Platform Security Remediation Engineer
Join a global technology team responsible for securing and maintaining a complex digital ecosystem supporting millions of users worldwide. As a Security Remediation Engineer, you will take ownership of vulnerability management across a large public-facing web estate, working closely with engineering teams to ensure security risks are identified, assessed, prioritized, and remediated effectively.
This is a highly technical role combining hands-on security expertise, cloud technologies, vulnerability management, and cross-functional collaboration.
📍 Kraków, Poland
🏢 Hybrid model: 6 days per month from the Kraków office
💼 B2B Contract
💰 140-170 PLN/h
Your responsibilities
- Own and maintain a consolidated view of security vulnerabilities across infrastructure, cloud, applications, CDN, WAF, and CMS layers
- Validate, triage, and prioritize findings from vulnerability scanners, penetration tests, security reviews, and vendor advisories
- Assess the real business and technical risk of identified vulnerabilities and challenge false positives where appropriate
- Drive remediation activities across engineering teams and track issues through to successful resolution
- Support patching initiatives across platforms, operating systems, runtimes, and third-party components
- Collaborate with engineers to design mitigation strategies and long-term security improvements
- Produce security posture and remediation reports for technology and risk stakeholders
- Contribute to automation, governance, and continuous improvement of vulnerability management processes
What we're looking for
Must-have
- Strong hands-on engineering background
- Experience in vulnerability management, security remediation, or application/infrastructure security
- Knowledge of:
- Web application security
- CDN and WAF technologies
- TLS, DNS, and HTTP security mechanisms
- Common web attack vectors and mitigation techniques
- Experience with cloud platforms, ideally Azure
- Ability to investigate, reproduce, and assess vulnerability findings beyond automated scanner results
- Strong stakeholder management and communication skills
- Fluent English
Nice to have
- Experience with WAF policy management
- Experience with enterprise CMS platforms (e.g. Sitecore)
- Scripting or automation skills (Python, PowerShell, etc.)
- Experience working within highly regulated environments
- Security certifications such as CISSP, OSCP, Azure Security Engineer Associate, or similar
What we offer
✅ Long-term cooperation on an international project
✅ Work in a global, distributed engineering environment
✅ Exposure to modern cloud and web technologies
✅ Luxmed private healthcare
✅ Multisport card
✅ Professional growth within enterprise-scale technology projects