Security Engineer

Nortal

Kraków

Hybrid

PLN 180,000 - 260,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

24 working days vacation
11 national holidays
Health care: up to 10 paid sick days &
Mental health support
Learning platform access
English language classes
Flexible benefits budget
Hybrid work options
Team events & gifts

Job summary

Nortal is seeking a Security Engineer to embed security practices across the software delivery lifecycle and enable teams to build and release secure products with minimal friction. You’ll collaborate with engineering, product, platform, and security to integrate controls, vulnerability management, and secure engineering throughout day-to-day delivery.

This hands-on role involves threat modelling, reviews, incident response, and building reusable secure-by-default solutions.

Qualifications

  • Experience applying security engineering practices within software, cloud, or platform environments.
  • Knowledge of secure software development principles, threat modelling, vulnerability management, and security testing approaches.
  • Understanding of application, infrastructure, and cloud security risks, attack vectors, and mitigation techniques.
  • Experience with authentication, authorisation, encryption, secrets management, and data protection principles.
  • Familiarity with security tooling for code analysis, vulnerability identification, security testing, and monitoring activities.
  • Working knowledge of cloud security controls, Infrastructure-as-Code, container technologies, modern deployment practices, and incident response processes.
  • Strong analytical, problem-solving, communication, and collaboration skills, with experience implementing security controls in agile delivery environments and working with cloud technologies.

Responsibilities

  • Conduct threat modelling, secure code reviews, and architecture reviews using established security standards and guidance.
  • Identify attack vectors, data flow weaknesses, and authentication and authorisation gaps, and provide actionable remediation guidance.
  • Perform vulnerability discovery, security testing, remediation planning, validation, and prioritisation of findings using established risk frameworks.
  • Configure and maintain security scanning, pipeline gates, secret detection, Infrastructure-as-Code security scanning, and other security automation.
  • Embed security into domain delivery processes through secure design patterns, reusable artefacts, templates, and security requirements.
  • Participate in security incident investigation activities, including evidence gathering, root cause analysis, remediation validation, and post-incident reviews.
  • Support compliance, audit readiness, threat monitoring, and security knowledge sharing across product and platform teams.

Skills

Security engineering practices
Threat modelling
Vulnerability management
Security testing
Secure software development
Cloud security
Infrastructure as Code security
Container technologies
Incident response
Agile delivery
Communication & collaboration

Tools

Security tooling

Job description

Overview

We are looking for a Security Engineer to help embed security practices into the software delivery lifecycle and enable teams to build and release secure products without unnecessary friction. In this role, you will work closely with engineering, product, platform, and security teams to integrate security controls, vulnerability management, and secure engineering practices into day‑to‑day delivery activities.
As a hands‑on technical contributor, you will participate in team ceremonies, conduct security reviews, support incident response activities, and build reusable secure‑by‑default solutions. You will collaborate with Security Architects and other security specialists to address complex security challenges while helping teams adopt secure development practices and improve overall security maturity.

About Nortal

W e’reNortal. We think big and createcutting‑edgedigital solutions with a global reach. And with 25 years of experience, 2,700+ professional experts, and half a billion people worldwideimpactedby our work, we believewe’vegot the numbers to back up that statement. Our global teams have played a significant role in many Fortune 5 00 companies’ projects and systems and have been the driving force of digital transformation for governments, healthcare institutions, and leading enterprises worldwide. We combine best-in‑class strategic consulting with software engineering, data, and design practices to bring our visions to life.

About TUI

TUI is a global business with over 70,000 people on board, a great history and challenging plans for building a digital future. TUI is the largest leisure, travel and tourism company globally, and it owns travel agencies, hotels, airlines, cruise ships and retail shops.

