Talent.com
Staff Security Engineer

Staff Security Engineer

BoxWarszawa, Województwo mazowieckie, Polska
30+ days ago
Job description

Box (NYSE : BOX) is the leader in Intelligent Content Management. Our platform enables organizations to fuel collaboration, manage the entire content lifecycle, secure critical content, and transform business workflows with enterprise AI. We help companies thrive in the new AI-first era of business. Founded in 2005, Box simplifies work for leading global organizations, including AstraZeneca, JLL, Morgan Stanley, and Nationwide. Box is headquartered in Redwood City, CA, with offices across the United States, Europe, and Asia.

By joining Box, you will have the unique opportunity to continue driving our platform forward. Content powers how we work. It’s the billions of files and information flowing across teams, departments, and key business processes every single day : contracts, invoices, employee records, financials, product specs, marketing assets, and more. Our mission is to bring intelligence to the world of content management and empower our customers to completely transform workflows across their organizations. With the combination of AI and enterprise content, the opportunity has never been greater to transform how the world works together and at Box you will be on the front lines of this massive shift.

Why Box needs you :

We are seeking a highly skilled and visionary Staff Security Engineer to lead the security strategy and implementation for Generative AI and Agentic AI technologies within Box's platform. You will be instrumental in designing, developing, and operationalizing security controls that address the novel risks introduced by autonomous AI agents and generative models. Additionally, you will drive strategic initiatives to leverage LLMs to enhance our secure development lifecycle. Your work will ensure that Box remains a trusted leader in AI-powered content management by embedding security-by-design principles into all AI features and tooling.

What you'll do :

  • Lead the design and implementation of security architectures specifically tailored for Generative AI and Agentic AI systems, including agentic identity models, least privilege access, runtime guardrails, and audit logging.
  • Develop threat modeling approaches adapted for dynamic, non-deterministic AI agent behaviors, identifying autonomy-related risks such as prompt injection, tool misuse, agent impersonation, and multi-agent system attacks.
  • Build and integrate advanced security tooling and automation to detect, prevent, and respond to AI-specific vulnerabilities across the development lifecycle, including adversarial testing frameworks for AI agents.
  • Spearhead the strategy for integrating LLMs into the secure development lifecycle, including code review automation, vulnerability detection, and security documentation generation.
  • Design and implement AI-powered security tools that can analyze code, identify potential vulnerabilities, and recommend secure coding patterns at scale.
  • Lead proof-of-concept initiatives to demonstrate how generative AI can improve security posture through automated threat modeling, security testing, and developer education.
  • Collaborate closely with product, engineering, and compliance teams to embed secure-by-default configurations and user consent checkpoints for sensitive AI actions involving PII, PHI, or critical business decisions.
  • Drive continuous improvement of AI security posture by researching emerging attack vectors like model poisoning, untrusted code execution, and supply chain risks related to open-source AI frameworks.
  • Mentor and guide other engineers on secure AI development practices and contribute to organizational knowledge sharing around AI risk mitigation strategies.

Who you are :

  • Experienced security engineer with 5+ years in application security, DevSecOps, or security tooling, ideally with exposure to AI / ML security challenges.
  • Deep understanding of AI agent architectures, generative AI models, and associated security risks such as prompt injection, adversarial attacks, and autonomous decision-making vulnerabilities.
  • Proven track record implementing security tools and automation (SAST, DAST, SCA, API security scanning) integrated into CI / CD pipelines at scale.
  • Experience with or strong interest in applying LLMs to security use cases, such as code analysis, vulnerability detection, or security documentation.
  • Demonstrated ability to translate security requirements into practical AI applications that enhance the secure development lifecycle.
  • Skilled in threat modeling methodologies and able to adapt traditional frameworks to dynamic AI systems.
  • Proficient in at least one scripting language (e.g. Python) and familiar with multiple programming languages, cloud-native environments and container security.
  • Strong communicator capable of articulating complex AI security concepts to both technical and non-technical stakeholders.
  • Passionate about cybersecurity innovation, with active participation in security communities, conferences, CTFs, bug bounty programs, or CVE submissions preferred.
  • Growth mindset with a proactive approach to learning and problem-solving in fast-evolving technology landscapes.
  • Preferred Skills :
  • Experience working with Security Architecture patterns and context-aware access control mechanisms.

