Security Engineer

Grid Dynamics·Poland·Офис·сегодня

We are seeking a Security Engineer to join a high-impact engineering initiative aimed at building, validating, and scaling a next-generation AI-driven security automation platform for a world leader in digital payment solutions. In this role, you will play a key technical role within a dedicated Grid Dynamics squad, owning detection quality, benchmark design, and vulnerability adjudication across all specialist analysis lenses. You will combine deep hands-on expertise in secure code review with strategic oversight—building seeded test cases across multiple programming languages, establishing rigorous measurement baselines, and ensuring the platform maintains unmatched precision against emerging security threats.

Essential functions

Responsibilities:

  • Own the end-to-end security capability roadmap, defining vulnerability coverage, detection frameworks, and competitive benchmarks against commercial and open-source tools.
  • Design, curate, and maintain the platform's benchmark corpus using seeded and labeled vulnerabilities across multiple programming languages.
  • Establish measurement methodologies to track detection performance, safeguard published metrics, and run standing evaluations against competing tools.
  • Adjudicate findings, define triage standards, and resolve complex false-positive or missed-detection reports.
  • Author multi-language test cases, manage vulnerability classification mappings (e.g., CWE, OWASP), and continuously expand the regression corpus.
  • Perform security reviews of harness code changes and external contributions prior to merging.
  • Reproduce reported detection failures, document minimal test cases, and execute benchmark passes with every platform release.

Qualifications

Vulnerability classes & detection methods, security testing frameworks/methodologies, benchmark corpus design (seeded/labelled vulnerabilities), detection measurement & metrics integrity, findings triage/adjudication, competitive tool evaluation, secure code review, multi-language vulnerability test case authoring, vulnerability classification mapping (np. CWE/OWASP), regression corpus management, false positive/negative handling.

Would be a plus

Min requirements:

  • 3+ years of commercial experience in application security, security engineering, or vulnerability research.
  • Strong hands-on experience in secure code review and threat analysis across multiple programming languages (e.g., Python, Java, Go, C/C++, JavaScript/TypeScript).
  • Deep understanding of vulnerability classification frameworks (CWE, OWASP Top 10) and root-cause analysis.
  • Proven track record in vulnerability triage, false-positive reduction, and developing reproducible test cases or PoCs.
  • Experience creating or managing security benchmark corpora, evaluation frameworks, or automated testing suites.
  • Solid grasp of modern security testing methodologies, static analysis (SAST), and dynamic evaluation techniques.

We offer

  • Opportunity to work on bleeding-edge projects
  • Work with a highly motivated and dedicated team
  • Competitive salary
  • Flexible schedule
  • Benefits package - medical insurance, sports
  • Corporate social events
  • Professional development opportunities
  • Well-equipped office

About us

Grid Dynamics (NASDAQ: GDYN) is a leading provider of technology consulting, platform and product engineering, AI, and advanced analytics services. Fusing technical vision with business acumen, we solve the most pressing technical challenges and enable positive business outcomes for enterprise companies undergoing business transformation. A key differentiator for Grid Dynamics is our 8 years of experience and leadership in enterprise AI, supported by profound expertise and ongoing investment in data, analytics, cloud & DevOps, application modernization and customer experience. Founded in 2006, Grid Dynamics is headquartered in Silicon Valley with offices across the Americas, Europe, and India.

Другие вакансии Grid Dynamics