HSBCJP00058469 (Cybersecurity) Security Engineer
Security Engineer (IAM & Cloud Security)
📍 Location: Kraków (hybrid, 6-8 days per month from the office) 💼 Employment: B2B or UoP via Antal 💰 Rate: up to 220 PLN net/hour (B2B)
About the Project:
Join a long-term strategic transformation program within the financial services sector focused on modernizing Identity and Access Management (IAM) capabilities. The project aims to deliver next-generation identity security solutions, strengthen Zero Trust adoption, and enhance security controls across cloud-native platforms and enterprise environments.
You will become part of an international technology team responsible for designing and implementing secure, scalable identity solutions supporting both human and non-human identities in a highly regulated environment. What We Offer:
Opportunity to work on a large-scale international transformation program
Long-term cooperation in a modern cloud and security environment
Exposure to cutting-edge IAM, Zero Trust, and DevSecOps technologies
Collaboration with global engineering, architecture, and security teams
Benefits package: Private medical care (LuxMed), Multisport card
B2B or permanent employment contract via Antal
Daily tasks
- Design and implement security controls across modern IAM platforms.
- Embed Secure by Design principles throughout solution delivery.
- Implement and maintain Zero Trust security controls.
- Configure authentication and authorization mechanisms.
- Secure service-to-service communication using mTLS.
- Implement security controls for workload, human, and machine identities.
- Develop Policy-as-Code solutions using OPA and related technologies.
- Integrate secrets management, PKI, and certificate lifecycle services.
- Support cryptographic key management and certificate rotation processes.
- Conduct security reviews, threat modeling, and risk assessments.
- Identify and remediate security vulnerabilities.
- Support vulnerability management and security patching initiatives.
- Define security standards, baselines, and hardening guides.
- Implement cloud security controls within GCP and Kubernetes environments.
- Configure monitoring, logging, alerting, and audit capabilities.
- Support identity governance and privileged access management.
- Participate in penetration testing and remediation activities.
- Contribute to DevSecOps practices and automated security testing.
- Collaborate with security operations and incident response teams.
- Produce security documentation and operational procedures.
Requirements
Essential Skills: Strong experience in Information Security Engineering Identity and Access Management (IAM) Zero Trust Architecture Authentication & Authorization Workload and Machine Identity Security PKI and Certificate Management Secrets Management Cryptography Cloud Security (GCP) Kubernetes Security Service Mesh Security API Security Policy-as-Code (OPA) DevSecOps Secure Software Development Lifecycle (SSDLC) Threat Modelling Vulnerability Management Security Monitoring and SIEM Security Compliance and Governance Incident Response
Must have: Information Security Engineering, IAM, Zero Trust Architecture, Authentication & Authorization, Workload and Machine Identity Security, Secrets Management, Cryptography, GCP, Kubernetes, Service mesh, API Security, OPA, DevSecOps, SSDLC, Threat Modelling