Security Transformation Consultant (regular/senior) (She/He/They)
HybridWarsaw, Mazovia, Poland or Wrocław, Lower Silesia, Poland
Job Summary
Lead security maturity assessments across applications, software delivery processes, and enterprise environments to define pragmatic transformation roadmaps. Design Secure SDLC operating models, governance frameworks, and assurance processes while advising clients on security-by-design and shift-left practices. Conduct security architecture reviews for end-to-end solutions spanning legacy, hybrid, and cloud-native environments on AWS, Azure, or GCP. Facilitate threat modeling, risk assessments, and workshops with technical and senior stakeholders to translate complex security risks into actionable recommendations. Establish security metrics, reporting models, and continuous improvement mechanisms to drive measurable progress in client security posture.
Required Qualifications
- Several years of experience in cybersecurity consulting, application security, security architecture, DevSecOps, security governance, or a related discipline
- Basic understanding of Secure SDLC concepts, with the ability to design or improve security processes, governance frameworks, and operating models across software delivery
- Experience leading or supporting security maturity assessments and translating findings into actionable transformation roadmaps for both technical and business stakeholders
- Good working knowledge of application security principles, with practical application of OWASP Top 10 and OWASP ASVS in security assessments, architecture reviews, and secure design guidance
- Hands-on familiarity with at least one cloud platform — AWS, Azure, or GCP — sufficient to assess architecture decisions, identify security gaps, and advise on secure design across cloud, hybrid, and on-premises environments
- Experience facilitating threat modelling, security architecture reviews, and risk assessments for complex applications and distributed enterprise environments
- Ability to define practical and scalable security requirements, assurance processes, and governance mechanisms across development, platform, and enterprise environments
- Strong communication and stakeholder management skills — comfortable engaging with development and platform teams on day-to-day security topics, as well as leading workshops and presenting to senior audiences
- Good proficiency in both Polish and English (minimum B2 level)
- Leadership mindset with the ability to drive security initiatives and build trusted relationships with clients and cross-functional teams
- Seniority levels Regular (approximately 3–5 years of relevant experience)
- A solid network security foundation is expected
- Active development toward cloud security, Zero Trust, and security advisory capabilities
- Senior (approximately 5+ years of relevant experience)
- Candidates at this level are expected to lead workstreams, provide technical direction, and mentor junior colleagues
- Demonstrated depth in network security architecture
- Real breadth across at least one adjacent domain — cloud security, Zero Trust, identity, or application security
- The standing to present and defend a position to senior client stakeholders up to CISO level
Desired Qualifications
- Experience in enterprise security transformation programs or security operating model design
- Practical knowledge of DevSecOps tooling and security integration within modern software delivery pipelines
- Experience with AI governance, AI risk management or securing AI-enabled applications and services
- Industry-recognized certifications in cybersecurity or cloud security
- Experience working across multiple industries or in large-scale, complex enterprise environments
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.