit, high-functioning teams with an unwavering dedication to serving our customers.When you join one of our teams, you'll be part of a nimble group that's empowered to set aggressive goals and move fast to achieve them. Strategic risks are encouraged and complex problems are solved together, by passing the microphone and iterating until the best solution comes to light. You won't have to look to find growth opportunities—ready or not, they'll find you. From retail to government to healthcare, we're on a mission to bring humanity, connection, and empathy back to business. Join over 6,000 people across the globe who think that's work worth doing.

Senior Security Engineer, Platform Security

The challenge

As Qualtrics continues to expand the Experience Management (XM) SaaS platform, we must ensure that we're protecting our customers and their data by building and operating secure systems. With over one thousand software & system engineers contributing to Qualtrics XM every day, we have a large attack surface to evaluate and secure. This role is critical to our mission.

Qualtrics is seeking an experienced security engineer with a passion for security to lead a new platform security team at Qualtrics. This is a new role reporting to the Head of Platform Security that includes a mix of hands-on security engineering, program operations and team leadership responsibilities.

The Platform Security team is responsible for measures to improve and ensure the security of web & mobile applications, code and related components, underlying infrastructure and cloud services in Qualtrics SaaS products (including those of our acquired companies). The team owns secure development standards and training, security testing tools (e.g., SAST, DAST, SCA, container vulnerability management, CSPM), threat modeling, penetration testing, red team, bug bounty, vulnerability disclosure and vulnerability management programs. Platform Security works in collaboration with other teams within the Information Security organization (including security operations and incident response, and security & privacy assurance) and across the Product Engineering organization.

A day in Life

  • Review source code & software/system designs, and consult with engineers across the organization to identify and/or avoid security issues through alignment with security standards and best practices
  • Leverage your accumulated subject matter expertise of Qualtrics applications, systems, code and infrastructure to propose and drive architectural improvements which address classes of security flaws in the platform
  • Support a team of security engineers through regular 1-on-1 sessions and team stand up meetings, coaching and workload management
  • Document and improve secure development lifecycle processes, standards and guidelines
  • Deliver training and provide mentoring to software engineers on security topics
  • Facilitate threat modeling exercises to ensure optimized security design decisions are being made
  • Document remediation recommendations and collaborate with engineers to ensure vulnerability findings are successfully and efficiently addressed
  • Support bug bounty and vulnerability disclosure programs, including the triage and validation of reported findings
  • Lead the selection, design, development, implementation and management of automated security testing tools
  • Support Platform Security-owned tools and services which are relied upon by other organizations, including those in support of the vulnerability management program
  • Coordinate with Platform Security counterparts based in the United States to align efforts
  • Contribute to the platform security architecture and program strategy; align and communicate roadmaps with stakeholders

The Expectation for Success

You will define and drive improvements to the product and application security program; mentor and support a team of skilled security engineers; and work effectively with the Qualtrics engineering organization and fellow security team members to protect our customers and their data by building and operating secure systems.

Minimum Qualifications

  • Bachelor's degree in Computer Science, Cyber Security or a related field
  • Over 5 years of relevant work experience
  • Experience as a security engineer in product, application, infrastructure and/or cloud security
  • Experience leading complex security projects and initiatives that require collaboration with teams across an organization
  • Sound understanding of application & cloud security vulnerabilities (e.g., OWASP Top 10), defense techniques and security best practices, including language-specific security practices and present-day threats
  • Experience with modern application development languages and frameworks (e.g., , Java, Golang, Python, React, Angular)
  • Experience securing infrastructure, applications and services in AWS

Preferred Qualifications

  • Experience with assessing and securing large, complex SaaS applications
  • One or more relevant security certifications (e.g., CISSP, CISM, CEPT, CMWAPT, CPT, CEH, LPT, GWAPT, GPEN, GXPN, OSCP, AWS Certified Security - Specialty Certification)
  • Some prior experience as a team, technical or project lead
  • Use of agile methodologies for project management
  • Manual web application penetration testing experience, including the use of professional penetration testing tools (e.g., Burp Suite)
  • Strong familiarity with AWS, Docker, Kubernetes, Linux and similar technologies
  • Experience securing iOS/Android mobile apps
  • Prior full time software development experience

