AppSec Jobs
← Back to all jobs

myGwork - LGBTQ+ Business Community

Staff Security Engineer

Hybrid
Warsaw, Mazowieckie, PolandPosted 1 week agoWebsite
Apply on LinkedIn →

At a Glance

PythonJavaJavaScript/TypeScriptGoCI/CDSAST

About This Role

Box (NYSE:BOX) is the leader in Intelligent Content Management. Our platform enables organizations to fuel collaboration, manage the entire content lifecycle, secure critical content, and transform business workflows with enterprise AI. We help companies thrive in the new AI-first era of business. Founded in 2005, Box simplifies work for leading global organizations, including AstraZeneca, JLL, Morgan Stanley, and Nationwide. Box is headquartered in Redwood City, CA, with offices across the United States, Europe, and Asia. At Box, we're reimagining how the world works together. Security is core to that mission. We're expanding a new Product & Platform Security Engineering capability in Poland to partner with our US-based Assurance & Architecture Engineering teams. As our Staff Security Engineer, you will partner with high-impact engineering team in Warsaw focused on scaling security and using AI for security across our platform and product stack. You'll work on projects for security automation, software supply chain integrity, SDLC guardrails, and advanced techniques like fuzzing and agent-based security. This role is an opportunity to impact vision and deliver measurable outcomes that protect millions of users.

Responsibilities

  • Contribute to a roadmap that scales Box's security capabilities across platform and product surfaces.
  • Ship MVPs and iterate on security automation, including supply chain security, SDLC agents/controls, and developer-first guardrails.
  • Partner with Assurance & Architecture Team and cross-functional teams (Product, Platform, Cloud, SRE, Developer Experience) to embed security into workflows and tooling.
  • Drive a breaker–builder approach: identify attack paths, validate with experimentation and feedback, and operationalize secure product development at scale.
  • Establish clear team operating mechanisms: prioritization, sprint/quarterly planning, metrics, and post-launch learning.
  • Define and track KPIs and KRIs that show risk reduction, coverage, and developer experience improvements.
  • Represent the team internally and in the community (e.g., open source, meetups), fostering a culture of learning and inclusion.

Requirements

DevSecOpsPythonGoJavaTypeScriptCI/CDSASTDAST
  • Strong security engineering foundation with hands-on familiarity in at least two of: DevSecOps automation, software supply chain security (SBOM, signing, provenance), SDLC controls/agents, fuzzing, or application security tooling.
  • Development skills in one or more languages (e.g., Python, Go, Java, or TypeScript) and a track record of building production systems.
  • Builder mindset with the ability to turn ambiguous risk areas into pragmatic roadmaps, MVPs, and measurable outcomes.
  • Comfortable with a breaker/attacker perspective to uncover weaknesses and a builder mindset to scale defenses through automation.
  • Proven cross-functional collaborator who can influence without authority and partner across Product, Engineering, and Cloud/SRE.
  • Data-driven decision-maker who defines success with metrics and iterates quickly based on signal.
  • Excellent communicator in English; able to align global stakeholders across time zones.
  • Preferred: Experience with SaaS at scale, developer platform/tooling, cloud-native environments, and contributions to open source or security communities.
  • Preferred: Familiarity with common tools or ecosystems (e.g., CI/CD, container registries, policy engines, SAST/DAST, package managers), and modern languages (e.g., Go, Python, Java).

Benefits & Perks

Equity ownership for new hires
Stock plan participation
Fair, transparent, performance-based pay
Flexible time off
Birthday holidays
Volunteer time off (VTO)
Sabbatical after seven years
Annual Hackathon participation
Learning programs and professional development
Clear career paths for management and professional development
Hybrid work arrangement
Global, inclusive healthcare benefits including mental health and wellbeing support
Family support including paid parental leave and fertility benefits
Fresh Air Days for recharge
Monthly wellness subsidy for fitness
11 employee-led resource groups
Over 20 interest groups
Global virtual events and programs
Paid volunteer time off for community causes

About myGwork - LGBTQ+ Business Community

myGwork is a global platform and networking hub dedicated to the LGBTQ+ business community. It connects over 1 million LGBTQ+ professionals, graduates, and students with more than 450 inclusive employers, promoting workplace diversity, equity, and inclusion. Headquartered in London, myGwork operates in the business services industry with a focus on empowering LGBTQ+ individuals and fostering inclusive workplaces. The platform offers a variety of services, including a job board featuring career opportunities from inclusive employers, networking opportunities for mentorship and professional relationship building, and events like the WorkFair and WorkPride. Additionally, myGwork provides educational resources, industry insights, and corporate services tailored to help employers achieve their diversity and inclusion goals. Individual membership is free, while corporate partners receive customized solutions to attract diverse talent.

Industry

information technology & services

Employees

230

1 engineers

Revenue

$3M

Website

Visit →

Security at myGwork - LGBTQ+ Business Community

Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.

3 Intel Signals

Security Philosophy

myGwork's public Privacy Policy states that they have implemented appropriate and reasonable technical and organizational security measures and process information for security and fraud prevention. However, their Terms of Use explicitly state that they do not guarantee their site will be secure or free from bugs or viruses. No public information was found regarding a stated AppSec mission, philosophy quotes, developer enablement vs gatekeeping language, risk philosophy, or team-level pain points/goals.

Security Team

Information regarding the organizational structure or reporting line for an Application Security team at myGwork is not publicly available. Similarly, no public-facing AppSec leaders (names/titles/quotes) or specific AppSec team size could be found. The company headcount is reported as 11-50 employees.

Key Initiatives

No public evidence was found for a Security Champions program, shift-left practices, triage SLAs, vulnerability management workflows, secure SDLC artifacts, or recently launched AppSec initiatives at myGwork.

Preparing for an AppSec interview?

Get the weekly briefing 2,000+ security pros trust.

Interested in this role?

Apply on LinkedIn