Offshore development center
A standing R&D team in Warsaw that works only on your security product. We hold employment, payroll. You hold the roadmap.












Cybersecurity software development is product engineering with people who build secure tools: threat-detection systems, cloud scanners, and agents that run inside customer workloads.
On The Spot Development staffs that work in three areas: cloud-native runtime security, application security, DevSecOps, and agentic security.
What makes these teams hard to build is the combination: product engineering plus a security domain.
You have a security product in the market with paying customers, and the roadmap is now moving faster than you can hire against it.
The roles are hard-to-fill: kernel and eBPF work, detection engineering, pipeline security.
Your engineering leadership sits in Israel, the UK or the US, and you want the second team inside CET working hours rather than twelve hours away.
You want to hold the contract, the roadmap and the right to buy the team out when it will be needed.
You are hiring in Poland for the first time. Beyond basic job boards, we source our security team directly via GitHub research, closed tech communities, and private Slack/Discord groups.
75 of our engineers work on security products, more than in any other domain we staff. Two of those accounts are public: Orca Security (since 2019) and Cycode.
Each engineer works full-time on one product. We don't rotate people between accounts or park them on a bench between projects.
We source and prescreen technically, then present profiles. You run the technical round, or our CTO or a technical expert runs it on your behalf, to your criteria. Either way the decision is yours, and no offer goes out before you make it.
The right to hire the team into your own company exists from day one. It is not tied to a term, a milestone or a waiting period.
Some security searches take months: kernel, eBPF, low-level Rust. We have filled them, and we tell you which of your roles could fall into that group.
Our team leads meet across accounts on real cases: review practice, incidents, hiring calls. As AI changed how engineering gets done, these sessions became where we work out adoption, metrics, agent workflows and tooling: what holds up on a production team.
A standing R&D team in Warsaw that works only on your security product. We hold employment, payroll. You hold the roadmap.
Security engineers hired into your own entity, prescreened technically before they reach you. You decide who runs the technical round: yourself, or our CTO or a tech expert runs it to your criteria.
Extra engineers on a defined piece of work: a collector, an integration, a migration, a QA push.
Senior technical leadership for early-stage security startups, from architecture and stack choice to the first hires.
Agents that live inside customer workloads and must not slow them down. eBPF for low-overhead observation, Linux and Windows internals, container and Kubernetes runtimes, serverless environments where conventional monitoring does not install. The work is measured in overhead and latency. Go, C++, Rust.
Turning attacker behaviour into rules that fire on real activity and stay quiet otherwise: privilege escalation, container escape, living-off-the-land techniques, cloud reconnaissance. The hard part is keeping the false positive rate low enough to still read the alerts.
Static analysis engines, scanners built for monorepos, ephemeral environments, GitOps workflows and machine-generated code. Correlating findings from many tools into one prioritised view instead of a long queue. Rust and Go for the engines, TypeScript and React for the interfaces people actually work in.
AWS, Google Cloud, Azure, Kubernetes, Docker, Terraform, Helm, Pulumi. Building the pipeline and writing the runbook around it.
Multi-party computation, key custody, hardware security module integration. Memory-safe languages are the requirement. Rust, WebAssembly.
Kafka, PostgreSQL, MongoDB, Elasticsearch, Redis on the data path; Prometheus, Grafana, OpenTelemetry, Datadog for watching it.
Full visibility into total monthly cost per engineer from day one
Buyout option from day one to hire engineers directly into your company when needed
No hidden charges or unexpected cost increases over time
Which roles, which parts of the product, which threat model. You leave the call with a realistic timeline per role.
Real CVs with real salary numbers, prescreened for skills, English and motivation. You run the technical round, or our CTO or a technical expert runs it to your criteria.
We handle the offer, the Polish employment contract, IP assignment and equipment. You approve the level and the number; the paperwork is ours.
Your repositories, your board, your review process, your definition of done. We handle employment, payroll, equipment and the Warsaw office from day one.
We check in after the first month, while impressions are still specific and anything worth correcting is cheap to correct. With the bar calibrated against real candidates, the following roles move faster than the first ones did.
Every engineer signs an NDA and an IP assignment before they see anything of yours. The work product is yours, set out in the contract. Access is granted inside your own systems, under your access controls, and revoked by you when an engineer rolls off. We are the employer, you are the one who decides what they can reach.
Cloud-native runtime security, where our teams work on agentless scanning of public and private cloud infrastructure and on a runtime sensor that observes workloads at the kernel level. Application security with DevSecOps, where the work is securing delivery pipelines and correlating events across the software development lifecycle.
Yes. The Orca Sensor team uses eBPF to keep the runtime footprint small on Linux, Windows and Kubernetes, and the same account covers kernel and low-level Rust work.
You do. We source, prescreen technically and present profiles, then you interview every candidate, or our CTO or a tech expert can run it to your criteria. Nobody joins your team without your decision, and you see the same information about each candidate that we do.
Hard-to-fill security roles take long, sometimes months, because the people who can do the work are already employed or not actively looking for a job. We give you the range for your specific role upfront.
Yes. Each engineer works full-time on one customer product.
Our engineers work inside the customer's own security processes: their onboarding, their access controls, their review requirements. Secure SDLC practice and OWASP guidance are the working default, and teams in Poland operate under GDPR.
Warsaw, Poland. Teams work from the office, remotely or in a hybrid pattern, whichever your engineering leadership prefers. Poland sits in CET, which gives a full working-day overlap with Israel and the UK and a partial one with the US East Coast.
Often not yet. If the product still changes shape every few weeks, or your stack gets rewritten monthly, a team in another country will spend its time waiting for direction. Senior technical leadership through our Fractional CTO engagement is usually the better first step.
Yes. ShardX, a crypto custody startup we staffed from 2018, was acquired by Gemini in 2021 together with the whole engineering team we had built. Eight of our customers have been through an M&A.
Each model trades control against speed and cost differently. The custom software development page sets the models side by side, including where our own model is the wrong choice. Compare the models.
Tell us early. We are the employer, so the search starts again on our side and you are not paying twice for the same role. The reason usually surfaces in the first month, which is why we ask for feedback.
Send us the roles and the part of the product they will work on. We will come back with a timeline per role and what each one costs in Poland.
We've successfully received your request! Our specialists will contact you within 24 hours. For any urgent requests, please contact us directly at join@onthespotdev.com

Essential cookies keep the site working and cannot be turned off. Everything else is your choice, and you can change it at any time from the footer.
Full list of cookies, with providers and retention periods, is in our Cookie Policy.
Required for page loading, security, and form submissions. The site does not work without them.
Google Analytics 4 via Google Tag Manager. Shows us which pages people read and where they leave. Data is aggregated.
HubSpot and LinkedIn. Lets us see which campaigns bring visitors and show relevant ads. If this is off, we cannot tell where your visit came from.