Our Team's Favourite Perks and Benefits

  • Annual Leave: 20 or 26 annual leave days per annum plus an additional day for each year of service (to a max of 5).
  • Private Medical Insurance- Luxmed health & dental cover for you and your dependants.
  • Commuter Assistance- Up to the value of 80 PLN net a month for public transport.
  • Savings Plan- Two company saving plans provided by Nationale Nederlanden: Employee Capital Plan (PPK) & Employee Saving Plan (PPO)
  • QED PROGRAM- Qualtrics Engineer Development (QED) program: support, engineering learning activities up to 10% of engineering work time each quarter.
  • Wellness- Up to the value of 800PLN gross per quarter can be reimbursed for a variety of wellness activities via our dedicated platform Twic.
  • A choice of Multispot cards available.
  • Our employee assistance program with Unum provides counselling and wellbeing support to all employees
  • Experience bonus- 7000 PLN gross per annum. Qualtrics experience bonus is a program designed to provide experiences to our employees they might not otherwise have.
  • Group Life & Income Protection Insurance
  • Glasses/Contact lenses Reimbursement
  • Free breakfasts, lunches, snacks, and drinks for everyone in the office
  • Tax-deductible expenses (up to 75% depending on role)

Qualtrics is an equal opportunity employer meaning that all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other protected characteristic.
​​​​​​​
Applicants in the United States of America have rights under Federal Employment Laws: Family & Medical Leave Act, Equal Opportunity Employment, Employee Polygraph Protection Act

Qualtrics is committed to the inclusion of all qualified individuals. As part of this commitment, Qualtrics will ensure that persons with disabilities are provided with reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please let your Qualtrics contact/recruiter know.

Qualtrics Work Experience - As we look to the future, we believe that our teams are better together. Being together will help us learn more, grow faster and ultimately deliver better results for our customers and Qualtrics. Roles tied to an office location work 4 days per week in the office together and 1 day from home, with a strong spirit of flexibility around taking time for personal, health, and family moments in our work weeks. Our managers work with their teams to create a collaborative, engaged work environment, and arrangement that works for each of our team members.

Not finding a role that's the right fit for now? Qualtrics Insiders is the one-stop shop for all things Qualtrics Life. Sign up for exclusive access to content created with you in mind and get the scoop on what we have going on at Qualtrics - upcoming events, behind the scenes stories from the team, interview tips, hot jobs, and more. No spam - we promise You'll hear from us two times a month max with fresh, totally tailored info - so be sure to stay connected as you explore your best role and company fit.

  • Kraków, Lesser Poland Qualtrics Pełny etat

    Senior Security Engineer, Platform Security Qualtrics Know what your customers and employees need, when they need it, and deliver it every time with powerful, AI driven Experience Management (XM) software. View company page At Qualtrics, we create software the world's best brands use to deliver exceptional frontline experiences, build high-performing...


  • Kraków, Lesser Poland Qualtrics Pełny etat

    At Qualtrics, we create software the world's best brands use to deliver exceptional frontline experiences, build high-performing teams, and design products people love. But we are more than a platform—we are the creators and stewards of the Experience Management category serving over 18K clients globally. Building a category takes grit, determination, and...


  • Kraków, Lesser Poland ASSA ABLOY Pełny etat

    Senior Security Operations EngineerDo you want to be part of a successful team providing top engineering access control solutions to the market? Join us in Krakow, Poland and enjoy a collaborative culture where you can build a career you'll be proud of.What You'll Do as Our Senior Security Operations EngineerContribute to driving a standard secure network...


  • Kraków, Lesser Poland Backbase Pełny etat

    Senior Application Security EngineerLooking for a journey instead of a job? Then let's talk We are THE pioneers in banking tech. We see opportunities and take the leap. Having the guts to push limits and break barriers to make things happen. We learn and reinvent ourselves for maximum impact, never giving up. We are creators, with a customer-centric mindset...

  • Security Engineer

    2 tygodni temu


    Kraków, Lesser Poland AirHelp Pełny etat

    Security EngineerDepartment: EngineeringEmployment Type: Full TimeLocation: KrakówReporting To: Head of SecurityDescriptionAre you excited about delivering reliable services to clients and are proactive about risk management and strategic security initiatives? Then join us as a Security Engineer. As a team, we are here to implement and manage security...


  • Kraków, Lesser Poland Securitas Security Services USA, Inc. Pełny etat

    Securitas Security Services USA, Inc. Security Specialist Concierge San Francisco , California Apply Now At Securitas we help make your world a safer place.Securitas is a global company that offers the most advanced and sustainable security solutions in the industry. We are located in 47 countries and have 355,000 employees worldwide and over 150,000...

  • Security Engineer

    2 tygodni temu


    Kraków, Lesser Poland Verisk Pełny etat

    Join Verisk's Global Enterprise Information Security Team and be part of the new Center of Excellence in Poland.As a Security Engineer, you'll have a great opportunity to enhance your security automation skills using Artificial Intelligence. Your role is vital in strengthening cybersecurity resilience and protecting our systems from evolving threats.Main...

