
201 - 500 employees
Founded 2009
đ„ Healthcare
đŠ Logistics
đ Manufacturing
Healthcare âą Logistics âą Manufacturing
ITRex Group is a technology consultancy and engineering firm that builds applied AI, generative AI, data platforms, and intelligent edge/IoT solutions for enterprise clients across healthcare, logistics, manufacturing, and other regulated industries. They provide end-to-end services including AI strategy and readiness assessments, product discovery and PoCs, LLM fine-tuning, MLOps/LLMOps and governance, data architecture and platform modernization (warehouses, lakes, vector DBs), and embedded hardware and edge software development. ITRex focuses on production-ready, compliant deployments that integrate models, data infrastructure, and edge devices to deliver scalable, secure AI-driven products and operations.
đ„ 3 minutes ago
đ Poland, Cyprus, +3 more countries â Remote
â° Full Time
đĄ Mid-level
đ Senior
đźââïž Cybersecurity / Security Engineer
đ» Ghost score 10%
Improve your chances of getting an interview by checking your resume score before you apply.

201 - 500 employees
Founded 2009
đ„ Healthcare
đŠ Logistics
đ Manufacturing
Healthcare âą Logistics âą Manufacturing
ITRex Group is a technology consultancy and engineering firm that builds applied AI, generative AI, data platforms, and intelligent edge/IoT solutions for enterprise clients across healthcare, logistics, manufacturing, and other regulated industries. They provide end-to-end services including AI strategy and readiness assessments, product discovery and PoCs, LLM fine-tuning, MLOps/LLMOps and governance, data architecture and platform modernization (warehouses, lakes, vector DBs), and embedded hardware and edge software development. ITRex focuses on production-ready, compliant deployments that integrate models, data infrastructure, and edge devices to deliver scalable, secure AI-driven products and operations.
âą Own and extend the threat model across the device, backend, and every third-party integration before the audit-ready build âą Defend the self-custody boundary by ensuring private keys, plaintext seed phrases, and user funds are never reachable from the server side âą Design split recovery backup and recovery-guard controls, including new-device verification, secondary authentication, cooling-off delays, rate limiting, alerts, and fraud logging âą Conduct a line-by-line internal security review of the signing path âą Drive mobile hardening through device integrity attestation, jailbreak/root detection, anti-tamper, certificate pinning, and biometric gating âą Implement the fail-closed AML/sanctions screening gate on the send path âą Implement pre-signing phishing and drainer risk scans for destination addresses and calldata âą Specify append-only audit records for every verification, screening, and decision âą Enforce privacy boundaries including PII segregation, field-level encryption, US-only residency, and retention/deletion by data category âą Own SAST, secret scanning, SCA, and licence scanning in the build pipeline âą Produce an SBOM for every release candidate and set dependency policy for signing and address-handling paths âą Co-sign every milestone exit checklist with the Delivery Lead âą Act as technical counterpart to the independent auditor and own the remediation register âą Prepare the audit-ready build, drive remediation of Severity 1/Severity 2 findings, and define rollout guardrail metrics and minimum-version policy âą Participate in the Severity 1 on-call rotation and produce a written postmortem within five business days of resolution âą Define the bug-bounty scope and severity-to-reward schedule âą Triage, reproduce, and coordinate remediation of confirmed findings
âą Experience with iOS and Android threat models âą Knowledge of iOS Secure Enclave and Android Keystore / StrongBox âą Experience with biometric APIs, platform attestation, RASP and anti-tamper, certificate pinning âą Hands-on mobile reverse engineering with Frida, objection, and MobSF âą Applied cryptography knowledge including BIP-32 / BIP-39 / BIP-44, ECDSA over secp256k1, AES-GCM, modern KDFs, envelope encryption, KMS and HSM operation, and key rotation âą Backend and cloud security experience with AWS security services, IAM, KMS, VPC, CloudTrail, GuardDuty, OAuth 2.0, OIDC, JWT, JWKS, WebAuthn, session and device binding, API authorisation, rate limiting, and secure service-to-service design âą Secure SDLC and supply-chain knowledge including threat modelling, secure code review, SAST, DAST, SCA, SBOM formats, secret scanning, and CI/CD hardening âą Digital-asset security knowledge including EVM and Bitcoin transaction structure, ERC-20 approval semantics, ERC-4337 account abstraction and paymaster abuse, smart-account wallets, address-poisoning and drainer patterns, and RPC provider and indexer trust assumptions âą Familiarity with sanctions and address-screening flows, KYC/CDD data handling, the Travel Rule data model, audit logging, retention design, US privacy requirements, ISO/IEC 27001, SOC 2, and NIST CSF âą Incident response experience including detection, severity triage, on-call practice, and postmortem discipline âą Strong written communication for auditors, counsel, and non-technical stakeholders âą English at C1 level âą Consistent overlap with US Central Time during the working day
âą Remote flexibility: Work where and how you work best - we trust you to deliver âą Competitive salary + benefits that matter (medical, wellness, learning) âą English classes âą Professional development âą Well-being support âą Career progression âą Regular meetups âą Tech talks
Apply Nowđ„ 14 hours ago
Application Security Engineer securing a high-traffic digital news platform for Solvd, an AI-native consulting and technology services firm. Validating architecture, APIs, privacy, and full-lifecycle security controls.
đ”đ± Poland â Remote
â° Full Time
đĄ Mid-level
đ Senior
đźââïž Cybersecurity / Security Engineer
AEM
đ August 26
Security Architect II defending Akamai's global DDoS mitigation platform. Analyzing customer traffic and resolving real-time network security issues for leading brands.
đ”đ± Poland â Remote
đ° Post-IPO Equity on 2001-07
â° Full Time
đĄ Mid-level
đ Senior
đźââïž Cybersecurity / Security Engineer
DNS
TCP/IP
đ August 25
Product Security Engineer securing Aras products, cloud platforms, and SDLC through DevSecOps. Building secure CI/CD pipelines and automating security controls across engineering teams.
đ”đ± Poland â Remote
â° Full Time
đĄ Mid-level
đ Senior
đźââïž Cybersecurity / Security Engineer
AWS
Azure
Cloud
Cyber Security
Groovy
Jenkins
Kubernetes
Python
SDLC
Terraform
đ August 21
Security Researcher investigating browser, mobile, and AI-driven fraud signals. Supporting MWDNâs IAM cybersecurity client with detection research, experiments, and SDK requirements.
đ”đ± Poland â Remote
â° Full Time
đĄ Mid-level
đ Senior
đźââïž Cybersecurity / Security Engineer
Android
Cyber Security
iOS
Java
JavaScript
Kotlin
Objective-C
Python
Swift
TypeScript
đ August 19
IT Security Officer securing systems, devices, identities, and data at Callstack, a cross-platform development consultancy. Managing cybersecurity, infrastructure, compliance, incident response, and security awareness.
đ”đ± Poland â Remote
đ” zĆ20k - zĆ30k / month
â° Full Time
đĄ Mid-level
đ Senior
đźââïž Cybersecurity / Security Engineer
AWS
Azure
Cloud
Cyber Security
DNS
Firewalls
Google Cloud Platform
Linux
MacOS