远程工作雷达

高级网络安全工程师 (Apps) | EMEA

Senior Cyber Security Engineer (Apps) | EMEA

开发工程限定地区(需当地身份)日间重叠约 2 小时,需偶尔早起或晚睡
公司Colliers
薪资未公开
工作地点Poland
地域资格限定地区(需当地身份)
时区要求日间重叠约 2 小时,需偶尔早起或晚睡
用工类型Full Time
发布时间今天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 Poland 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
作息提示:日间重叠约 2 小时,需偶尔早起或晚睡。

高级网络安全工程师将与IT和业务团队紧密合作,审查现有和新应用,确保应用安全符合安全最佳实践。该职位还负责定义并确保任何IaaS、PaaS或本地基础设施上的安全需求得到实施,并识别可能影响信息资产保密性、完整性和可用性的SaaS平台风险。作为高级网络安全工程师,你将亲自参与工作,并有广泛的机会塑造和支撑Colliers的安全体系。

你的主要职责:

  • 产品安全审查。你将对新旧应用进行安全审查,确保所有安全需求得到实施,并且每个应用都符合组织制定的安全基线。定期地,你将根据不断变化的威胁、行业标准和组织需求,审查并更新安全基线。
  • 架构与设计。你将支持架构团队进行威胁建模,评估风险,并帮助实施安全控制和/或缓解措施以解决已识别的问题。你将直接指导关键应用的实施,以确保我们实现安全设计。
  • 建立安全原则、政策和治理流程,包括与治理、风险与合规团队合作,设计和实施安全开发生命周期框架及相关流程。你将在产品生命周期的所有阶段嵌入安全——从早期发现和威胁建模到设计评审和安全交付,以及发布后的持续监控和测试。
  • 漏洞识别与分析。你将负责寻找新的和创新的方法来识别和解决安全漏洞。这包括静态和动态代码分析、安全扫描、调查来自信息安全团队或其他可信合作伙伴的安全报告,以及直接与我们的事件响应团队合作处理应用安全问题和事件。你将定义范围并监督应用渗透测试。

核心职责:

  • 对应用(云和本地)进行深入的架构和安全审查,以识别漏洞
  • 设计应用安全需求,执行威胁建模并管理应用渗透测试
  • 通过确定安全与业务需求之间的权衡来支持决策
查看英文原文

The Senior Cyber Security Engineer will work closely with IT and business teams to review existing and new applications and make sure applications security are aligned with security best practices. This role is also responsible to define and ensure security requirements are implemented on any IaaS, PaaS or on-prem infrastructure and to identify risks within SaaS platforms that could impact the confidentiality, integrity, and availability of information assets. As a Senior Cyber Security Engineer, you will be hands-on and have wide-ranging of opportunities to shape and support the security of Colliers.
Your key activities:

  • Product security reviews. You will perform security reviews on new and existing applications to ensure that all security requirements are implemented and that each application aligns with the organization’s established security baselines. Periodically, you will review and update the security baselines in line with evolving threats, industry standards, and organizational needs.
  • Architecture and design. You will support the architecture team with threat model, assess risks, and help implement security controls and/or mitigations to address identified issues. You will directly steer the implementation of key applications to ensure we are secure-by-design.
  • Establish security principles, policies, and governance processes, including design and implement the secure development lifecycle framework and related processes in conjunction with Governance, Risk and Compliance teams. You will embed security into all phases of the product lifecycle—from early discovery and threat modeling to design reviews and secure delivery, and ongoing monitoring and testing post-release.
  • Vulnerability identification and analysis. You will be responsible for finding new and novel ways to identify and resolve security vulnerabilities. This includes static and dynamic code analysis, security scanning, investigation of security reports from InfoSec, or other trusted partners, and direct work with our incident response team on application security issues and incidents. You will define scope and oversee applications pentest.

Core responsibilities:

  • Perform deep architecture and security reviews on applications (cloud and on-prem) to identify vulnerabilities
  • Design applications security requirements, performing threat modelling and managing applications pentests.
  • Support decision-making by determining the tradeoffs between security and business requirements
  • Lead implementation of strategic security initiatives that improve security across Colliers

Key skills and qualifications:

  • Bachelor’s degree in computer science, Cybersecurity, or a related field (or equivalent experience).
  • 5–8+ years of experience in cloud applications, cybersecurity, or related domains.
  • Strong experience performing threat modelling and security reviews.
  • Possess hands-on experience on whitebox, greybox, and blackbox assessments or oversight applications pen tests focusing on OWASP.

Must have skills:

  • Strong documentation skills.
  • Experience working with various IT Teams and non-IT teams of various disciplines.
  • The ability to assimilate complex technical challenges and provide appropriate security advice that delivers the right business outcomes.

Preferred:

  • Relevant certifications: CISSP, CCSP, or equivalent.
  • Expert knowledge of zero trust, identity, threat detection, and threat modelling and security practices.

What We value:

  • Self-motivated, experience in solving complex problems.
  • Strong communication and collaboration skills who feels comfortable working closely with Architecture and Infrastructure teams.
  • Ability to learn and apply new technologies quickly and in complex deployments.

What we offer:

  • Remote work in Poland;
  • Contract of employment;
  • International environment, working in English;
  • Private healthcare with rehabilitation, 6 additional days off yearly for parents, cafeteria programme and other benefits;
  • Internal training program;
  • Job in a company that cares about the sustainable development of the organization;
  • Working in a company with the titles: Best Employer 2017 and 2019 awarded by Kincentric (formerly AON) and Investor in Human Capital 2019, 2021, 2022, 2023, 2024 and 2025.

Check our Warsaw Newffice | Colliers
Colliers is a leading diversified professional services company. With operations in 70 countries, our more than 24,000 enterprising people work collaboratively to provide expert advice to maximize the value of property for real estate occupiers, owners, and investors.
As a global leading real estate firm, Colliers is redefining workplace strategy worldwide, helping organisations rethink where they work, how much space they need, and how their workplaces should function in an increasingly complex, hybrid, and sustainability-driven landscape.
Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

← 返回全部职位