All remote jobs
Open role
Remote opportunity atDocplanner

Senior Platform Security Engineer (100% Remote within Poland)

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

Published
38Listing views
2Application actions
23 Sep 2026Apply before
Opportunity details

About this role.

AI Summary

Docplanner is seeking a Senior Platform Security Engineer to secure and evolve its internal platform for a large, distributed healthcare technology organization. The role focuses on Kubernetes security, vulnerability management, compliance automation, secure networking, CI/CD, and highly available AWS-based infrastructure. The engineer will partner closely with Global Security, platform teams, PMS teams, legal stakeholders, and application-focused experience teams to improve security posture and resolve escalated incidents. This is a senior, Poland-only remote role requiring at least five years of security experience, strong infrastructure-as-code skills, and the ability to influence secure engineering practices across teams.

Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

Job Complexity

5/5
EasyHard

Pace & Pressure

4/5
RelaxedFast-paced

Autonomy Level

5/5
GuidedFull ownership

Communication Load

5/5
IndependentCollaborative
AI insightThis is a highly technical senior role spanning cloud, Kubernetes, network security, compliance, incident response, and developer-platform enablement at organizational scale. Success requires independently prioritizing security risks while aligning many technical and nontechnical stakeholders.

Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate
$175,000
US market range$145k–$210k
AI insightNo numeric salary is disclosed; the stated pay is only described as adequate to experience and skills. For US-market benchmarking, this estimate reflects a senior platform security engineer with Kubernetes, AWS, Terraform, vulnerability-management, and compliance ownership: an estimated annual median of $175,000, with a typical market range of $145,000 to $210,000 USD. This is a market estimate only and is not an advertised compensation range for this Poland-based role.

Core skills

Skills and capabilities most closely associated with this opportunity.

Sample interview questions
How would you design a scalable vulnerability-management workflow for Kubernetes workloads used by many engineering teams?

I would integrate image and dependency scanning into CI, registry admission controls, runtime visibility, and a centralized triage process. Findings should be enriched with asset ownership, exploitability, exposure, and business criticality so teams can prioritize meaningful risks. I would define remediation SLAs, exception workflows, dashboards, and recurring reporting to make progress measurable.

What controls would you implement to secure Kubernetes clusters across multiple regions?

I would use least-privilege RBAC, workload identity, network policies, admission policies, secrets encryption, audited API access, hardened node images, and regular version patching. I would also standardize cluster baselines through infrastructure as code, continuously monitor configuration drift, and validate recovery processes for critical services.

How have you used Terraform to improve security and compliance?

I use Terraform modules to make secure configurations the default, such as encrypted storage, restricted security groups, logging, and approved IAM patterns. I add policy-as-code checks and plan reviews in CI/CD, maintain versioned modules, and detect drift so teams can deploy compliant infrastructure consistently without manual configuration.

How would you respond to an escalated DDoS or abuse incident affecting a customer-facing service?

I would first assess impact, traffic patterns, and service health while activating the incident process and clear stakeholder communication. Depending on the attack, I would apply rate limits, WAF rules, CDN or Cloudflare protections, autoscaling safeguards, and targeted network restrictions. After stabilization, I would document root causes, tune detections and runbooks, and coordinate preventive improvements with relevant teams.

How do you influence developers to adopt security best practices without becoming a delivery bottleneck?

I focus on enabling teams through paved-road templates, reusable CI checks, self-service documentation, and risk-based guidance rather than manual gatekeeping. I explain the practical impact of a finding, offer clear remediation paths, and involve teams early in design discussions. Metrics such as remediation time, policy adoption, and recurring issue rates help demonstrate progress and guide further improvements.

This analysis is generated from the job description. Salary estimates, role characteristics and sample answers are guidance, not employer-provided facts.

Welcome to the good side of tech 👋

You might have heard about us, but with a different name: Znany Lekarz. It all started 12 years ago when we asked ourselves: is anyone in healthcare thinking about patients? We jumped in and we empowered patients by giving them access to leave and read reviews about their visit. We then provided doctors with the technology to manage bookings easily and save time, so they could devote themselves to what they always wanted: treating patients. And today is the day in which we ask you: wanna join us in the next step of making the healthcare experience more human?

Docplanner at scale

We are leaders in 13 countries so far, and more than 90 million patients trust us every month. 300k+ specialists believe in us and our product, and so do leading venture capital funds such as Point Nine Capital, Goldman Sachs Asset Management and One Peak Partners. And yet, employing over 2.500 people all over the globe, we managed to keep the startup-mindset we started with over 10 years ago.

How does Docplanner Tech fit here?

At Docplanner Tech we are a diverse group of over 400 people working in Engineering, Data, and Product teams. We are responsible for building the product for all locations. Many of us have been here for over 5 years, yet we still welcome each new person with great joy and excitement.

We could tell you about us, but we will let our reviews on Glassdoor speak for themselves. In case you’d like to see how it feels to be 100% yourself at work, here’s a video of us.

And why should you join us?

Because it feels good to tell your family and your friends how you made the world a little bit better. You go to bed knowing that what you do matters, and that your talents align with your beliefs.

We want to make the healthcare experience more human, and that starts with you being you. We believe that taking the diversity of human experience into account makes a better healthcare experience for all . We’re not just different: we embrace diversity. We will encourage you to come to work your whole self, and that includes not coming to the office at all if you prefer not to, as we’re 100% remote friendly.

Job Description

The Internal Platform is a pivotal foundation that accelerates product development by providing a reliable, scalable, and self-service ecosystem. It supports the entire software lifecycle and is meticulously tailored to meet the organization’s technological needs and strategic direction.

