Lead Security Engineer

OANDA Corporation

Kraków

On-site

PLN 200,000 - 320,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

OANDA Corporation in Krakow is seeking a Lead Security Engineer to drive secure software and mentor a talented security team. You will design authentication, authorization, 2FA, and protect transaction integrity while guiding DevSecOps across CI/CD and AI governance.

Work spans on-premise and cloud-native environments, with Go, Python, JavaScript, C++, and Java. You will collaborate across engineering and security operations to strengthen defenses and manage cryptographic secrets in a fast-paced

Qualifications

  • Bachelor's degree in Computer Science, Computer Engineering, or related field.
  • 5+ years in core engineering with DevSecOps experience.
  • 1–3 years supervising technical teams.
  • Strong background in infrastructure concepts and multiple modern languages.
  • Experience with security frameworks and compliance standards (SOC2, ISO27001/2, NIST).

Responsibilities

  • Lead and mentor a Security Engineering team, managing work streams and tracking goals.
  • Design secure software features (authentication, authorization, 2FA) and ensure secure coding across languages.
  • Embed automated security tools (SAST, DAST, SCA, Secrets, fuzzing) into CI/CD.
  • Harden on-premise and cloud-native environments (databases, networks, Docker, Kubernetes).
  • Share security metrics with stakeholders and automate security workflows.

Skills

Security engineering leadership
Go, Python, JS, C++, Java
DevSecOps
Threat modeling
Cloud & on-prem architecture

Education

Bachelor's in Computer Science / Computer Engineering

Tools

SAST
DAST
SCA
IaC
Secrets management
Kubernetes

Job description

## Lead Security EngineerApplylocations: Krakowtime type: Full timeposted on: Posted Todayjob requisition id: JR000837**Fancy helping to shape the future of FinTech?** We have always been innovators. In 1996 we were the first company to share exchange rate information, free of charge on the internet. Today, we are a world leading online trading group. **Join us to:*** Help build the future of online trading* Be part of a culture driven by integrity and global impact* Become part of an award-winning company - check out our full list of awards here **We are only as good as our people. Luckily, our people are the best. Join us!** ****How do we work?****We believe that security shouldn't be a bottleneck or an afterthought - we bake it directly into everything we build. As a team, we operate on a "push security left" philosophy, meaning we collaborate deeply with our engineering and product teams early in the development lifecycle rather than checking things at the very end. We value cross-functional flexibility, strong defense-in-depth principles, and continuous automation. On any given week, you might find yourself switching gears from cloud hardening and writing infrastructure-as-code to reviewing application vulnerability fixes, advising on secure AI governance, or mentoring engineers. We foster an open, supportive culture where diverse technical opinions are brought together to solve complex problems, and where we actively invest in our people's professional growth and industry presence.### ****In this role, you will:***** **Lead & Mentor:** Manage and guide a talented Security Engineering team, organizing work processes, tracking strategic goals, and actively mentoring team members to level up their technical and professional skills.* **Build Secure Software:** Directly design and build security-critical features (like authentication, authorization, 2FA, and transaction integrity components), and navigate security pitfalls across various languages like Go, Python, JS, C++, and Java.* **Champion DevSecOps & AI Security:** Scale our impact by embedding automated security tools (SAST, DAST, SCA, Secrets, fuzzing) into our CI/CD pipelines, and establish security gates and governance for the safe deployment of AI technologies.* **Implement Defense-in-Depth:** Harden environments across both on-premise and cloud-native infrastructure—including databases, networks, Docker containers, and Kubernetes clusters.* **Make Security Accessible:** Instrument and share meaningful security metrics with business stakeholders, and automate workflows (e.g., via ChatOps) to make proactive security practical and visible for everyone.* **Assess Risk & Drive Strategy:**Author security standards, collaborate with Security Operations to stay ahead of upcoming threats, and maintain top-tier cryptographic and secrets management practices.* **Grow the Team:**Contribute to defining talent needs, resource planning, reviewing resumes, and shaping our engineering interview process.### ****What skillset do you need to be successful in this role?***** 5+ years of solid experience rooted in core engineering principles and DevSecOps, alongside 1 to 3 years of experience supervising, scheduling, and directing technical teams.* A strong background in infrastructure concepts (networking, databases, cloud, and on-premise setups) and the ability to confidently develop/code in at least a few modern languages (Go, Python, JS, C++, Java).* Proven capability in triaging, tracking, and remediating SAST, IaC, supply-chain, and Secrets vulnerabilities.* A university degree in Computer Science, Computer Engineering, or a related discipline, backed by industry certifications such as CISSP, CCSP, or cloud-specific security credentials.* Working knowledge of major security frameworks and compliance standards (e.g., SOC2, ISO27001/2, NIST, OWASP, SANS).* Exceptional project management skills, independent problem-solving ability, and the emotional intelligence to manage minor team conflicts and collaborate seamlessly across departments.### ****Nice to have:***** Hands-on experience or specialized knowledge in securing AI development processes and AI tools.* Experience in the Financial or FinTech industry, or a strong familiarity with the specific threat landscapes and regulatory obligations that come with it.* A passion for staying connected to the broader security community (attending or participating in events like RSA, DefCon, or BSides).\_\_\_At OANDA, to help us efficiently process applications, we use AI-driven tools to help source and rank candidates based on professional experience and skills. While these tools provide recommendations, our recruitment process remains human-centric: all final shortlisting and hiring decisions are made by OANDA team. You have the right to request a human review of your application.OANDA Global Corporation is a diverse and global team with offices around the world. We value the unique skills and experiences each individual brings to OANDA. We are committed to creating and sustaining a collegial work environment in which all individuals are treated with dignity and respect and one which reflects the diversity of the community in which we operate. We provide an inclusive and accessible environment for everyone. Candidates selected for an interview will be contacted directly. If you require accommodation during the recruitment and selection process, please let us know. We will work with you to provide as seamless a recruitment experience as possible.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer
Senior Application Security Engineer

oanda • Kraków

On-site
PLN 180,000 - 230,000
Staff Systems Administrator
Staff Systems Administrator

OANDA Corporation • Kraków

On-site
PLN 120,000 - 160,000
Senior GRC Analyst
Senior GRC Analyst

OANDA • Kraków

On-site
PLN 180,000 - 240,000
CRM Manager
CRM Manager

OANDA Corporation • Warszawa

On-site
PLN 70,000 - 90,000
AML Associate
AML Associate

OANDA Corporation • Kraków

On-site
PLN 140,000 - 200,000
Senior Application Security Engineer
Senior Application Security Engineer

OANDA Corporation • Kraków

On-site
PLN 180,000 - 260,000
Senior Application Security Engineer
Senior Application Security Engineer

OANDA Poland sp. z o.o. • Kraków

On-site
PLN 180,000 - 300,000
Head of Software Engineering
Head of Software Engineering

OANDA Corporation • Warszawa

Hybrid
PLN 700,000 - 1,000,000
Head of Software Engineering
Head of Software Engineering

OANDA Poland sp. z o.o. • Kraków

Hybrid
PLN 600,000 - 900,000
Head of Software Engineering
Head of Software Engineering

OANDA • Kraków

Hybrid
PLN 500,000 - 800,000