Lead Application Security/DevSecOps Engineer

Faria Education Group

Kraków

On-site

PLN 260,000 - 420,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive compensation
Career development
Learning platform
Team events
MacBook Pro equipment

Job summary

Faria Education Group is seeking a Lead Security/DevSecOps Engineer to join the Product Engineering team in Kraków. This role is hands-on and leadership-focused, reporting to the VP of Engineering, with potential to build a small team and collaborate with vCISO, DevOps, and engineering groups.

You will drive risk-based prioritisation across five products, stand up an AppSec program, embed a secure SDLC, and integrate SAST/DAST/SCA tooling into CI/CD.

Qualifications

  • 7+ years in application/product security.
  • Strong AI knowledge and curiosity in the space, with proactive protection.
  • Hands-on, founding, solo function — self-directed under ambiguity.
  • Breadth across stacks: Ruby on Rails, PHP/Laravel, .NET/C#, Python.
  • Strong cloud security across AWS and Azure.
  • Deep grasp of vulnerability classes and secure coding practices.
  • Hands-on with AppSec tooling and DevSecOps/CI/CD integration.
  • Threat-modeling experience.
  • Excellent communication and influencing skills in engineering teams.

Responsibilities

  • Do an initial deep-dive assessment and prioritisation of security responsibilities.
  • Stand up and own the application security program across all products.
  • Define and embed a secure SDLC with guardrails and coding standards.
  • Select, deploy, and operationalise AppSec tooling integrated into CI/CD.
  • Implement and operationalise secrets management across CI/CD pipelines.
  • Build risk-based vulnerability management and drive remediation.
  • Run threat modeling and security reviews for new architecture/features.
  • Improve cloud security posture on AWS (primary) and Azure.
  • Lead technical incident response for application-layer incidents.
  • Build security awareness and a security-champions network.
  • Uphold student-data privacy and regulatory obligations.
  • Contribute metrics to support the security roadmap and hiring decisions.

Skills

AppSec leadership
AI security familiarity
Hands-on leader
Cloud security AWS
Threat modeling
Secure SDLC
CI/CD tooling
Strong communication

Tools

SAST/DAST/SCA
Secrets management
GitHub Advanced Security
CI/CD integrations
AWS/Azure security tooling

Job description

Faria is a leader in international education systems & services, offering an integrated suite across learning, admissions, school-to-home, and online courses — trusted by 10,000+ schools and 4 million students across 155 countries

Our product family includes ManageBac (curriculum, assessment & reporting for international schools), OpenApply (admissions management & CRM, used by 600+ leading international and independent schools), SchoolsBuddy (co-curricular & activity management), and Vectare (school transport management)

We are looking for a Lead Security/DevSecOps Engineer on the Product Engineering team, with a great opportunity to be self-directed and level up security practices and capabilities. We expect this to be a hands‑on leadership role with a potential opportunity to build/upskill a small team. The person will report to the VP of Engineering and work in partnership with the vCISO, DevOps team, and engineering teams.

Key Responsibilities
  • Do an initial deep-dive assessment and evaluation to drive risk-based prioritisation of the following responsibilities
  • Stand up and own the application security program across all five products — this is effectively greenfield.
  • Define and embed a secure SDLC (shift-left): security requirements, design reviews, guardrails, and coding standards for an AI engineering reality.
  • Select, deploy, and operationalise AppSec tooling (SAST, DAST, SCA/dependency and secrets scanning) integrated into CI/CD.
  • Implement and operationalise secrets management: detection, rotation, and vault integration across CI/CD pipelines.
  • Build risk-based vulnerability management: triage, prioritise, and drive remediation across teams and stacks. Lead remediation of some vulnerabilities as necessary in support of the software engineering team
  • Run threat modeling and security reviews for new architecture and significant features.
  • Improve cloud security posture across AWS (primary) and Azure, partnering with platform/infra.
  • Lead technical incident response for application-layer incidents; coordinate with SOC and vCISO on cross-domain incidents.
  • Build security awareness and a security-champions network to upskill engineers.
  • Uphold student-data privacy and regulatory obligations.
  • Contribute technical evidence and metrics to support the security roadmap and future hiring decisions
Requirements (must have)
  • 7+ years in application/product security, ideally including standing up or substantially maturing an AppSec program (ideally near-zero to functioning).
  • Strong AI knowledge and curiosity in the space, with the aim of proactive protection, as well as approaching problem-solving AI-first
  • Comfortable as a founding, hands‑on, solo function — self-directed and pragmatic under ambiguity
  • Breadth across stacks: able to work across Ruby on Rails, PHP/Laravel, .NET/C#, and Python (deep in one or two, competent across the rest).
  • Strong cloud security across AWS (primary) and Azure.
  • Deep grasp of common vulnerability classes and secure coding practices.
  • Hands‑on with AppSec tooling and DevSecOps / CI/CD integration.
  • Threat‑modeling experience.
  • Excellent communication and influencing skills — able to drive change in an engineering org, new to formal security.
Nice to have
  • GitHub Advanced Security experience is a strong nice‑to‑have.
  • The candidate has worked with student data or PII-heavy regulated environments (FERPA, COPPA, GDPR for UK/EU students).
  • Proven experience managing large vulnerability backlogs: ability to classify, deduplicate, and drive burn-down across hundreds of repositories.