  • Background in adversarial machine learning or AI robustness testing.
  • Contributions to open source AI security projects or research publications in AI safety / security.
  • Experience building or working with LLM-powered developer tools or security automation.
  • Knowledge of prompt engineering techniques to optimize LLM outputs for security applications.
  • Understanding of the limitations of current LLM technologies and strategies to mitigate false positives / negatives in security contexts.
  • Percentage of Time Spent :

    40% building the AI Security program

    30-40% leading a strategy for building capabilities of generative AI

    20-30% partnership with the Engineering Teams

    Box lives its values, with community and in-person collaboration being a core part of our culture. Boxers are expected to work from their assigned office a minimum of 2 days per week, with a focus on Tuesdays and Thursdays. Your Recruiter will share more about how we work and company culture during the hiring process.

    EQUAL OPPORTUNITY

    We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability, and any other protected ground of discrimination under applicable human rights legislation.

    Accepted file types : pdf, doc, docx, txt, rtf

    Enter manually

    Accepted file types : pdf, doc, docx, txt, rtf

    LinkedIn Profile

    Website

    How did you hear about this job?

    Do you now, or will you in the future, require sponsorship for employment visa status (e.g., H-1B visa status, etc.) to work legally for Box in Poland?

  • Select...
  • In what City, State / Province, Country and Zip Code are you currently residing?

    Have you ever been employed at Box, including working as a contractor, intern, grad, or full-time employee?

  • Select...
  • By checking this box, I agree to allow Box to store and process my data for the purpose of considering my eligibility regarding my current application for employment.

    #J-18808-Ljbffr

    Create a job alert for this search

    Security Engineer • Warszawa, Województwo mazowieckie, Polska

    Related jobs
    • Promoted
    Security Engineer @ Appfire

    Security Engineer @ Appfire

    AppfireWarsaw, Poland
    Appfire is seeking a highly skilled Security Engineer to join our Appfire Information Security team.This Security Engineer role will report to our Deputy CISO and work within our Security Engineeri...Show moreLast updated: 11 days ago
    • Promoted
    Cloud Security Engineer

    Cloud Security Engineer

    CycladWarszawa, Masovian, Poland
    In Cyclad we work with top international IT companies in order to boost their potential in delivering outstanding, cutting edge technologies that shape the world of the future.For our customer, we ...Show moreLast updated: 16 days ago
    • Promoted
    • New!
    Staff Security Engineer

    Staff Security Engineer

    hyperexponentialWarszawa, Województwo mazowieckie, Polska
    At hyperexponential, we're building the AI-powered platform that enables the world's most critical decisions in a $7 trillion industry, which risks to take, and how to price them.These are the deci...Show moreLast updated: 11 hours ago
    • Promoted
    Security Engineer

    Security Engineer

    AppfireWarszawa, Warszawa, Polska
    Appfire is seeking a highly skilled Security Engineer to join our Appfire Information Security team.This Security Engineer role will report to our Deputy CISO and work within our Security Engineeri...Show moreLast updated: 30+ days ago
    • Promoted
    Security engineer

    Security engineer

    Bending SpoonsWarszawa, Województwo mazowieckie, Polska
    At Bending Spoons, we’re striving to build one of the all-time great companies.A company that serves a huge number of customers. A company where team members grow to their full potential.A company t...Show moreLast updated: 28 days ago
    • Promoted
    Senior security engineer, product and platform security @ box inc.

    Senior security engineer, product and platform security @ box inc.

