About the Role
Kogo poszukujemy?
Deep understanding of security domains, especially security findings assessment and remediation areas, supported by at least 3+ years of hands-on experience
Governance knowledge, proven by experience in at least one of the security findings fields: Containers vulnerabilities; Static Application Security Testing (SAST); External Attack Surface Management (EASM) findings; Threat Modelling findings; API-related findings
Knowledge and experience within the fields of problem management, Secure DevOps, DORA, OWASP
Advanced trouble-shooting and conceptual skills with the ability to come up with solutions to uncommon problems related to remediation actions
Knowledge of tools & methodologies for security findings assessment and enrichment
Ability to interpret and communicate results using exploratory data analysis and statistical modelling techniques
Understanding of risk based approach and management
Prepare and deliver presentations to stakeholders, clearly communicating remediation progress, risks, and strategic recommendations
Fluent English
Demonstrated experience in automation, preferably using Python, Apache Airflow, and/or Power Automate
Practical application of AI technologies in governance processes and automation workflows
Ability to mentor team members
Czym będziesz się zajmować?
The role is remote, but it requires occasional visits to the office in Gdańsk (for example, once per quarter).
Lead the identification of remediation gaps and drive strategic resolution initiatives across the organisation
Provide expert guidance to stakeholders on remediation strategies, ensuring alignment with security best practices and regulatory expectations
Analyse complex scanning results to define actionable steps that reduce risk exposure for the bank
Collaborate cross-functionally with accountable and responsible remediation owners to ensure timely and effective execution
Ensure security findings are clearly understood and that remediation efforts are progressing at an appropriate pace
Demonstrate autonomy and ownership in task execution, maintaining a proactive governance approach and influencing remediation outcomes
Tech Stack
cybersecuritysecurity governancevulnerability assessmentSASTEASMthreat modellingAPI securityOWASPsecure devopsPythonApache Airflowteam mentoring