Staff Security Engineer

Box Box · Enterprise · Warsaw, Poland · Security

Staff Security Engineer at Box, focusing on scaling security capabilities using AI, including security automation, software supply chain integrity, SDLC guardrails, and agent-based security techniques. The role involves contributing to the roadmap, shipping MVPs, partnering with cross-functional teams, and establishing team operating mechanisms.

What you'd actually do

  1. Contribute to a roadmap that scales Box’s security capabilities across platform and product surfaces.
  2. Ship MVPs and iterate on security automation, including supply chain security, SDLC agents/controls, and developer-first guardrails.
  3. Partner with Assurance & Architecture Team and cross-functional teams (Product, Platform, Cloud, SRE, Developer Experience) to embed security into workflows and tooling.
  4. Drive a breaker–builder approach: identify attack paths, validate with experimentation and feedback, and operationalize secure product development at scale.
  5. Establish clear team operating mechanisms: prioritization, sprint/quarterly planning, metrics, and post-launch learning.

Skills

Required

  • Security engineering foundation
  • DevSecOps automation
  • software supply chain security (SBOM, signing, provenance)
  • SDLC controls/agents
  • fuzzing
  • application security tooling
  • Python
  • Go
  • Java
  • TypeScript
  • building production systems
  • cross-functional collaboration
  • influencing without authority
  • data-driven decision-making
  • metrics
  • English communication

What the JD emphasized

  • agent-based security
  • SDLC agents/controls
  • developer-first guardrails

Other signals

  • AI for security
  • agent-based security
  • security automation