Security Engineering Manager, Platform Security

4 tygodni temu


Kraków, Lesser Poland Qualtrics Pełny etat

At Qualtrics, we create software the world's best brands use to deliver exceptional frontline experiences, build high-performing teams, and design products people love. But we are more than a platform—we are the creators and stewards of the Experience Management category serving over 18K clients globally. Building a category takes grit, determination, and a disdain for convention—but most of all it requires close-knit, high-functioning teams with an unwavering dedication to serving our customers.When you join one of our teams, you'll be part of a nimble group that's empowered to set aggressive goals and move fast to achieve them. Strategic risks are encouraged and complex problems are solved together, by passing the microphone and iterating until the best solution comes to light. You won't have to look to find growth opportunities—ready or not, they'll find you. From retail to government to healthcare, we're on a mission to bring humanity, connection, and empathy back to business. Join over 6,000 people across the globe who think that's work worth doing.

Security Engineering Manager, Platform Security

The challenge

As Qualtrics continues to expand the Experience Management (XM) SaaS platform, we must ensure that we're protecting our customers and their data by building and operating secure systems. With over one thousand software & system engineers contributing to Qualtrics XM every day, we have a large attack surface to evaluate and secure. This role is critical to our mission.

Qualtrics is seeking an experienced security engineer with a passion for security and demonstrated leadership abilities to manage a platform security team. This is a new role reporting to the Head of Platform Security that includes a mix of people management, hiring, strategy, program operations and hands-on security engineering responsibilities.

The Platform Security team is responsible for measures to improve and ensure the security of web & mobile applications, code and related components, underlying infrastructure and cloud services in Qualtrics SaaS products (including those of our acquired companies). The team owns secure development standards and training, security testing tools (e.g., SAST, DAST, SCA, container vulnerability management, CSPM), threat modeling, penetration testing, red team, bug bounty, and vulnerability disclosure and vulnerability management programs. Platform Security works in collaboration with other teams within the Information Security organization (including vulnerability management, security operations and incident response, and security & privacy assurance) and across the Product Engineering organization.

A day in Life

  • Develop and execute the platform security architecture and program strategy; align and communicate roadmaps with stakeholders
  • Support and manage a team of security engineers through regular 1-on-1 sessions and team meetings, coaching, workload management and performance reviews
  • Review source code & software/system designs, and consult with engineers across the organization to identify and/or avoid security issues through alignment with security standards and best practices
  • Leverage your accumulated subject matter expertise of Qualtrics applications, systems, code and infrastructure to propose and drive architectural improvements which address classes of security flaws in the platform
  • Document and improve secure development lifecycle processes, standards and guidelines
  • Deliver training and provide mentoring to software engineers on security topics
  • Facilitate threat modeling exercises to ensure optimized security design decisions are being made
  • Document remediation recommendations and collaborate with engineers to ensure vulnerability findings are successfully and efficiently addressed
  • Support bug bounty and vulnerability disclosure programs, including the triage and validation of reported findings
  • Direct the selection, design, development, implementation and management of automated security testing tools; maintain relationships with product vendors and manage contract lifecycles
  • Support Platform Security-owned tools and services which are relied upon by other organizations, including those in support of the vulnerability management program
  • Coordinate with Platform Security counterparts based in the United States to align efforts

The Expectation for Success

You will define and drive improvements to the product and application security program; hire, mentor, and support a team of skilled security engineers; and work effectively with the Qualtrics engineering organization and fellow security team members to protect our customers and their data by building and operating secure systems.

Minimum Qualifications

  • Bachelor's degree in Computer Science or a related field
  • Over 12 years of relevant work experience
  • Experience as a senior/staff/lead security engineer in product, application, infrastructure and/or cloud security
  • Experience leading complex security projects and initiatives that require collaboration with teams across an organization
  • Sound understanding of application & cloud security vulnerabilities (e.g., OWASP Top 10), defense techniques and security best practices, including language-specific security practices and present-day threats
  • Experience with modern application development languages and frameworks (e.g., , Java, Golang, Python, React, Angular)
  • Experience securing infrastructure, applications and services in AWS

Preferred Qualifications

  • Experience with assessing and securing large, complex SaaS applications
  • One or more relevant security certifications (e.g., CISSP, CISM, CEPT, CMWAPT, CPT, CEH, LPT, GWAPT, GPEN, GXPN, OSCP, AWS Certified Security - Specialty Certification)
  • Two or more years of experience as a people manager
  • Use of agile methodologies for project management
  • Manual web application penetration testing experience, including the use of professional penetration testing tools (e.g., Burp Suite)
  • Strong familiarity with AWS, Docker, Kubernetes, Linux and similar technologies
  • Experience securing iOS/Android mobile apps
  • Prior full time software development experience

