XTB

Senior Security Engineer

XTB Warsaw, Masovian Voivodeship, Poland

Financial Services · 1,001-5,000 employees

Yesterday
Remote security Senior (5-10 yrs) Full-time Poland
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Senior Security Engineer will manage ICT security incidents, maintain cybersecurity tools, and oversee vulnerability assessments across network, web, mobile, and cloud environments. They will also support threat modeling processes and conduct security training for internal teams.

What they look for

Security incident response Vulnerability management Threat modeling Penetration testing Blue teaming Red teaming Cloud security Network security Python Bash CI/CD Risk assessment Security architecture Technical documentation Cybersecurity training

Requirements

Candidates must have at least 5 years of technical experience in IT security, including expertise in either Blue Teaming or Red Teaming. Strong communication skills in English and practical knowledge of security controls for operating systems, networks, and cloud environments are required.

Benefits

Training budget Extra day off on birthday Extra day off for parents Equipment tailored to needs Private medical care Group insurance E-learning platform access Benefits platform Wellbeing platform Private therapy sessions

Full description

XTB is a global company from the financial industry, focusing on online trading of financial instruments. We are the largest FinTech in Poland and a leader in Central and Eastern Europe, and the range of our operations covers several countries, including Asia and South America. At XTB, we focus on the development of our employees, giving them opportunities to gain knowledge and skills in various fields, as well as offering a number of training and development programs. If you are looking for challenges and want to gain valuable experience in an international business environment, XTB is the right place for you.

We are a certified Great Place to Work company.

We are looking for a candidate to join our team as a Senior Security Engineer. In this role, you will serve as a key technical expert, combining deep competencies in both defensive and offensive security. Your primary goal will be to ensure the security of ICT processes and assets. You will also collaborate regularly with IT teams, DevOps, and Product Managers.

\n

Responsibilities

• Detection & Security Incident Response: Responding to and handling ICT security incidents, alongside operational support for the monitoring process.

• Security Tools & Solutions: Maintaining, evaluating, and implementing new cybersecurity tools and solutions.

• Vulnerability Management: Managing vulnerability scans, as well as executing the vulnerability assessment and mitigation process for networks, web & mobile environments, on-premises, and cloud infrastructure in cooperation with technology teams.

• Threat Modeling & Assessment: Supporting the threat modeling process from an attacker’s perspective, including reviewing and testing IT systems for secure configuration.

• Best Practices & Training: Establishing and promoting security best practices, including preparing and conducting cybersecurity training sessions.

Requirements

• Minimum 5 years of technical experience in the IT security domain (e.g., Security Engineer, Pentester, L3 SOC Analyst).

• Practical technical knowledge and experience in either Blue Teaming (monitoring, incident handling and analysis, security tool maintenance) or Red Teaming (penetration testing, vulnerability assessment).

• Experience conducting vulnerability scans, risk assessments, and creating technical documentation, procedures, and security guidelines.

• Practical knowledge of security controls for operating systems, computer networks, web/mobile applications, and cloud environments.

• Strong skills and experience in conducting training sessions and collaborating with development teams, DevOps, and business stakeholders.

• Good command of English enabling effective communication.

Nice to have

• Knowledge of industry standards, regulations, and best practices supported by training, courses, or certifications (e.g., OSCP, CEH, CISSP, ISO/IEC 27001, etc.).

• Practical experience in managing the ICT incident response process and security tool architecture.

• Practical scripting and automation skills (e.g., Python, Bash) and familiarity with CI/CD processes.

What we offer

  • Real influence on the development of the company and the product.
  • Work in an experienced team that is happy to share its knowledge.
  • A clear vision of development thanks to regular feedback and clear career paths.
  • Regular team-building meetings.

Benefits

  • A training budget for courses and conferences that interest you.
  • An extra day off on your birthday.
  • An extra day off for parents.
  • Equipment tailored to your needs.
  • Private medical care and group insurance.
  • Access to an e-learning platform for learning English and a benefits platform.
  • Access to a wellbeing platform and the opportunity to take advantage of workshops and private therapy sessions.
  • Remote work, from the office in Warsaw or from a coworking space in your city.

\n

Similar roles