Oferty pracy
Your responsibilities
- Own and continuously improve the application security posture of internally developed solutions, ensuring security is embedded throughout the software development lifecycle (SDLC).
- Monitor, assess, prioritise, and manage application security vulnerabilities identified through penetration testing, SAST, DAST, dependency scanning, bug bounty programmes, and other security assessment activities, ensuring remediation within agreed SLAs.
- Triage security findings to determine business risk, remediation requirements, and false positives, providing clear technical justification for all decisions.
- Design, recommend and implement long-term, scalable security controls and automation to reduce recurring vulnerabilities, minimise manual intervention, and improve remediation efficiency across development teams.
- Drive a shift-left security approach by integrating automated security testing, policy enforcement, and secure development practices into CI/CD pipelines and engineering workflows.
- Identify recurring vulnerability patterns and implement preventative controls, secure frameworks, coding standards, and developer guardrails that eliminate classes of vulnerabilities at source.
- Serve as the primary liaison with external penetration testing providers, ensuring security assessments are completed in a timely manner and findings are actionable, risk-based, and aligned with business priorities.
- Partner with Group Security teams to maintain a single source of truth for vulnerabilities, consult, agree risk ratings, and resolve disputes relating to remediation requirements or false-positive findings.
- Provide expert guidance on securing modern web applications, APIs, authentication mechanisms, and cloud-native architectures, with particular focus on .NET and Angular solutions.
- Act as the Application Security subject matter expert for the Solution Delivery organisation, promoting secure design principles and security-by-default practices across all stages of solution delivery.
- Maintain and enhance secure development standards, application security policies, and security engineering processes in line with OWASP, NIST, and industry best practices.
- Proactively monitor emerging threats, OWASP Top 10 trends, attack techniques, and security tooling innovations, ensuring the organisation remains ahead of evolving application security risks.
- Deliver security awareness and secure coding guidance to developers, technical leads, architects, and delivery teams to improve organisational security maturity.
- Update on application security posture, vulnerability trends, remediation performance, and risk reduction initiatives to governance forums and steering groups, providing data-driven insights and recommendations.
Requirements
- Strong practical knowledge of the OWASP Top 10 and common web application attack vectors.
- Deep understanding of securing modern web applications, REST APIs, authentication and authorisation mechanisms (OAuth2, OIDC, JWT).
- Experience implementing and managing SAST, DAST, SCA, API security and penetration testing programmes.
- Experience automating security controls within CI/CD pipelines and software delivery processes.
- Strong knowledge of secure software engineering practices and secure-by-design principles.
- Experience with .NET, Angular, JavaScript/TypeScript, and modern web application architectures.
- Ability to identify strategic security improvements rather than focusing solely on vulnerability remediation.
- Strong stakeholder management skills, with the ability to influence development teams, architects, and security functions.
- Highly motivated, enthusiastic, and capable of working both independently and collaboratively in a team-oriented environment.
- Exceptional analytical and problem-solving skills, with attention to detail and a business-focused approach.
- Strong interpersonal skills, with the ability to influence technical decisions and communicate effectively in a fast-paced environment.
- Demonstrates creativity and resourcefulness in presenting solutions to complex security challenges.
What we offer:
- Opportunities for personal development in an international environment
- Working with modern technologies and constant occasion to learn something new
- Work in English on an everyday basis
- Flexible working hours and home office (hybrid work)
- Work in a good atmosphere, supportive teams, among employees who are willing to share their knowledge, among others as part of internal development initiatives
Development opportunities:
- conferences in Poland
- development budget
- external training
- industry e-learning platforms
- in-company training
- mentoring
- soft skills training
- substantive support from technology leaders
- exchange of technical knowledge within the company
Benfits
- training budget
- remote work options (hybrid work)
- flexible working time
- integration events
- no dress code
- video games at work
- relaxation zone
- employee referral program