Staff Security Engineer

PolandWarsawlead
SecuritySecurity EngineerCybersecurity
2 views0 saves0 applied

Quick Summary

Key Responsibilities

identify attack paths, validate with experimentation and feedback, and operationalize secure product development at scale. Establish clear team operating mechanisms: prioritization,

Technical Tools
SecuritySecurity EngineerCybersecurity

Box (NYSE:BOX) is the leader in Intelligent Content Management. Our platform enables organizations to fuel collaboration, manage the entire content lifecycle, secure critical content, and transform business workflows with enterprise AI. We help companies thrive in the new AI-first era of business. Founded in 2005, Box simplifies work for leading global organizations, including AstraZeneca, JLL, Morgan Stanley, and Nationwide. Box is headquartered in Redwood City, CA, with offices across the United States, Europe, and Asia.

By joining Box, you will have the unique opportunity to continue driving our platform forward. Content powers how we work. It’s the billions of files and information flowing across teams, departments, and key business processes every single day: contracts, invoices, employee records, financials, product specs, marketing assets, and more. Our mission is to bring intelligence to the world of content management and empower our customers to completely transform workflows across their organizations. With the combination of AI and enterprise content, the opportunity has never been greater to transform how the world works together and at Box you will be on the front lines of this massive shift.

 

At Box, we’re reimagining how the world works together. Security is core to that mission. We’re expanding a new Product & Platform Security Engineering capability in Poland to partner with our US-based Assurance & Architecture Engineering teams. As our Staff Security Engineer, you will partner with high-impact engineering team in Warsaw focused on scaling security and using AI for security across our platform and product stack.

You’ll projects for security automation, software supply chain integrity, SDLC guardrails, and advanced techniques like fuzzing and agent-based security. This role is an opportunity to impact vision and deliver measurable outcomes that protect millions of users.

 

Responsibilities

~1 min read
  • Contribute to a roadmap that scales Box’s security capabilities across platform and product surfaces.

  • Ship MVPs and iterate on security automation, including supply chain security, SDLC agents/controls, and developer-first guardrails.

  • Partner with Assurance & Architecture Team and cross-functional teams (Product, Platform, Cloud, SRE, Developer Experience) to embed security into workflows and tooling.

  • Drive a breaker–builder approach: identify attack paths, validate with experimentation and feedback, and operationalize secure product development at scale.

  • Establish clear team operating mechanisms: prioritization, sprint/quarterly planning, metrics, and post-launch learning.

  • Define and track KPIs and KRIs that show risk reduction, coverage, and developer experience improvements.

  • Represent the team internally and in the community (e.g., open source, meetups), fostering a culture of learning and inclusion.

 

We are an AI-first company. This means you approach your work with a growth mindset and find ways to leverage AI to help make faster, smarter decisions that will 10X your impact at Box.

 

  • Strong security engineering foundation with hands-on familiarity in at least two of: DevSecOps automation, software supply chain security (SBOM, signing, provenance), SDLC controls/agents, fuzzing, or application security tooling.

  • Development skills in one or more languages (e.g., Python, Go, Java, or TypeScript) and a track record of building production systems.

  • Builder mindset with the ability to turn ambiguous risk areas into pragmatic roadmaps, MVPs, and measurable outcomes.

  • Comfortable with a breaker/attacker perspective to uncover weaknesses and a builder mindset to scale defenses through automation.

  • Proven cross-functional collaborator who can influence without authority and partner across Product, Engineering, and Cloud/SRE.

  • Data-driven decision-maker who defines success with metrics and iterates quickly based on signal.

  • Excellent communicator in English; able to align global stakeholders across time zones.

  • Preferred skills:

    • Experience with SaaS at scale, developer platform/tooling, cloud-native environments, and contributions to open source or security communities.

    • Familiarity with common tools or ecosystems (e.g., CI/CD, container registries, policy engines, SAST/DAST, package managers), and modern languages (e.g., Go, Python, Java).

 

About the Role

~1 min read

We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability, and any other protected ground of discrimination under applicable human rights legislation.

For details on how we protect your information when you apply, please see our Personnel Privacy Notice.

For more details on how Box Poland protects your information, please see our Supplemental Personnel and Candidate Privacy Notice

 

#LI-Hybrid

#LI-KS2

Listing Details

First seen
March 26, 2026
Last seen
April 21, 2026

Posting Health

Days active
26
Repost count
0
Trust Level
31%
Scored at
April 21, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

B
Staff Security Engineer