Xenoss logo

Head of Security (Application & Cloud Security)

Xenoss·Salary not specified

Primary stack

KubernetesAWSGCPAzure

Job description

Head of Security (Application & Cloud Security) at Toshiba (Poland)

About the Position

The Head of Security (Application & Cloud Security) is responsible for designing, implementing, and managing the security strategy for the TGCS’s applications, cloud environments, and DevSecOps processes. This role focuses on securing software development, cloud infrastructure, and ensuring compliance with industry security frameworks. The ideal candidate will lead security initiatives, partner with engineering teams including our Toshiba Security Governance in Japan, and establish robust security controls to safeguard applications, data, and cloud-based assets from threats.

Key Responsibilities

Security Strategy & Leadership

  • Define and execute the application and cloud security strategy, aligning with business and SaaS objectives.
  • Lead the Application Security (AppSec) and Cloud Security teams, ensuring best-in-class security practices.
  • Drive a security-first culture across development and infrastructure teams.
  • Provide executive leadership with regular security updates, risk assessments, and mitigation plans.
  • Evaluate and implement modern security tools and technologies to enhance security posture.

Application Security & DevSecOps

  • Integrate security into the software development lifecycle (SDLC), enabling secure-by-design development.
  • Implement and manage SAST, DAST, and SCA tools for automated security testing.
  • Define secure coding standards and provide guidance to development teams.
  • Work closely with DevOps teams to implement DevSecOps practices, automating security within CI/CD pipelines.
  • Lead threat modeling exercises and penetration testing to identify vulnerabilities in applications.

Cloud Security & Infrastructure Protection

  • Design and enforce security best practices for multi-cloud and hybrid cloud environments (AWS, Azure, GCP).
  • Implement cloud security posture management (CSPM) solutions to monitor and secure cloud configurations.
  • Ensure identity and access management (IAM) policies, encryption, and zero-trust principles are followed.
  • Monitor and respond to cloud security incidents, working closely with IT and SOC teams.
  • Lead compliance efforts for ISO 27001, SOC 2, NIST, GDPR, and other cloud security frameworks.

Threat Detection, Incident Response & Risk Management

  • Oversee security monitoring, log analysis, and threat intelligence for cloud and application environments.
  • Implement SIEM, XDR, and SOAR solutions for real-time security event detection and response.
  • Define incident response playbooks for cloud and application security threats.
  • Conduct regular security audits, red teaming, and penetration testing to identify and mitigate risks.

Compliance, Governance & Security Awareness

  • Ensure compliance with industry security standards (NIST, OWASP, CSA, ISO 27001, SOC 2, GDPR, CCPA).
  • Lead cloud security risk assessments, ensuring vendors and third parties meet security requirements.
  • Develop and enforce security policies, training programs, and awareness campaigns.
  • Partner with legal and compliance teams to ensure data protection and privacy regulations are met.

Qualifications & Experience

  • Bachelor’s or Master’s degree in Cybersecurity, Computer Science, or related field.
  • 10+ years of experience in application security, cloud security, or cybersecurity leadership roles.
  • Expertise in securing Azure, GCP, AWS, and Kubernetes environments.
  • Strong background in DevSecOps, CI/CD security, and software security principles.
  • Hands-on experience with SAST, DAST, SCA, CSPM, and SIEM tools.
  • Deep knowledge of cloud security frameworks (CIS Benchmarks, CSA, NIST, OWASP Cloud-Native Security).
  • Strong understanding of identity and access management (IAM), zero trust, and container security.

Preferred Certifications

  • CISSP (Certified Information Systems Security Professional)
  • CCSP (Certified Cloud Security Professional)
  • OSCP (Offensive Security Certified Professional)
  • CISM (Certified Information Security Manager)
  • Azure Certified Security - Specialty, Google Cloud Security Engineer, or AWS Security Engineer

Looking for another position?

See all our open positions and learn why you should consider joining the Xenoss team.

Careers at Xenoss

© Xenoss. This job description was sourced from the employer's public career page. TheJob is not the employer — we index the posting and route candidates to the source. All content rights and hiring decisions belong to the employer.

Xenoss is a software development house solving complex big data, AI and high-load problems.We build high-load multi-user software, AI-powered systems, data mining and big data solutions.We do hard-core programming. Which means, we daily deal with tree and graph processing, create search algorithms, multidimensional optimization tasks, machine learning algorithms.Xenoss top management has a solid engineering background, over 20 years of industry experience, and is deeply involved in product development.We operate in small senior teams of people who love programming. Developers have the freedom to make their own engineering decisions and a broad space for creativity.We store, transform, and leverage petabytes of data and work with systems processing millions of requests per seconds. We use NoSQL, in-memory storages, Hadoop, distributed storing, complex data sharding, replication algorithms. Our data solution stack: Clickhouse, Aerospike, BigQuery, Redshift, Aurora, MongoDB, Redis, Cassandra, Druid, PostgreSQL, MySQL, MariaDB, Oracle, MSSQL, CouchDB.At Xenoss, we offer the options to work remotely or from the office. Our engineers work from Kyiv, Kharkiv, Dnipro, Lviv and many other Ukrainian cities, as well as from the UK and the US.Our clients are leading SaaS companies, world-known enterprises, and aggressively growing startups. The software we’ve delivered is now the tech basis of multi-billion businesses and is being used by Nestlé, Adidas, Virgin, HSBC.Join us to work along like-minded peers on complex tech projects.

More at Xenoss

All 10 roles

Similar jobs

Popular searches