    Box Inc.Warsaw, Masovian Voivodeship, Polska
    Our compensation structure is the base salary and equity in the form of restricted stock units.Box (NYSE : BOX) is the leader in Intelligent Content Management. Our platform enables organizations to ...Show moreLast updated: 11 days ago
    • Promoted
    Offensive security engineer penetration testing

    Offensive security engineer penetration testing

    Procter & GambleWarszawa, Mazowieckie, Polska
    Are you a person who is passionate about breaking applications, devices, services and / or processes to help protect them against the worlds most advanced cyber security adversaries?.The Information ...Show moreLast updated: 30+ days ago
    • Promoted
    Cloud & Infrastructure Security Engineer

    Cloud & Infrastructure Security Engineer

    CodepoleWarszawa, Warszawa, Polska
    Join Codepole as Cloud & Infrastructure Security Engineer and work with clients such as Scania, Warner Bros, Klarna, and Spotify. Are you a hands-on security professional passionate about protecting...Show moreLast updated: 30+ days ago
    • Promoted
    Security Engineer – Incident Response Team

    Security Engineer – Incident Response Team

    Sii Sp. z o.o.Warszawa, Masovian, Poland
    We are seeking an experienced Security Engineer to join our client’s Computer Security Incident Response Team.As part of a team, you will play a crucial role in protecting our organization against ...Show moreLast updated: 30+ days ago
    • Promoted
    Security Engineer, Application Security

    Security Engineer, Application Security

    AsanaWarszawa, Województwo mazowieckie, Polska
    At Asana, security is foundational to our mission of helping humanity thrive by enabling the world’s teams to work together effortlessly. Our security team protects Asana’s employees, users, and cus...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Security Engineer, Product and Platform Security @ Box Inc.

    Senior Security Engineer, Product and Platform Security @ Box Inc.

    Box Inc.Warsaw, Poland
    Our compensation structure is the base salary and equity in the form of restricted stock units.Box (NYSE : BOX) is the leader in Intelligent Content Management. Our platform enables organizations to f...Show moreLast updated: 16 days ago
    • Promoted
    AD Security & Authentication Engineer

    AD Security & Authentication Engineer

    CLOUDICA sp. z o.o.Warszawa, Masovian, Poland
    We’re seeking an Active Directory Security & Trust Engineer for a US-based project focused on AD hardening and trust remediation in large, multi-forest enterprise environments.You’ll strengthen aut...Show moreLast updated: 16 days ago
    • Promoted
    Offensive Security Engineer Penetration Testing

    Offensive Security Engineer Penetration Testing

    Procter & GambleWarszawa, PL
    Are you a person who is passionate about breaking applications, devices, services and / or processes to help protect them against the worlds most advanced cyber security adversaries?.The Information ...Show moreLast updated: 2 days ago
    • Promoted
    Security Engineer

    Security Engineer

    ICEYEWarszawa, Województwo mazowieckie, Polska
    Reporting to : SOC Team Manager.Employment is subject to applicable security screening (incl.The Mission of the Security Engineer. To build and maintain the backbone of our security monitoring and r...Show moreLast updated: 9 days ago
    • Promoted
    Security Engineer, Red Team

    Security Engineer, Red Team

    AsanaWarszawa, Województwo mazowieckie, Polska
    At Asana, security is foundational to our mission of helping humanity thrive by enabling the world's teams to work together effortlessly. Our security team protects Asana's employees, users, and cus...Show moreLast updated: 17 days ago
    • Promoted
    Infrastructure Security Engineer (Security) @ JetBrains

    Infrastructure Security Engineer (Security) @ JetBrains

    JetBrainsWarszawa, Poland
    At JetBrains, we are passionate about creating software tools for individual developers and teams that help them work more productively and enjoyably. Our Security team is currently looking for an e...Show moreLast updated: 1 day ago
    • Promoted
    Staff Security Engineer (AI Security) @ Box Inc.

    Staff Security Engineer (AI Security) @ Box Inc.

    Box Inc.Warsaw, Poland
    Our compensation structure is the base salary and equity in the form of restricted stock units.Box (NYSE : BOX) is the leader in Intelligent Content Management. Our platform enables organizations to f...Show moreLast updated: 30+ days ago
    • Promoted
    Application Security Engineer

    Application Security Engineer

    Sii Sp. z o.o.Warszawa, mazowieckie, Polska
    We are seeking a talented Security Engineer to join our client’s Application Security team.In this role, you will focus on securing applications through activities such as Static Application Securi...Show moreLast updated: 30+ days ago