All qualified applicants will be considered for employment without regard to age, race, creed, color, national origin, ancestry, marital status, affectional or sexual orientation, gender identity or expression, disability, nationality, or sex. Faria operates a safer recruitment policy, and the successful applicant may be required to complete an enhanced DBS disclosure and an Enhanced Check for Regulated Activity

Please note: Only shortlisted candidates will be contacted due to a high volume of applicants.

What we offer
  • Compensation - Competitive compensation and opportunities for career development
  • Learning - We encourage continued education, providing an online learning platform, unlimited book purchases, and diverse internal and external training programs.
  • Team - Friendly atmosphere, group activities, and corporate events
  • Equipment - MacBook Pro or another laptop of your specification, peripherals, and displays included
ABOUT FARIA EDUCATION GROUP

For over 15 years, Faria Education Group has deeply understood the needs of schools, leveraging extensive experience in education. Our dedication to reaching every learner and inspiring every educator has supported over 10,000 schools and 4 million students across 155 countries. We are committed to driving transformative experiences for learners, educators, and families globally.

Our integrated SaaS solutions suite supports all aspects of curriculum management (Atlas), teaching and learning (ManageBac), admissions (OpenApply), and school-to-home communications (SchoolsBuddy). With an unwavering commitment to innovation, our technology meets rigorous data protection and security standards and provides first-class training and support.

Through our innovative online schools (Pamoja and Wolsey Hall), we provide comprehensive educational experiences with IB Diploma and Cambridge online courses, delivering high-quality education to schools and homes worldwide.

Join us in our commitment to transforming education and empowering communities worldwide.

https://www.faria.org/careers

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior AppSec & DevSecOps Lead for AI-Driven Apps
Senior AppSec & DevSecOps Lead for AI-Driven Apps

Faria Education Group • Kraków

On-site
PLN 260,000 - 420,000
Competitive compensation
Career development
Learning platform
+2
Application Security Engineer - Senior
Application Security Engineer - Senior

SOFTSWISS • Warszawa

On-site
PLN 210,000 - 270,000
Private health insurance
Sports benefits
Mental Health Program
+6
Principal Application Security Software Engineer
Principal Application Security Software Engineer

3003 Sabre Polska Sp. z o.o. • Kraków

On-site
PLN 220,000 - 320,000
Paid time off
Parental leave
Volunteer time off
+4
Advanced Specialist, AI Scientist
Advanced Specialist, AI Scientist

Pearson • Poland

Hybrid
PLN 298,000 - 385,000
IT Support Engineer L2
IT Support Engineer L2

Fundraise Up • Warszawa

Hybrid
PLN 180,000 - 240,000
31 days off
Telemedicine plan
Home office setup assistance
+5
Application Security Engineer
Application Security Engineer

Starburst • Poland

Hybrid
PLN 120,000 - 180,000
Competitive pay
Attractive stock grants
Flexible paid time off
Senior Security Software Engineer – .NET, Assistant Vice President
Senior Security Software Engineer – .NET, Assistant Vice President

State Street • Kraków

On-site
PLN 210,000 - 300,000
Permanent contract
Birthday Day Off
3rd year anniversary Day Off
+9
Senior Information Security Engineer
Senior Information Security Engineer

SmartRecruiters • Kraków

On-site
PLN 180,000 - 270,000
Director of Engineering
Director of Engineering

Internetwork Expert • Warszawa

Hybrid
PLN 682,000 - 1,062,000
Fully remote position
Global team
Flexible working hours
Senior Security Engineer
Senior Security Engineer

F5, Inc. • Poland

On-site
PLN 80,000 - 100,000