Mid Cybersecurity Engineer - eBilet
Warszawa, PL, 00-841 Poznań, PL, 61-569
Join the Allegro Cybersecurity team! In this role, you will work closely with eBilet team, safeguarding one of the most visible and high-scale platforms in the region. High performance, engineering best practices and a great atmosphere guaranteed!
Important things for you:
-
Flexible working hours in the hybrid model (4/1) - working hours start between 7:00 a.m. and 9:00 a.m. We also have 30 days of occasional remote work.
-
Annual bonus based on your annual performance and company results.
-
Our team is based in Warsaw and Poznań.
About the job:
-
Take ownership of eBilet’s day-to-day security work, from identifying risks and planning improvements to implementing controls, testing them and following up on findings.
-
Help teams include security throughout the software development lifecycle through threat modelling, design reviews, security requirements and automated checks.
-
Improve the security of applications, infrastructure and cloud environments through hardening, vulnerability management and hands-on security testing.
-
Bring Allegro Group’s security standards into eBilet’s day-to-day work, adapting them in cooperation with product, engineering and operations teams.
-
Use automation and AI to make security work more effective, assess risks related to AI technologies and design controls to prevent, detect and respond to them.
Skills required:
-
You take initiative and can own security work from identifying a need to implementing a solution and checking that it works.
-
You have practical experience in application, infrastructure or cloud security (Azure), and understand how these areas connect.
-
You know how to build security into the software development lifecycle, for example through threat modelling, security requirements, design reviews and secure development practices.
-
You can assess technical risks, prioritize vulnerabilities and work with engineering teams to get findings fixed.
-
You have experience with security testing, such as application or infrastructure testing, code reviews or penetration tests.
-
You understand security hardening (Windows/Linux/cloud), including access controls, secure configuration, patching, secrets management and logging.
-
You can turn security standards and policies into practical controls that work for a business and its technology teams.
-
You communicate clearly, build good working relationships and can explain security issues to both technical and non-technical colleagues.
-
You use AI and automation to make security work and processes more efficient, understand the risks introduced by AI technologies, and design practical controls to prevent, detect and respond to them.
-
You know English at at least B2 level.
Your main responsibilities:
-
Act as the dedicated security engineer for eBilet, taking ownership of its day-to-day security work in close cooperation with eBilet teams and Group Security.
-
Turn Group Security policies, standards and requirements into practical controls, processes and priorities for eBilet.
-
Assess eBilet’s security risks and maintain a roadmap of improvements, taking into account business needs, technical changes, incidents and assessment findings.
-
Build security into the software development lifecycle by introducing practices such as threat modelling, security requirements, design reviews and secure development guidance.
-
Drive security hardening across applications, infrastructure and cloud environments, including access management, secure configuration, patching, secrets and logging.
-
Manage vulnerabilities and security findings from identification through prioritization, remediation and verification.
-
Perform hands-on security reviews and technical testing, and coordinate external assessments when needed.
-
Work with engineering and product teams to design and implement security controls that reduce risk without creating unnecessary friction.
-
Support incident response with Group Security, help identify lessons learned and follow through on resulting improvements.
-
Track security work and report on key risks, findings and progress to eBilet and Group Security stakeholders.
What's in it for you:
-
Well-located offices (with e.g. fully equipped kitchens, bicycle parking, terraces full of greenery) and excellent work tools (e.g., raised desks, ergonomic chairs, interactive conference rooms).
-
A 16" or 14" MacBook Pro or corresponding Dell with Windows (if you don't like Macs) and all the necessary accessories.
-
A wide selection of fringe benefits in a cafeteria plan - you choose what you like (e.g., medical, sports or lunch packages, insurance, purchase vouchers).
-
English classes that we pay for related to the specific nature of your job.
-
A training budget, inter-team tourism (see more here), hackathons, and an internal learning platform where you will find multiple trainings.
-
An additional day off for volunteering, which you can use alone, with a team, or with a larger group of people connected by a common goal.
-
Social events for Allegro people - Spin Kilometers, Family Day, Fat Thursday, Advent of Code, and many other occasions we enjoy.
And that's just the beginning! You can read more about the benefits here.
#goodtobehere means that:
-
You will join a team you can count on - we work with top-class specialists who have knowledge- and experience-sharing in their DNA.
-
You will love our level of autonomy in team organization, the space for continuous development, and the opportunity to try new things. You get to choose which technology solves the problem and you are responsible for what you create.
-
You will be equipped with modern AI tools to automate repetitive tasks, allowing you to focus on analyzing complex threats, developing advanced security automation, and refining secure architectures.
-
You will meet the Allegro Scale, which starts with over 1000 microservices, an open-source data bus (Hermes) with 300K+ rps, a Service Mesh with 1M+ rps, tens of petabytes of data, and production-used machine learning.
-
You will become part of Allegro Tech - We speak at industry conferences, cooperate with tech communities, run our own blog (it's been over 10 years!), record podcasts, lead guilds, and we organize our own internal conference - the Allegro Tech Meeting. We create solutions we love (and can) to talk about!
Send us your CV and… see you at Allegro!