OANDA

Lead Security Engineer

OANDA · Krakow, Lesser Poland Voivodeship, Poland

Financial Services · 201-500 employees

14 h ago
Senior (5-10 yrs) Full-time Poland
Log in to apply, save this posting, or score it against your profile with AI.

About the role

Lead and mentor a security engineering team while designing and building security-critical features for online trading platforms. Implement automated security tools into CI/CD pipelines and harden infrastructure across cloud and on-premise environments.

What they look for

Security Engineering DevSecOps Infrastructure-as-code Cloud Security Go Python JavaScript C++ Java SAST DAST Kubernetes Docker Cryptography Risk Assessment Team Leadership

Requirements

Requires 5+ years of experience in core engineering and DevSecOps, with 1-3 years of supervisory experience. Candidates must hold a university degree in a technical field and possess strong proficiency in modern programming languages and security frameworks.

Full description

Fancy helping to shape the future of FinTech? We have always been innovators. In 1996 we were the first company to share exchange rate information, free of charge on the internet. Today, we are a world leading online trading group.

Join us to:

  • Help build the future of online trading 
  • Be part of a culture driven by integrity and global impact
  • Become part of an award-winning company - check out our full list of awards here

We are only as good as our people. Luckily, our people are the best. Join us! 

How do we work?

We believe that security shouldn't be a bottleneck or an afterthought - we bake it directly into everything we build. As a team, we operate on a "push security left" philosophy, meaning we collaborate deeply with our engineering and product teams early in the development lifecycle rather than checking things at the very end. We value cross-functional flexibility, strong defense-in-depth principles, and continuous automation. On any given week, you might find yourself switching gears from cloud hardening and writing infrastructure-as-code to reviewing application vulnerability fixes, advising on secure AI governance, or mentoring engineers. We foster an open, supportive culture where diverse technical opinions are brought together to solve complex problems, and where we actively invest in our people's professional growth and industry presence.

In this role, you will:

  • Lead & Mentor: Manage and guide a talented Security Engineering team, organizing work processes, tracking strategic goals, and actively mentoring team members to level up their technical and professional skills.
  • Build Secure Software: Directly design and build security-critical features (like authentication, authorization, 2FA, and transaction integrity components), and navigate security pitfalls across various languages like Go, Python, JS, C++, and Java.
  • Champion DevSecOps & AI Security: Scale our impact by embedding automated security tools (SAST, DAST, SCA, Secrets, fuzzing) into our CI/CD pipelines, and establish security gates and governance for the safe deployment of AI technologies.
  • Implement Defense-in-Depth: Harden environments across both on-premise and cloud-native infrastructure—including databases, networks, Docker containers, and Kubernetes clusters.
  • Make Security Accessible: Instrument and share meaningful security metrics with business stakeholders, and automate workflows (e.g., via ChatOps) to make proactive security practical and visible for everyone.
  • Assess Risk & Drive Strategy: Author security standards, collaborate with Security Operations to stay ahead of upcoming threats, and maintain top-tier cryptographic and secrets management practices.
  • Grow the Team: Contribute to defining talent needs, resource planning, reviewing resumes, and shaping our engineering interview process.

What skillset do you need to be successful in this role?

  • 5+ years of solid experience rooted in core engineering principles and DevSecOps, alongside 1 to 3 years of experience supervising, scheduling, and directing technical teams.
  • A strong background in infrastructure concepts (networking, databases, cloud, and on-premise setups) and the ability to confidently develop/code in at least a few modern languages (Go, Python, JS, C++, Java).
  • Proven capability in triaging, tracking, and remediating SAST, IaC, supply-chain, and Secrets vulnerabilities.
  • A university degree in Computer Science, Computer Engineering, or a related discipline, backed by industry certifications such as CISSP, CCSP, or cloud-specific security credentials.
  • Working knowledge of major security frameworks and compliance standards (e.g., SOC2, ISO27001/2, NIST, OWASP, SANS).
  • Exceptional project management skills, independent problem-solving ability, and the emotional intelligence to manage minor team conflicts and collaborate seamlessly across departments.

Nice to have:

  • Hands-on experience or specialized knowledge in securing AI development processes and AI tools.
  • Experience in the Financial or FinTech industry, or a strong familiarity with the specific threat landscapes and regulatory obligations that come with it.
  • A passion for staying connected to the broader security community (attending or participating in events like RSA, DefCon, or BSides).

___

At OANDA, to help us efficiently process applications, we use AI-driven tools to help source and rank candidates based on professional experience and skills. While these tools provide recommendations, our recruitment process remains human-centric: all final shortlisting and hiring decisions are made by OANDA team. You have the right to request a human review of your application.

OANDA Global Corporation is a diverse and global team with offices around the world. We value the unique skills and experiences each individual brings to OANDA. We are committed to creating and sustaining a collegial work environment in which all individuals are treated with dignity and respect and one which reflects the diversity of the community in which we operate. We provide an inclusive and accessible environment for everyone. Candidates selected for an interview will be contacted directly. If you require accommodation during the recruitment and selection process, please let us know. We will work with you to provide as seamless a recruitment experience as possible.

Learn more about our culture here.

Review OANDA Privacy Policy and learn more about how we treat your personal data and protect your privacy.