Our Team's Favourite Perks and Benefits

    • Annual Leave: 20 or 26 annual leave days per annum plus an additional day for each year of service (to a max of 5).
    • Private Medical Insurance- Luxmed health & dental cover for you and your dependants.
    • Commuter Assistance- Up to the value of 80 PLN net a month for public transport.
    • Savings Plan- Two company saving plans provided by Nationale Nederlanden: Employee Capital Plan (PPK) & Employee Saving Plan (PPO)
    • QED PROGRAM- Qualtrics Engineer Development (QED) program: support, engineering learning activities up to 10% of engineering work time each quarter.
    • Wellness- Up to the value of 800PLN gross per quarter can be reimbursed for a variety of wellness activities via our dedicated platform Twic.
    • A choice of Multispot cards available.
    • Our employee assistance program with Unum provides counselling and wellbeing support to all employees
    • Experience bonus- 7000 PLN gross per annum. Qualtrics experience bonus is a program designed to provide experiences to our employees they might not otherwise have.
    • Group Life & Income Protection Insurance
    • Glasses/Contact lenses Reimbursement
    • Free breakfasts, lunches, snacks, and drinks for everyone in the office
    • Tax-deductible expenses (up to 75% depending on role)

Qualtrics is an equal opportunity employer meaning that all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other protected characteristic.
​​​​​​​
Applicants in the United States of America have rights under Federal Employment Laws: Family & Medical Leave Act, Equal Opportunity Employment, Employee Polygraph Protection Act

Qualtrics is committed to the inclusion of all qualified individuals. As part of this commitment, Qualtrics will ensure that persons with disabilities are provided with reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please let your Qualtrics contact/recruiter know.

Qualtrics Work Experience - As we look to the future, we believe that our teams are better together. Being together will help us learn more, grow faster and ultimately deliver better results for our customers and Qualtrics. Roles tied to an office location work 4 days per week in the office together and 1 day from home, with a strong spirit of flexibility around taking time for personal, health, and family moments in our work weeks. Our managers work with their teams to create a collaborative, engaged work environment, and arrangement that works for each of our team members.

Not finding a role that's the right fit for now? Qualtrics Insiders is the one-stop shop for all things Qualtrics Life. Sign up for exclusive access to content created with you in mind and get the scoop on what we have going on at Qualtrics - upcoming events, behind the scenes stories from the team, interview tips, hot jobs, and more. No spam - we promise You'll hear from us two times a month max with fresh, totally tailored info - so be sure to stay connected as you explore your best role and company fit.

  • Kraków, Lesser Poland Qualtrics Pełny etat

    Senior Security Engineer, Platform Security Qualtrics Know what your customers and employees need, when they need it, and deliver it every time with powerful, AI driven Experience Management (XM) software. View company page At Qualtrics, we create software the world's best brands use to deliver exceptional frontline experiences, build high-performing...

  • Security Manager

    2 tygodni temu


    Kraków, Lesser Poland Tripadvisor Pełny etat

    Viator: Unleashing Extraordinary ExperiencesViator, a part of the esteemed Tripadvisor family, stands out as the go-to hub for a wide array of travel adventures. Emphasizing the creation of lasting memories, we offer over 300,000 travel experiences, ranging from leisurely tours to thrilling escapades and everything intriguing in between. Within our platform,...


  • Kraków, Lesser Poland Qualtrics Pełny etat

    At Qualtrics, we create software the world's best brands use to deliver exceptional frontline experiences, build high-performing teams, and design products people love. But we are more than a platform—we are the creators and stewards of the Experience Management category serving over 18K clients globally. Building a category takes grit, determination, and...


  • Kraków, Lesser Poland Qualtrics Pełny etat

    At Qualtrics, we create software the world's best brands use to deliver exceptional frontline experiences, build high-performing teams, and design products people love. But we are more than a platform—we are the creators and stewards of the Experience Management category serving over 18K clients globally. Building a category takes grit, determination, and...


  • Kraków, Lesser Poland Securitas Security Services USA, Inc. Pełny etat

    Securitas Security Services USA, Inc. Security Specialist Concierge San Francisco , California Apply Now At Securitas we help make your world a safer place.Securitas is a global company that offers the most advanced and sustainable security solutions in the industry. We are located in 47 countries and have 355,000 employees worldwide and over 150,000...

  • Staff Security Engineer

    2 tygodni temu


    Kraków, Lesser Poland Clari Pełny etat

    Clari's Revenue platform gives forecasting accuracy and visibility from the sales rep to the board room on revenue performance -helping them spot revenue leak to answer if they will meet, beat, or miss their sales goals. With insights like this, no wonder leading companies worldwide, including Okta, Adobe, Workday, and Zoom use Clari to drive revenue...

  • Security Engineer

    2 tygodni temu


    Kraków, Lesser Poland AirHelp Pełny etat

    Security EngineerDepartment: EngineeringEmployment Type: Full TimeLocation: KrakówReporting To: Head of SecurityDescriptionAre you excited about delivering reliable services to clients and are proactive about risk management and strategic security initiatives? Then join us as a Security Engineer. As a team, we are here to implement and manage security...