  • Staff Security Engineer

    2 tygodni temu


    Kraków, Lesser Poland Clari Pełny etat

    Clari's Revenue platform gives forecasting accuracy and visibility from the sales rep to the board room on revenue performance -helping them spot revenue leak to answer if they will meet, beat, or miss their sales goals. With insights like this, no wonder leading companies worldwide, including Okta, Adobe, Workday, and Zoom use Clari to drive revenue...

  • Senior Security Engineer

    2 tygodni temu


    Kraków, Lesser Poland Remitly Poland Sp. z o.o. Pełny etat

    Senior Security Engineer - Detection & Response page is loaded Senior Security Engineer - Detection & Response Apply locations Krakow, Poland time type Full time posted on Posted 30+ Days Ago job requisition id R_101748 Job Description:Remitly's vision is to transform lives with trusted financial services that transcend borders. Since 2011, we have been...


  • Kraków, Lesser Poland Gpc Global Technology Center Pełny etat

    Technologies-expected : Git Lab Azure Dev Ops Security about-project : As we continue to scale and evolve, it has become increasingly important for us to protect our applications.That's why we're looking for an experienced Senior Security Engineer in the area of application security for AI systems.Join our Gen AI team and contribute to the development of our...

  • Senior Security Engineer

    2 tygodni temu


    Kraków, Lesser Poland Remitly Pełny etat

    Senior Security Engineer Kraków, Lesser Poland Voivodeship Remitly's vision is to transform lives with trusted financial services that transcend borders. Since 2011, we have been tirelessly delivering on our promises to people who send money around the world. Today, we are reimagining global financial services and building products that extend beyond...

  • Security Engineer

    2 tygodni temu


    Kraków, Lesser Poland Certara Pełny etat

    Overview Security Engineer plays a key part for correlation rules and dashboard creation and support the rest of the team. The Security Engineer works in a team with an investigative spirit, good perception, and judgment of the security landscape. The Security Engineer will help develop our strategy for finding innovative ways to monitor our...

  • Senior Security Engineer

    2 tygodni temu


    Kraków, Lesser Poland Remitly Pełny etat

    Senior Security Engineer - Detection & Response Remitly Transfer money internationally to 170+ countries and 100+ currencies with no hidden fees. Receive funds securely using convenient delivery options. View company page Remitly's vision is to transform lives with trusted financial services that transcend borders. Since 2011, we have been tirelessly...

  • Mid-Senior PHP Engineer

    2 tygodni temu


    Kraków, Lesser Poland Nord Security Pełny etat

    The Backend department uses modern and innovative technologies to create our world-leading cybersecurity products. We have squads that work towards different goals, but we are mainly known as driven professionals writing quality code. Main Responsibilities Write clear, tested, documented code that delivers real business value;Be involved in creating API's...


  • Kraków, Lesser Poland Backbase Inc. Pełny etat

    Looking for a journey instead of a job? Then let's talk We are THE pioneers in banking tech. We see opportunities and take the leap. Having the guts to push limits and break barriers to make things happen. We learn and reinvent ourselves for maximum impact, never giving up. We are creators, with a customer-centric mindset that love what they do and bring fun...


  • Kraków, Lesser Poland GPC Global Technology Center Pełny etat

    As we continue to scale and evolve, it has become increasingly important for us to protect our applications. That's why we're looking for an experienced Senior Security Engineer in the area of application security for AI systems. Join our GenAI team and contribute to the development of our latest products and services.ResponsibilitiesUse technical skills and...

  • Senior Security Engineer

    2 tygodni temu


    Kraków, Lesser Poland IBM Pełny etat

    IntroductionAt IBM, work is more than a job - it's a calling: To build. To design. To code. To consult. To think along with clients and sell. To make markets. To invent. To collaborate. Not just to do something better, but to attempt things you've never thought possible. Are you ready to lead in this new era of technology and solve some of the world's most...

  • Security Engineer

    2 tygodni temu


    Kraków, Lesser Poland Verisk Pełny etat

    Verisk The world's most effective and responsible data analytics company in pursuit of our customers' most strategic opportunities. View company page We help the world see new possibilities and inspire change for better tomorrows. Our analytic solutions bridge content, data, and analytics to help business, people, and society become stronger, more...


  • Kraków, Lesser Poland Zendesk Pełny etat

    Job DescriptionThe Product Security org at Zendesk build and maintain tooling to detect and prevent vulnerabilities, safeguarding Zendesk's customers, products and services. We partner with our engineers to prioritize security during the entire software development process and provide tools and programs to do so including, but not limited to, a mature bug...


  • Kraków, Lesser Poland Backbase Pełny etat

    Backbase We are the pioneers of Engagement Banking. Our industry-leading platform helps banks and other financial institutions get closer to their customers like... View company page Keep millions of mobile users (and software) safe and secure as they enjoy everything their bank has to offer, wherever they may be.Meet the jobNo day at Backbase is the same,...