Senior Cybersecurity Engineer (Network Security)

Added: 20.07.2026

Senior Cybersecurity Engineer (Network Security)

Work type:

HybridRemote

Location:

Poland

Tech stack:

English

Added: 20.07.2026

Apply

Multiple locations

Region: Europe

Country
Poland

Your responsibilities:

Product Ownership and Technical Leadership

  • Act as the primary Subject Matter Expert (SME) for Secure Access technologies, providing deep technical expertise in the evaluation and selection of emerging security tools.
  • Drive the long-term technical roadmap for network access, ensuring all initiatives are strictly aligned with Zero Trust security architecture and strategy.
  • Partner with business units to translate high-level security requirements into actionable, scalable technical initiatives and functional policies.
  • Provide mentorship and technical leadership to junior engineers, fostering a culture of continuous learning and operational excellence within the team

 

Identity-Based Access and Authentication

  • Design, deploy, and maintain robust authentication solutions utilizing protocols such as 802.1X, EAP-TLS, EAP-TEAP, RADIUS, TACACS+, SAML, and MFA.
  • Integrate disparate security platforms with enterprise Identity Providers (IdPs) to ensure a seamless and secure authentication flow across the environment.
  • Architect and manage highly available authentication services to support global workforce and critical business operations.
    Network Access Control (NAC) and Segmentation
  • Lead the end-to-end lifecycle management of Cisco ISE deployments, including software upgrades, capacity planning, and platform optimization.
  • Develop and refine endpoint profiling techniques to accurately identify and secure corporate, medical, and IoT devices.
  • Implement advanced access control mechanisms, including Dot1x, MAC Authentication Bypass (MAB), Guest Access, and posture-based authorization.
  • Design and oversee the implementation of Cisco TrustSec and Scalable Group Tag (SGT)-based micro-segmentation to reduce the network attack surface.
    Operational Excellence and Automation
  • Serve as a senior point of escalation for complex technical incidents, performing deep root-cause analysis to prevent recurrence.
  • Develop and maintain comprehensive observability, monitoring, and reporting dashboards to track platform health and security compliance.
  • Advocate for and implement Infrastructure-as-Code (IaC) principles and security automation to improve deployment speed and consistency.
  • Build and optimize API-driven integrations and self-service capabilities to empower other IT teams while maintaining security standards.

 

Global Operations

  • Ensure secure and reliable connectivity for tens of thousands of endpoints across diverse global regions.
  • Collaborate effectively with globally distributed product squads and stakeholders to deliver integrated security solutions.

We are looking for you, if you have:

Education / Experience

  • Educational Background: Bachelor’s degree in Computer Science, Software Engineering, Information Security, or a related technical field
  • Network Access Control Mastery: 5+ years of hands-on experience in designing, implementing, and managing enterprise-grade NAC solutions, specifically Cisco ISE
  • Perimeter & Inspection Expertise: Proven track record in deploying from scratch, configuring and maintaining Palo Alto Next-Generation Firewalls (NGFW), including SSL decryption and threat prevention
  • Automation Engineering: Proven experience using Ansible/Terraform and Python to manage network security infrastructure at scale
  • Large-Scale Infrastructure: Experience managing security controls in complex, global environments involving thousands of diverse device profiles (IoT, Medical, Corporate)
  • Regulated Industry: Experience working in highly regulated environments (e.g., Pharmaceuticals, Healthcare, or Finance) is a significant plus

 

Technical Skills:

  • Cisco ISE Expert: Expert-level knowledge of Cisco ISE, including hands-on experience with TrustSec, Dot1x, MAB, Profiling, Guest Portals, REST APIs, Complex enterprise policies, EAP-TLS, EAP-TEAP
  • Strong understanding of RADIUS, TACACS+ and identity-based access control. Enterprise PKI and certificate lifecycle management
  • Segmentation Technologies: Proficiency in network virtualization and segmentation techniques (such as TrustSec, SGTs, and VRFs) applied to security use cases
  • Palo Alto Mastery: Proven track record in deploying and troubleshooting Palo Alto Firewalls in complex HA environments (Active/Active and Active/Passive)
  • Architectural Mindset: Ability to design “Defense in Depth” flows that connect device identity to granular network permissions

 

Skills below will be considered a plus:

  • Infrastructure as Code (IaC): Proficiency in Terraform and GitHub to design and manage reproducible, version-controlled network security configurations. Network Security Automation through APIs
  • Engineering & Orchestration: Proven ability to build CI/CD pipelines with Gitlab/GitHub and automated workflows that streamline cross-platform security operations and eliminate manual friction
  • Coding & Integration: Strong scripting skills in Python, PowerShell, or Bash to develop self-service tools and custom API integrations between security platforms. API integrations between security platforms
  • Enterprise Networking: Solid foundation in enterprise networking (L2/L3), including advanced knowledge of routing protocols (BGP, OSPF) and switching (VLANs, VXLAN) to ensure seamless security policy integration
  • Leadership Skills
    Communication: Excellent communication and stakeholder management skills to build trust with network and infrastructure experts and explain complex security policy concepts to non-technical stakeholders
  • Innovation & Curiosity: A relentless passion for staying ahead of threat actors by researching emerging network security trends and automated enforcement techniques
  • Thriving in Ambiguity: Ability to navigate global complexity and drive clarity when translating high-level security requirements into functional network policies
  • Self-Starter: Proven ability to manage technical workstreams from concept to production with minimal supervision, taking full ownership of the NAC product lifecycle
  • Expertise in mentoring junior cybersecurity engineers to build their technical proficiency. This includes coaching on network security analysis and identity-driven security best practices to foster operational excellence within global squads

 

Additional Qualifications

  • Demonstrated ability to mentor colleagues with less experience and provide guidance on cybersecurity best practices and analysis techniques
  • Strong facilitation, communication, and conflict resolution skills to ensure alignment across multiple product squads and complex stakeholder networks
  • Demonstrated interpersonal, collaborative and commitment to operational excellence skills

We offer:

  • Participation in interesting and demanding projects.
  • Flexible working hours.
  • A great, non-corporate atmosphere.
  • Possibility to work remote or hybrid (2 days per week from the office).
  • Opportunities for development and promotion.
  • Attractive package of benefits.

We reserve the right to contact the selected candidates.

Why is it worth joining TTMS?

1

Flexible working hours

Not everyone feels comfortable working the standard 9 a.m. to 5 p.m. hours. We have been successfully running projects for many years despite diversified work patterns.

2

Possibility of hybrid work

At TTMS, desk-to-desk work is what drives us, but we understand if someone prefers a hybrid model. We are equipped with all the necessary tools to work in a hybrid model.

3

Great, non-corporate atmosphere

Professionalism, attention to the quality of work and a friendly, informal atmosphere are not mutually exclusive. A flat structure and natural, friendly relationships create the basis for creativity and innovation.

4

Interesting, international projects

We create solutions for medium and large companies, we are present in Poland, Malaysia, Denmark, the UK, Switzerland, and India – the effects of your work will travel around the world. In TTMS you have an influence on the company’s success.

5

Together towards climate neutrality

We select subcontractors to minimize the carbon footprint, organize bush plantings, save peat bogs – all to achieve climate neutrality in 2025. We are glad that we are attracting more and more people who also care about sustainable development and environmental protection.

6

Friendly offices

Our offices are modern spaces that inspire employees and are environmentally friendly. Białystok is the kingdom of Marvel superheroes, Krakow is a soothing tropical forest, Wrocław is an art gallery, and the Lublin branch is a rock u0022hall of fameu0022.

Would you like to work for us?

Our offices