  • Kraków, Lesser Poland FLYR, Inc. Pełny etat

    Flight Itinerary (About The Role)Manage & lead an organizational team that partners with product and delivery engineering teams to provide customers with platform capabilities and reliable services for FLYR's evolving product portfolio. The Platform Engineering Function is one of our teams at the center of our strategy for scaling, and constantly improving...


  • Kraków, Lesser Poland GFT Technologies Pełny etat

    You will work with and learn from top IT experts. You will join a crew of experienced engineers: 70% of our employees are senior level. You will be part of QA community composed of over 100 engineers.Interested in the cloud ? You will enjoy our full support in developing your skills: training programs, certifications and our internal community of experts. We...

  • Security Analyst

    2 tygodni temu


    Kraków, Lesser Poland Software Mind Pełny etat

    Software Mind A software house that provides software development services to boost product engineering and digital transformation capabilities. View company page We are Software Mind, an awesome team of engineers who are ready to ramp up any top-notch company's projects Our aim? To always be one step ahead. Become part of a multicultural company in...


  • Kraków, Lesser Poland ITDS Business Consultants Pełny etat

    Security Engineer – Antimalware Endpoint SecurityJoin us, and enhance security across global infrastructuresKrakow-based opportunity with the possibility to work 100% remotelyAs a Security Engineer – Antimalware Endpoint Security, you will be working for our client, a global financial services organization focused on safeguarding its vast network and...


  • Kraków, Lesser Poland Motorola Solutions Pełny etat

    At Motorola Solutions, we're guided by a shared purpose - helping people be their best in the moments that matter - and we live up to our purpose every day by solving for safer. Because people can only be their best when they not only feel safe, but are safe. We're solving for safer by building the best possible technologies across every part of our safety...

  • Engineering Manager

    2 tygodni temu


    Kraków, Lesser Poland Avsystem Pełny etat

    Engineering Manager at AVSystem Location: AVSystem Technologies Expected: Jira, Gitlab, Java, Scala We are looking for an Engineering Manager to lead our team for the Coiote Io T Device Management Platform at AVSystem. If you are enthusiastic about Io T and ready to make a difference, we welcome you onboard. Role Requirements: Worked as a Software...

  • Security Engineer

    2 tygodni temu


    Kraków, Lesser Poland IBM Pełny etat

    IntroductionAt IBM, work is more than a job - it's a calling: To build. To design. To code. To consult. To think along with clients and sell. To make markets. To invent. To collaborate. Not just to do something better, but to attempt things you've never thought possible. Are you ready to lead in this new era of technology and solve some of the world's most...

  • Security Risk Analyst

    2 tygodni temu


    Kraków, Lesser Poland Experis ManpowerGroup Sp. z o.o. Pełny etat

    Conducting risk assessments (ideally of third-party vendors) against security standards, such as ISO 27001 and NIST Understanding of concepts of cyber security controls in IT areas (e.g. Access management, Application security) Knowledge of security assessments methodology Analyzing and evaluating security controls and documentation policies (evidence) ...


  • Kraków, Lesser Poland Hsbc Service Delivery Pełny etat

    About-project : Operating within the Cybersecurity Global Defence function and under the management of the Global Head of Cybersecurity Operations, the Global Cybersecurity Operations (GCO) team provides a coordinated suite of "Network Defence" related services and are responsible for the detection and response to information and cybersecurity threats across...


  • Kraków, Lesser Poland GFT TECHNOLOGIES SE Pełny etat

    Select how often (in days) to receive an alert: Cloud Security Delivery Specialist Date: May 17, 2024 Location: Kraków, PL, Poznań, WP, PL, Warszawa, PL, Łódź, PL, Working place: Remote / Hybrid You will work with and learn from top IT experts. You will join a crew of experienced engineers: 70% of our employees are senior level. Interested in...

  • Cyber Security Engineer

    2 tygodni temu


    Kraków, Lesser Poland KION Group Pełny etat

    The KION Group is a world-leading supplier of forklift trucks, warehouse technology and supply chain solutions, which require modern and advanced IT Services. To strengthen KION's Business Strategy and IT capabilities, the new IT Service Hub has been built in Kraków as part of KION Business Services.The IT Hub is the center of highly qualified IT talents...


  • Kraków, Lesser Poland Experis ManpowerGroup Sp. z o.o. Pełny etat

    We are seeking a highly motivated and organized individual to join our team as an Information Security Officers (ISO) Assistant. In this role, you will provide crucial support in overseeing and managing the organization's Global Security program for the EU region. The ideal candidate will have a strong understanding of cybersecurity principles, exceptional...


  • Kraków, Lesser Poland Cognizant Technology Solutions Pełny etat

    Location: Poland, KrakówWhat we do:As Top Employer, we are dedicated to helping the world's leading companies build stronger businesses — helping them go from doing digital to being digital. Cognizant Poland offices are in Gdansk, Wroclaw, and Kraków. With the capacity to support various clients, we offer a world of opportunities for both professionals...