Jobs and Careers
NO
Senior Security Engineer
NortalKraków, Polandfull_timeVerifiedPosted 30 Jan 2025
About the role
<h2>Overview</h2>
<p>Pwrteams are seeking a <strong>S</strong><strong>enior Security Engineer</strong> to join the Security Platform team, which owns and maintains a unified and overarching CDN & WAF capability at TUI for our digital services. You will be working alongside the Security Practice team which provides solutions, consultancy, education and guidance across the Product & Engagement area. The team’s focus is to drive forward maturity in developing secure software components and products. </p>
<p>This a great opportunity to join a team of innovative and passionate people, working with other practice teams who are driving the development, operation and ongoing evolution of a new global cloud-based e-commerce platform, a fundamental and strategic element of our digital transformation. </p>
<p>The Senior Security Engineer is a practitioner and an advocate of state-of-the-art secure coding, secure design and security automation practices with a broad toolkit of technologies and methods and with a strong DevSecOps mindset, being able to tackle the whole software development cycle of designing, building, testing and deploying applications. Working in an agile environment and keeping up with the ever-evolving technical landscape the Senior Security Engineer is a lifelong learner and likes to think outside the box.</p>
<p> </p>
<p><strong>About TUI Group</strong>TUI is a global business with over 70,000 employees and a legacy of excellence in the travel industry. We operate travel agencies, hotels, airlines, cruise ships, and retail shops around the world, all united by our goal to deliver exceptional travel experiences. TUI is focused on building a digital future, embracing new technologies and solutions that will shape the next generation of travel.</p>
<h2>Responsibilities</h2>
<ul>
<li>You will use your deep technical skills to create software products that are secure by default and work collaboratively with software engineers, cloud engineers and architects to ensure information security is considered throughout the design and implementation of software products and services. </li>
<li>You stay up to date with TUI group practices and foster a “security first” mindset. You work alongside engineering teams to understand the threat landscape, business requirements and to describe security risks and goals. </li>
<li>You provide your team with tooling and automation to identify possible threats and vulnerabilities before they are promoted to production, thereby helping them to protect our customers’ data.</li>
<li>You tackle the whole cycle of designing, building, testing and deploying software artefacts.</li>
<li>You take an engineering approach to solving security problems, selecting and guiding teams to use the right tools for the right jobs and thus solve the given business and technical problems in an efficient way.</li>
<li>You show a commercial mentality, focusing on solving business problems in the best way.</li>
<li>You are able to verbalise your thoughts and ideas and take the initiative to translate ideas into outcomes.</li>
<li>You will research, evaluate and test new approaches, processes and tools and help teams to use them effectively. </li>
<li>You are well-connected across the domain, within the broader TUI community and relevant Communities of Practice.</li>
<li>You are responsible for the operation and constant security optimisation and adoption of TUI’s Web Application Firewall infrastructure. Furthermore, you work with global teams in the organisation to enhance their security posture.</li>
<li>You love to learn and acquire new skills and keep up to date with latest developments in your focus areas</li>
</ul>
<h2>Qualifications</h2>
<ul>
<li>Proficient experience in working with <strong>CDN</strong> and <strong>WAF</strong> solutions like <strong>Akamai or Cloudflare</strong> </li>
<li>Advanced experience in designing secure, highly available, distributed applications in an <strong>Amazon Web Services (AWS) environment </strong></li>
<li>Ability to understand and analyse complex security events as well as adjust the resulting ongoing security profiles </li>
<li>Experience in defining, planning, implementing, maintaining, and upgrading security measures, guardrails and controls for WAF and CDN </li>
<li>Familiar with information security standards & practices and their practical implications </li>
<li>Experienced in securing APIs </li>
<li>Deep automation skills, hands-on with some programming languages such as Python </li>
<li>Advanced experience with CI/CD, preferably Gitlab CI </li>
<li>Being customer centric, passionate about delivering great digital products and services </li>
<li>Passionate about continuous improvement, collaboration and great teams </li>
<li>Strong problem-solving skills coupled with good communication skills </li>
<li>Understanding of social and ethical implications of software engineering </li>
<li>Open minded, inquisitive, life-long learner </li>
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s