Security Engineer Poland

3 dni temu

Kielce, Województwo świętokrzyskie, Polska Virtus Lab Sp. z o.o. All trademarks their respective owners Pełny etat 180 000 zł - 300 000 zł Umowa

VirtusLab is a leading European software consulting and engineering company. Our mission is to craft clean code and practical solutions with precision and purpose. We foster a dynamic culture rooted in strong engineering, a sense of ownership, and transparency, empowering professionals to make a substantial impact in the software industry.

About the Engagement

Shape the future of a rapidly scaling UK insurance leader. The scope of cooperation encompasses supporting security operations within a modern security stack and streamlining integration capabilities to unify a high-growth MGA and brokerage ecosystem. Core deliverables include contributing to incident response operations, managing AV/EDR mechanisms, developing and updating security policy frameworks, optimizing SIEM operations, and driving IAM hardening initiative.

Networking Security Regular

Azure Security Regular

Zero Trust Concepts Regular

Infrastructure as a Code Regular

Entra Internet Access & Private Access Nice to have

Project

Enterprise Security E2E

Project Scope

Establishing a modern, enterprise-grade security function for one of the UK’s fastest-growing Managing General Agents and brokerage groups. The end-client operates across three continents with entities spanning the UK, Europe, and Asia-Pacific, expanding dynamically through M&A operations.

The scope focuses on hardening a complex hybrid Microsoft environment, unifying fragmented security tooling across a multi-entity ecosystem, and driving a consistent, governed, and resilient security baseline across the entire Group.

Legacy, reactive security practices are being replaced with a Zero Trust architecture – deploying Microsoft’s full security stack across identity, endpoints, cloud apps, data, and network. The project aims at strengthening detection and response capabilities to protect a high-growth insurance business operating under Lloyd’s, UK GDPR, and MAS regulatory frameworks.

Key Deliverables & Challenges

The primary objective is hardening the Group’s security posture across a multi-entity structure and building operational capabilities to detect, respond to, and recover from security events. Main areas of engagement:

  • Deploying and Optimizing Microsoft Defender XDR: Onboarding entities to Defender for Endpoint, Defender for Identity, and Defender for Cloud Apps, alongside integrating operational signals into Microsoft Sentinel as the central SIEM/SOAR platform.

  • Identity and Access Hardening: Implementing Zero Trust identity controls including phishing-resistant MFA, Privileged Identity Management (PIM), Conditional Access policies, and Active Directory security hardening across hybrid on-premises and Entra ID environments.

  • Security Operations & Incident Response: Co-operating with external MDR providers to optimize operational response workflows.

  • Security Policy Standardization: Developing, documenting, and monitoring compliance with security baselines, configuration standards, and control frameworks across all Group entities worldwide.

  • Cloud and SaaS Security Governance: Securing M365, Azure, and the broader SaaS ecosystem through Purview data classification, DLP policies, MDCA session controls, and continuous posture management.

  • M&A Security Integration: Execution of a repeatable security onboarding framework for newly acquired entities during continuous business expansion.

The engagement takes place within a lean, agile project environment delivering complete security stack coverage across DevOps, Infrastructure Engineering, Security Engineering, and Business Analysis domains, requiring close cross-functional alignment with business stakeholders to facilitate effective knowledge transfer and strict integration with strategic goals.

Required Technical Expertise & Capabilities

  • 5+ years of track record in Cloud/SaaS Infrastructure Security consulting or engineering engagements.
  • Hands-on expertise with Microsoft Security Stack including Entra ID, Microsoft Defender, Intune, Network Security, and Cloud Security.
  • Proficiency in security practices: incident response, security analysis, and posture hardening.
  • Demonstrated experience in securing and maintaining Microsoft Stack services.
  • Experience with insurance infrastructure ecosystems is a plus.
  • Formal background in Computer Science, STEM, or equivalent practical industry expertise.
  • English communication skills at B2+ level or higher.
  • Familiarity with security standards and compliance frameworks such as ISO 27001 / SOC-2 is advantageous.

A few perks of being with us

  • Building tech community
  • Home office reimbur