Security Engineer
Offer summary

(Summary generated by AI based on the full job description)

The project focuses on protecting an aviation-market product within a small central security team. Required technologies include AWS IAM, CloudTrail, CloudWatch, plus Linux, Bash and networking fundamentals (VPC, Security Groups). Responsibilities cover designing and maintaining security controls, vulnerability management, threat hunting and detection in AWS, identity and access management, building metrics and participating in incident response and the technical side of ISO 27001. Fluent Polish and very good English are required.

newquick applyyou can start ASAP

Security Engineer

Company: Smart4Aviation

from: 7 October 2026
to: 6 November 2026
80 - 120 złnet (+ VAT)/ hr.B2B contract (full-time)
10 000 - 15 000 złgross/ mth.contract of employment
Offer parameters
level:mid
working mode:hybrid
Gdańsk, Pomeranian
Gdańsk, PomeranianTrzy Lipy 3View on map

Requirements

Expected technologies

AWS
IAM
CloudTrail
CloudWatch
Bash
Linux
Git

Optional technologies

Claude Code
Terraform
Ansible
OpenSearch
Elastic
Splunk
Grafana

Operating system

Linux

Our requirements

  • 3–5 years of hands-on experience in an engineering role with a substantial security component (e.g. Security Engineer, SecOps or DevSecOps, an infrastructure engineer who owned security, or a software developer who moved into security).
  • University degree in Computer Science, Information Technology, Cybersecurity, Mathematics, or a closely related field.
  • Practical experience with AWS, including IAM, CloudTrail, CloudWatch and network security (VPC, Security Groups), as well as a broad understanding of the AWS services that underpin modern enterprisegrade applications.
  • Solid Linux and networking fundamentals, and Bash scripting skills.
  • Working understanding of the modern SDLC, including Git, CI/CD, and building custom automations, including with AI tools (e.g. Claude Code) for routine tasks.
  • Experience in vulnerability management, including practical understanding of the OWASP Top 10 and sufficient technical knowledge to analyse exploitability (e.g. PoCs) in the context of a specific environment.
  • Ability to work with ambiguous problems, across multiple domains and parts of the organisation.
  • Independent judgement combined with an understanding of the bigger picture and business context (or openness to building it)
  • Ability to raise concerns constructively and stand by well-reasoned recommendations.
  • Readiness to handle recurring operational work, such as periodic reviews and documentation.
  • Ability to adapt quickly to unfamiliar areas, including our tech stack.
  • Fluent Polish for daily communication and very good command of English, both spoken and written, for correspondence with customers, auditors and vendors

Optional

  • Familiarity with security industry best practices, including a broad understanding of security controls, how they relate to each other and which risks they mitigate, within a recognised framework (e.g. ISO 27001, PCI DSS, NIST CSF, NIST 800-171, OWASP SAMM, BSIMM).
  • Practical experience in software development at any stage of the technical lifecycle (development, infrastructure preparation, deployment, support and maintenance), preferably with Java/JavaScript multitier enterprise-grade applications deployed to AWS and integrated with external APIs, especially via messaging.
  • Familiarity with build and dependency management tools for the JVM/Java ecosystem.
  • DevOps skills, including familiarity with Terraform and Ansible.
  • Relevant certifications, such as OSCP, eJPT, AWS certifications (including AWS Certified Security – Specialty) or CISSP.
  • Experience in detection engineering or writing SIEM queries (e.g. OpenSearch, Elastic, Splunk, Grafana).
  • Experience in CSIRT, incident response or cyber forensics, especially in AWS and Linux environments.

Your responsibilities

  • Security controls - designing, implementing, deploying and maintaining all types of security controls, as a part of company's security risk mitigation effort across domains, and making us compliant with industry best practices. Also the technical part of company's ISO 27001 compliance program, with the control reviews, documentation and tracking that go with it.
  • Vulnerability management - scanning, triaging findings by real exploitability in our context, driving fixes and temporary mitigations, vulnerability reporting, designing and implementing the processes and automations behind it.
  • Threat hunting and detection in AWS - designing, building and running log aggregation, threat detection and alerting across various cloud components, authoring, tuning and maintaining detection rules.
  • Identity and access management - reviewing and hardening access to production and infrastructure, managing privileged access, running the daily IAM process.
  • Metrics - building and running the measurements to show progress in numbers.
  • Incident response - a seat in company's security incident response team, investigating suspected events, contributing to post-incident reviews.
Company

About the project

Have you been dreaming of a job where you can protect one of the best products available on the worldwide aviation market?
As a Security Specialist, you will join a small central security team responsible for end-to-end security and data protection at Smart4Aviation. A small team means impactful work: you will work directly with IT administration, infrastructure (including the AWS cloud, which we consider our native ecosystem), software development product teams and security governance, and you will have direct access to the CIO. It also means that creativity, taking ownership from day one and willingness to understand security in a broader context are valued here.
This is primarily an engineering role, not a compliance administration or tool operator role.

Benefits

  • sharing the costs of sports activities
  • private medical care
  • sharing the costs of foreign language classes
  • sharing the costs of professional training & courses
  • life insurance
  • remote work opportunities
  • flexible working time
  • fruits
  • integration events
  • corporate library
  • no dress code
  • coffee / tea
  • leisure zone
  • christmas gifts
  • employee referral program
  • MyBenefit Cafeteria/Multisport

Smart4Aviation

Smart4Aviation jest firmą stworzoną z pasji do lotnictwa i z pomysłu, aby moc sieci wykorzystywać w branży lotniczej. Smart4Aviation to ponad dwadzieścia lat wsparcia i rozwoju oprogramowania dla największych linii lotniczych na świecie. Dostarczamy czternaście różnych modułów oprogramowania obsługując w ten sposób ponad 700 samolotów dziennie i tysiące pracowników linii lotniczych.
Security Engineer
10k–15k zł / mth. (CoE), 80–120 zł / hr. (B2B)
I apply to:
Smart4Aviation
Gdańsk, Pomeranian

Need more information?

  • Make sure the body of the offer doesn’t already include what you’re looking for.
  • Ask a question if you need more information you’re interested in.
  • We’ll forward your question to the employer and aim to provide a response within 3 business days.

Share this offer