The platform enables development teams to operate autonomously in 80% of cases, reducing dependency on the Internal Platform team, and ensuring that compliance, security, and business continuity are integrated across the entire platform – defending general reliability of services, and data integrity.

Overall, a platform engineering team plays a critical role in ensuring a company’s technology infrastructure is reliable and scalable.

The Internal Platform team consists of 34 people including 27 individual contributors 2 Staff Engineers, 4 Engineering Managers and Head of Internal Platform. The team is organized in a way to efficiently address Stakeholders needs.

What are the challenges in the team?

  • Platform Security is a team within the Internal Platform. The team is a first point of contact for the Global Security Team. The team is responsible for security and integrity of the underlying infrastructure that supports the organization, safeguarding the platform from potential vulnerabilities, threats, and attacks.

  • Developing and maintaining tools for Global Security in order to deliver vulnerability management platforms for application triaging and continuous compliance

  • The complexity of the Docplanner organization: Docplanner is a complex organization with multiple teams working on various products and services. One of the main challenges for the platform security engineer is to understand and integrate the diverse technology stacks used by different teams.

  • Scalability and reliability of systems: As Docplanner grows and expands, the demand for the technology infrastructure also increases. The platform engineering team must ensure that the systems are designed to handle high traffic, are scalable, and secure

Who will you work closely with?

  • Global Security – as the main external stakeholder for security initiatives. You’ll collaborate on platform compliance, risk management, and act as a technical point of contact during escalated incidents such as DDoS or abuse cases.

  • PMS (Practice Management Systems) teams – to audit existing systems, support secure migration to the central platform, and interpret global security and legal requirements in the context of PMS implementations.

  • Core Team within Internal Platform – by consulting on technical compliance, networking standards, and resolving misconfigurations or vulnerabilities detected across platform components.

  • Experience Teams – by providing guidance on infrastructure-related application security topics, secure encryption practices, and collaborating on secure CSP integrations.

  • Legal – to ensure alignment with data protection regulations, encryption standards, and locality requirements. You’ll use their insights to assess and improve the security posture of the platform.

How would you be impacting our mission?

  • Making sure that our platform is compliant with the best industry practices and standards for security (ISO27001, C5, SOC2)

  • Help us to introduce security on every step of our platform lifecycle

  • Ability to vigilantly understand and mitigate security threats before they arise

  • Optimize system scalability and cost efficiency

  • Development, monitoring, and maintenance of Kubernetes clusters on several continents.

  • CI / CD development and maintenance.

  • Make sure that all of our services are deployed in a way that makes them highly available.

  • Fixing urgent issues and optimizing performance.

  • Support other team members in their daily work.

Qualifications

What will help you thrive?

  • At least 5 years of experience related with security

  • Vast experience with container orchestration platforms like Kubernetes and how to secure them (must-have).

  • You know how to maintain, develop policy for security-focused CNI/Service Mesh (eg. Calico, Cilium).

  • You know how to scan for and manage vulnerabilities at scale.

  • You have experience with Hashicorp Vault.

  • You know why and how to use Terraform and popular CI/CD tools.

  • You know about building scalable and secure production HA environments using AWS.

  • You know your ways around network security services eg. AWS WAF/Cloudflare.

  • You are not afraid of developing tools or scripts in Bash or GO to automate work.

  • You can communicate in English (both spoken and written – min. B2 level).

  • You know how to bring people on your side when talking about security and best practices.

Let’s talk money

  • A salary adequate to your experience and skills.

True flexibility and work-life balance

  • Remote or hybrid work model with or hub in Warsaw;

  • Flexible working hours (fully flexible, as in most cases you only have to be on a couple of meetings weekly);

  • 20/26 days of paid time off (depending on your contract);

  • Additional paid day off on your birthday or work anniversary (you choose what you want to celebrate).

Health comes first

  • Private healthcare plan with Signal Iduna for you and subsidized for your family.

  • Multisport card co-financing for you to have access to sports facilities across Poland.

  • Access to iFeel, a technological platform for mental wellness offering online psychological support and counseling.

Keep growing with us

  • Free English and Spanish classes.

We promote and embrace equal opportunities in our hiring process, and also every day at work. When you apply for our roles you receive equal treatment regardless of age, disabilities, gender reassignment, marital or civil partner status, pregnancy or parental status, race, colour, nationality, ethnic or national origin, religion or belief, sex, sexual orientation or any other dimension of human difference. If you require additional support in your recruitment process, we kindly encourage you to let us know. Behind those words you’re reading, there’s a person (hi!) who already helped a candidate by adapting the interviews, and now we’re lucky to have this person with us. So, even if you’ve never asked for it before, may this serve as a sign that, now, you can do so. We can only truly be equal if we adapt to each other.

“We believe all humans, in all their beautiful diversity, should have equal rights, dignity and respect. Period.” Mariusz Gralewski, CEO

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Did you apply?Let us know, and we’ll help you track your application.
Application method

Continue on the employer website

Protect your personal information and never pay to secure an interview or job offer. View safety guidance.

Log in to save
One quick step before you apply

Create your free account, then apply.

Build a more organized job search on Jobicy and continue to the employer's application when you're ready.

  • Never lose a promising opportunitySave roles and return to them from your dashboard.
  • See your entire search at a glanceTrack applications, stages and next steps in one place.
  • Get matched with relevant remote jobsChoose the alerts and digests that work for you.
or continue without an account
Applying is free. The employer's application opens in a new tab.
Add alert
Jobs Talent AI Tools Salaries
Menu