Responsibilities
  • Conduct threat modelling, secure code reviews, and architecture reviews using established security standards and guidance.
  • Identify attack vectors, data flow weaknesses, and authentication and authorisation gaps, and provide actionable remediation guidance.
  • Perform vulnerability discovery, security testing, remediation planning, validation, and prioritisation of findings using established risk frameworks.
  • Configure and maintain security scanning, pipeline gates, secret detection, Infrastructure-as-Code security scanning, and other security automation.
  • Embed security into domain delivery processes through secure design patterns, reusable artefacts, templates, and security requirements.
  • Participate in security incident investigation activities, including evidence gathering, root cause analysis, remediation validation, and post‑incident reviews.
  • Support compliance, audit readiness, threat monitoring, and security knowledge sharing across product and platform teams.
Qualifications
  • Experience applying security engineering practices within software, cloud, or platform environments.
  • Knowledge of secure software development principles, threat modelling, vulnerability management, and security testing approaches.
  • Understanding of application, infrastructure, and cloud security risks, attack vectors, and mitigation techniques.
  • Experience with authentication, authorisation, encryption, secrets management, and data protection principles.
  • Familiarity with security tooling for code analysis, vulnerability identification, security testing, and monitoring activities.
  • Working knowledge of cloud security controls, Infrastructure-as-Code, container technologies, modern deployment practices, and incident response processes.
  • Strong analytical, problem‑solving, communication, and collaboration skills, with experience implementing security controls in agile delivery environments and working with cloud technologies.
Nortal Offers
  • 24 working days of paid vacation
  • 11 paid national holidays
  • Health care: up to 10 paid sick days, on-demand medical insurance, vaccinations
  • Mental health support: webinars, resources, and compensation for therapy sessions
  • Access to our corporate learning platform
  • Language classes (English)
  • Flexible benefits budget: a fixed monthly amount you can spend on what matters most to you - medical insurance, sports, leisure, fuel, and more
  • 8-hour workday aligned with the client’s working hours
  • Hybrid work options: work from home with the option to use our cozy office space whenever needed
  • Engaging team events and thoughtful gifts throughout the year

In your resume please allow our company to use your personal data

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer | Senior
Application Security Engineer | Senior

Nord Security • Poland

On-site
Private health insurance
Flexible work arrangements
Physical well-being programs
+3
Information Security Manager
Information Security Manager

Nortal • Poland

On-site
PLN 240,000 - 360,000
Security Engineer | Mid - Senior | WebSec Team
Security Engineer | Mid - Senior | WebSec Team

Nord Security • Poland

On-site
Private health insurance
Online workouts with experts
Flexible work from anywhere
+2
Product Designer | NordVPN Apps | Mid-Senior
Product Designer | NordVPN Apps | Mid-Senior

Nord Security • Warszawa

On-site
PLN 120,000 - 180,000
Gym access
Private health insurance
Extra vacation days
+4
Application Security Engineer
Application Security Engineer

AXA IT Solutions • Poland

Hybrid
PLN 180,000 - 240,000
Personal development
International environment
English work environment
+9
Mobile Engineer | Senior | iOS
Mobile Engineer | Senior | iOS

Nord Security • Warszawa

On-site
PLN 140,000 - 210,000
Work from anywhere
Private health insurance
Multisport card
+1
Product Marketing Manager | AI Security
Product Marketing Manager | AI Security

Nord Security • Warszawa

On-site
PLN 120,000 - 180,000
Private health insurance
Company events
Mental health resources
+1
Windows Engineer | Senior | NordLocker
Windows Engineer | Senior | NordLocker

Nord Security • Warszawa

On-site
PLN 240,000 - 360,000
Global experts
Mentorship
Work from anywhere
+7
Staff Core Platform Engineer
Staff Core Platform Engineer

n8n • Poland

On-site
PLN 300,000 - 520,000
Competitive pay
Equity
Remote-first environment
+4
ERP Security Manager
ERP Security Manager

Smith+Nephew • Wrocław

On-site
PLN 120,000 - 150,000
Generous annual bonus
Private health and dental plans
Flexible vacation and time off
+1