Security Engineer
Security Architect
Krakowski
Apply on the employer's siteRole description
Why Billennium?
Billennium
is a global technology company with over 20 years of experience, committed to innovation and empowering businesses. As an employer, we offer a supportive, growth-focused environment where collaboration and creativity thrive.
Join us to shape the future of technology together !
Role Summary:
We are looking for a
Senior Security Architect
with strong
Application Security (AppSec)
expertise to join our Security Architecture team.
In this role, you will be responsible for designing and assessing secure IT architectures for new and existing solutions, including applications, APIs, system integrations, on-premise infrastructure and hybrid environments. You will act as a
Security SME
across business and technology projects, supporting solutions from the concept and design stage through to implementation.
You will conduct security architecture reviews, technical security assessments and threat modeling, identify potential risks and translate them into clear, actionable security requirements and recommendations.
This is a
project- and architecture-focused role
. We are looking for someone who can combine strong AppSec knowledge with a broader understanding of the security of entire solutions, including identity and access management, data protection, communication between components and trust boundaries.
You will work closely with architects, developers, DevOps and cloud teams, system administrators, product owners and other business and technology stakeholders.
Role Requirements:
Must Have
- 5+ years of experience in cybersecurity
, including practical experience in Security Architecture and/or Application Security. - Proven experience conducting
security architecture reviews, technical security assessments and threat modeling
. - Strong knowledge of
web application, API and integration security
, including:authentication and authorization, - data protection,
- encryption,
- secrets management,
- secure communication between components.
- Strong understanding of application security standards and best practices, including:
OWASP Top 10
, - OWASP ASVS
, - OWASP API Security Top 10
, - NIST SSDF
, - CWE Top 25
. - Ability to analyse
solution architecture diagrams, data flows, trust boundaries and communication between components
. - Strong understanding of security risks related to
identity, access management and network/system segmentation
. - Ability to translate identified security risks into
clear technical requirements and actionable security recommendations
. - Experience working directly with technical and business stakeholders and influencing security decisions.
- Fluent
Polish
and at least
B2 English
, both written and spoken.
Nice to Have
- Experience with
cloud and hybrid architectures
. - Knowledge of security aspects of
microservices, containers and Kubernetes
. - Experience working in the
financial sector or another highly regulated environment
. - Relevant cybersecurity certifications.
Core Responsibilities:
- Design and review
secure architectures
for new and evolving IT solutions. - Conduct
technical security assessments, architecture reviews and threat modeling
for applications, APIs, integrations and system solutions. - Act as a
Security SME
within business and technology projects, from initial concept through implementation. - Provide security guidance and recommendations during the design of new features, applications and systems.
- Assess
authentication and authorization mechanisms, data protection, encryption, secrets management and communication between system components
. - Analyse architecture diagrams, data flows and
trust boundaries
to identify potential security risks. - Evaluate risks related to
identity, access, segmentation and integration between systems
. - Translate security risks into
specific technical security requirements, controls and recommendations
. - Collaborate with Solution/Enterprise Architects, Developers, DevOps, Cloud and Infrastructure teams, Product Owners and System Owners.
- Support teams in implementing practical security controls and ensure that security requirements are considered throughout the solution lifecycle.
- Contribute to security standards, architectural principles and
technical guardrails
across the organization. - Share security knowledge and promote secure-by-design practices across technology teams.
What makes this role interesting?
You will join a
Security Architecture team responsible for the strategic security of the organization
, working on projects that directly impact critical processes, services and data protection. The role provides exposure to real-world cybersecurity challenges in the financial sector and the opportunity to influence how security is designed and implemented across the organization.
This is
not a SOC, GRC, penetration testing or security tool administration role
. We are specifically looking for an architect who can assess solutions, identify risks and work with engineering teams to build security into the architecture from the start.
Perks and benefits (our offer):
- Comprehensive benefits
- enjoy Udemy for Business, private medical care, Multisport card, veterinary package, language lessons, and shopping vouchers. - Career growth
- access opportunities for professional development and learning, including perks related to our official partnerships with global IT giants: Microsoft, AWS, Snowflake, Salesforce & more. - Global collaboration
- work with a diverse, international team. - Innovative environment
- be part of a forward-thinking and growth-oriented workplace. - Engaging community
– Work with passionate professionals and participate in team-building events, hackathons, and CSR initiatives to make an impact beyond work. - Team-building events
including our company tradition (annual company event in
Mazury
).
- A pleasant surprise
to start your journey with us in the form of a welcome pack.
This is a saved copy of a posting published elsewhere. Postings get taken down without notice — check the employer's site before applying. mentors.coach is not the hiring party.