Oferty pracy

Application Security Engineer image

Application Security Engineer

We are looking for an Application Security Engineer (F/M) to join our engineering team and help us build security into the software development lifecycle. This role is an opportunity to move beyond traditional vulnerability management and drive a proactive approach to application security. You will work closely with software engineers, architects, DevOps and security teams to automate security controls, integrate security into CI/CD pipelines, improve secure development practices and help teams build secure-by-design applications.

.NET Angular JavaScript TypeScript CI/CD SonarQube Checkmarx B2B Specialist (Mid/Regular) Senior Specialist (Senior)

Your responsibilities

  • Own and continuously improve the application security posture of internally developed solutions, ensuring security is embedded throughout the software development lifecycle (SDLC).
  • Monitor, assess, prioritise, and manage application security vulnerabilities identified through penetration testing, SAST, DAST, dependency scanning, bug bounty programmes, and other security assessment activities, ensuring remediation within agreed SLAs.
  • Triage security findings to determine business risk, remediation requirements, and false positives, providing clear technical justification for all decisions.
  • Design, recommend and implement long-term, scalable security controls and automation to reduce recurring vulnerabilities, minimise manual intervention, and improve remediation efficiency across development teams.
  • Drive a shift-left security approach by integrating automated security testing, policy enforcement, and secure development practices into CI/CD pipelines and engineering workflows.
  • Identify recurring vulnerability patterns and implement preventative controls, secure frameworks, coding standards, and developer guardrails that eliminate classes of vulnerabilities at source.
  • Serve as the primary liaison with external penetration testing providers, ensuring security assessments are completed in a timely manner and findings are actionable, risk-based, and aligned with business priorities.
  • Partner with Group Security teams to maintain a single source of truth for vulnerabilities, consult, agree risk ratings, and resolve disputes relating to remediation requirements or false-positive findings.
  • Provide expert guidance on securing modern web applications, APIs, authentication mechanisms, and cloud-native architectures, with particular focus on .NET and Angular solutions.
  • Act as the Application Security subject matter expert for the Solution Delivery organisation, promoting secure design principles and security-by-default practices across all stages of solution delivery.
  • Maintain and enhance secure development standards, application security policies, and security engineering processes in line with OWASP, NIST, and industry best practices.
  • Proactively monitor emerging threats, OWASP Top 10 trends, attack techniques, and security tooling innovations, ensuring the organisation remains ahead of evolving application security risks.
  • Deliver security awareness and secure coding guidance to developers, technical leads, architects, and delivery teams to improve organisational security maturity.
  • Update on application security posture, vulnerability trends, remediation performance, and risk reduction initiatives to governance forums and steering groups, providing data-driven insights and recommendations.

Requirements

  • Strong practical knowledge of the OWASP Top 10 and common web application attack vectors.
  • Deep understanding of securing modern web applications, REST APIs, authentication and authorisation mechanisms (OAuth2, OIDC, JWT).
  • Experience implementing and managing SAST, DAST, SCA, API security and penetration testing programmes.
  • Experience automating security controls within CI/CD pipelines and software delivery processes.
  • Strong knowledge of secure software engineering practices and secure-by-design principles.
  • Experience with .NET, Angular, JavaScript/TypeScript, and modern web application architectures.
  • Ability to identify strategic security improvements rather than focusing solely on vulnerability remediation.
  • Strong stakeholder management skills, with the ability to influence development teams, architects, and security functions.
  • Highly motivated, enthusiastic, and capable of working both independently and collaboratively in a team-oriented environment.
  • Exceptional analytical and problem-solving skills, with attention to detail and a business-focused approach.
  • Strong interpersonal skills, with the ability to influence technical decisions and communicate effectively in a fast-paced environment.
  • Demonstrates creativity and resourcefulness in presenting solutions to complex security challenges.

What we offer:

  • Opportunities for personal development in an international environment
  • Working with modern technologies and constant occasion to learn something new
  • Work in English on an everyday basis
  • Flexible working hours and home office (hybrid work)
  • Work in a good atmosphere, supportive teams, among employees who are willing to share their knowledge, among others as part of internal development initiatives

Development opportunities:

  • conferences in Poland
  • development budget
  • external training
  • industry e-learning platforms
  • in-company training
  • mentoring
  • soft skills training
  • substantive support from technology leaders
  • exchange of technical knowledge within the company

Benfits

  • training budget
  • remote work options (hybrid work)
  • flexible working time
  • integration events
  • no dress code
  • video games at work
  • relaxation zone
  • employee referral program