Skip to content

Open nowPosted 3 days ago

Security Tooling Engineer II

Box122 open roles

Where
Warsaw, Poland
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity Tooling Engineer IIBox · Warsaw, Poland
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Box's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Box postings stay open a median of 26 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 3 days ago

Box median: 26 days open

The posting

WHAT IS BOX?

Box (NYSE:BOX) is the leader in Intelligent Content Management. Our platform enables organizations to fuel collaboration, manage the entire content lifecycle, secure critical content, and transform business workflows with enterprise AI. We help companies thrive in the new AI-first era of business. Founded in 2005, Box simplifies work for leading global organizations, including JLL, Morgan Stanley, and Nationwide. Box is headquartered in Redwood City, CA, with offices across the United States, Europe, and Asia.

By joining Box, you will have the unique opportunity to continue driving our platform forward. Content powers how we work. It’s the billions of files and information flowing across teams, departments, and key business processes every single day: contracts, invoices, employee records, financials, product specs, marketing assets, and more. Our mission is to bring intelligence to the world of content management and empower our customers to completely transform workflows across their organizations. With the combination of AI and enterprise content, the opportunity has never been greater to transform how the world works together and at Box you will be on the front lines of this massive shift.

WHY BOX NEEDS YOU

Box is building the industry's most trusted, secure content and AI platform. Our Production Security Tools team is seeking a Security Tooling Engineer II with curiosity and a security mindset to help build and operate infrastructure security across our tooling stack, including monitoring, vulnerability scanning, data loss prevention (DLP), and hardening checks. In this role, you will implement and operate security tooling and controls under the guidance of senior engineers; collaborate with engineering, privacy, legal, and other security teams to reduce data exposure and configuration risk; and help keep Box's infrastructure secure-by-design and secure-by-default while enabling rapid, responsible product development and AI adoption.

WHAT YOU'LL DO

  • Deploy and help maintain cloud-native security tooling in our multi-cloud environment.
  • Contribute to infrastructure and policy management using Terraform and Terragrunt, following team standards and module patterns.
  • Contribute configuration-as-code changes for host and service configuration, paired with the infrastructure-as-code changes needed to roll them out safely — with version control, peer reviews, and automated tests.
  • Implement cloud security configuration checks in tools that use OVAL and Rego, using regex patterns.
  • Patch and upgrade tooling deployments on a regular cadence, following team runbooks, to maintain security, availability, and reliability.
  • Build monitoring, metrics, and alerting for owned components to support risk reduction and operational excellence.
  • Help automate detection and remediation of misconfigurations in CI/CD and runtime, and reduce toil across policy workflows and operational tooling.
  • Support RTB requests by writing targeted detection rules and running ad-hoc scans as needed.
  • Collaborate with Legal, Privacy, and Compliance to align tool implementation with regulatory needs (FedRAMP, SOC 2, PCI, HIPAA).
  • Produce reports and evidence artifacts that demonstrate control effectiveness to auditors and internal stakeholders.
  • Attend and engage in weekly stand-ups, team meetings, and manager 1:1s.
  • Work collaboratively with other engineers, team members, and across teams.
  • Play a role in developing and fostering Box culture in our Warsaw office.
  • Represent Box Poland internally and externally.
  • Document standards and playbooks and share knowledge and best practices with peers.
  • Collaborate across global teams, including occasional shifted hours for cross-time-zone projects.
  • Participate in our on-call rotation, available at all times while on-call to help respond to and triage any issues that arise.

WHO YOU ARE

We are an AI-first company. This means you approach your work with a growth mindset and find ways to leverage AI to help make faster, smarter decisions that will 10X your impact at Box.

  • You have a BA/BS in Computer Science or related field.
  • 2+ years of experience with cloud-native security tooling and infrastructure-as-code (Terraform preferred; exposure to Terragrunt a plus) in a cloud environment.
  • Working knowledge of configuration-as-code practices for host and service configuration, and comfort pairing config changes with the infrastructure-as-code changes needed to deploy them safely.
  • Familiar with security policy engines (e.g., OVAL, Rego) for configuration compliance checks.
  • Working knowledge of policy-as-code practices (version control, CI/CD, reviews, unit/integration tests).
  • Familiar with REST APIs and at least one major language (Python, Java, Go, or Node.js); solid debugging and testing skills, and able to write modular, testable, and maintainable code with guidance.
  • Comfortable debugging across multiple system layers.
  • Interest in automation; contributes to templates and libraries that scale repetitive work.
  • Security and privacy minded; awareness of FedRAMP, SOC 2, PCI, and HIPAA, with willingness to build depth.
  • Collaborative communicator who shares findings with peers and stakeholders and raises roadblocks early.
  • Team-oriented — actively contributes to discussions and projects, and keeps stakeholders informed.
  • Growth mindset — open to feedback, curious about industry trends and tools, and motivated to expand your professional expertise.
  • Interest in DLP policy authoring (JSON/YAML, RE2 regex, dictionaries, context rules).
  • Flexible and reliable with on-call responsibilities and occasional shifted hours in a hybrid work environment.
  • Strong communication skills in English
  • Preferred Skills Interest in DLP policy authoring (JSON/YAML, RE2 regex, dictionaries, context rules). Experience contributing to classification, tagging, and policy enforcement to prevent sensitive data exfiltration. Experience with compliance frameworks such as FedRAMP, SOC 2, PCI, or HIPAA.

BENEFITS

Check out the overview of Life at Box which include general perks and benefits.

Box lives its values, with community and in-person collaboration being a core part of our culture. Boxers are expected to work from their assigned office a minimum of 3 days per week. Your Recruiter will share more about how we work and company culture during the hiring process.

At Box, we believe unique and diverse experiences benefit our culture, our products, our customers, our company, and our world. We aim to recruit a passionate, high-performing workforce that reflects the world we live in. If you are head-over-heels about this role but unsure if you meet all the requirements, we encourage you to apply!

EQUAL OPPORTUNITY

We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability, and any other protected ground of discrimination under applicable human rights legislation.

For details on how we protect your information when you apply, please see our Personnel Privacy Notice.

For more details on how Box Poland protects your information, please see our Supplemental Personnel and Candidate Privacy Notice.

#LI-Hybrid

#LI-KS2

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Box's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Box's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Box's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.