Senior Security Architect (f/m/x)
⚲ Warszawa, Bydgoszcz, Kraków, Gdańsk, Katowice, Łódź, Lublin, Poznań, Rzeszów, Szczecin
Do uzgodnienia
Wymagania
- OWASP
- OWASP ASVS
- Burp Suite
- OWASP ZAP
- SIEM
- DevSecOps
- REST
- Git
- CI/CD
- Linux
Opis stanowiska
We are looking for an experienced Security Architect to lead the design and governance of security solutions across multiple web applications and systems.
In this role, you will be responsible for shaping secure architecture, overseeing application security practices, and working closely with development and DevOps teams to ensure secure delivery in a complex enterprise environment.
Your tasks
• Designing and evolving application security architecture across multiple systems
• Defining and enforcing security standards for web applications
• Supervising penetration testing and guiding vulnerability remediation according to OWASP ASVS
• Collaborating with development, DevOps, and PM teams on secure design and delivery
• Supporting system integration and ensuring security alignment across environments
• Leading security testing, audits, and compliance activities
• Defining and aligning security policies with ISO 27001 standards
• Contributing to SIEM use cases and improving security monitoring
• Supporting the selection and implementation of DevSecOps tools
• Creating and maintaining security and technical documentation
Requirements
• Minimum 8 years of experience in application security architecture
• Experience in delivering projects for the healthcare industry
• Deep knowledge of OWASP standards and secure SDLC
• Strong experience with security testing tools such as Burp Suite and OWASP ZAP
• Practical experience with SIEM tools like Splunk or Sentinel
• Hands-on expertise in DevSecOps practices and tools
• Proficiency in designing and implementing REST APIs
• Strong command of Git and CI/CD processes, combined with solid experience working in Linux and Microsoft Windows environments
• Fluent Polish
In this role, you will be responsible for shaping secure architecture, overseeing application security practices, and working closely with development and DevOps teams to ensure secure delivery in a complex enterprise environment.
Your tasks
• Designing and evolving application security architecture across multiple systems
• Defining and enforcing security standards for web applications
• Supervising penetration testing and guiding vulnerability remediation according to OWASP ASVS
• Collaborating with development, DevOps, and PM teams on secure design and delivery
• Supporting system integration and ensuring security alignment across environments
• Leading security testing, audits, and compliance activities
• Defining and aligning security policies with ISO 27001 standards
• Contributing to SIEM use cases and improving security monitoring
• Supporting the selection and implementation of DevSecOps tools
• Creating and maintaining security and technical documentation
Requirements
• Minimum 8 years of experience in application security architecture
• Experience in delivering projects for the healthcare industry
• Deep knowledge of OWASP standards and secure SDLC
• Strong experience with security testing tools such as Burp Suite and OWASP ZAP
• Practical experience with SIEM tools like Splunk or Sentinel
• Hands-on expertise in DevSecOps practices and tools
• Proficiency in designing and implementing REST APIs
• Strong command of Git and CI/CD processes, combined with solid experience working in Linux and Microsoft Windows environments
• Fluent Polish
🔍 Dekoder Ogłoszenia
🟡
lead the design and governance of security solutions
Może oznaczać zarówno strategiczne kierowanie, jak i bardziej operacyjne nadzorowanie istniejących procesów.
🟡
shaping secure architecture
Może oznaczać tworzenie od podstaw, ale też dostosowywanie i modyfikowanie istniejących architektur.
🟡
working closely with development and DevOps teams
Może oznaczać ścisłą współpracę, ale też konieczność przekonywania i edukowania tych zespołów w kwestiach bezpieczeństwa.
🔴
complex enterprise environment
Sugestia, że systemy są rozbudowane, często przestarzałe i trudne do zmian, co może generować frustrację.
🔴
Hands-on expertise
Oczekuje się, że będziesz aktywnie wdrażać i konfigurować narzędzia, a nie tylko delegować zadania.