Unlock Full Resume Report

New offer - be the first one to apply!

September 1, 2026

Mid Cybersecurity Engineer - AppSec/SecDev

Mid • On-site

Warsaw, Poland

Benefits

  • Flexible working hours in a hybrid 4/1 model, with start times between 7:00 a.m. and 9:00 a.m.
  • 30 days of occasional remote work.
  • Annual bonus based on individual performance and company results.

About the job

  • Secure, test, and optimize a high-availability cloud and on-premises environment handling thousands of requests per minute.
  • Work with offensive and defensive security tools, automated SAST/DAST pipelines, C2 frameworks, cryptography, and security for production AI models.
  • Take ownership of security services from threat modeling and attack simulation through deployment of protective guardrails.
  • Solve security challenges across distributed systems, AI vulnerabilities, and a large real-time marketplace.

Skills required

  • Proven experience in deep-dive manual penetration testing of web and mobile applications, APIs, and AI-driven features, with strong secure code review skills.
  • Solid knowledge of fintech security standards and regulations, including PCI-DSS, PSD3/DORA, OWASP Top 10, OWASP API Top 10, and secure handling of PII and banking data.
  • Practical experience embedding security into the SDLC, analyzing software architectures, reviewing feature proposals, and leading threat-modeling sessions.
  • Hands-on experience designing, tuning, and deploying SAST, DAST, and SCA solutions in fast-paced CI/CD pipelines without blocking deployment velocity.
  • Ability to independently triage, risk-score, and manage vulnerabilities across APIs, microservices, and financial infrastructure.
  • Familiarity with microservices architectures, cloud security, containerization, and secure system configuration.
  • Self-starter mindset, task ownership, effort estimation, and clear communication of actionable security guidance to engineering and product teams.

Your main responsibilities

  • Design, execute, and report manual and automated security tests across APIs, microservices, and fintech infrastructure; identify vulnerabilities and assess business risks.
  • Manage the vulnerability lifecycle, from identification and financial-impact-based risk scoring to remediation tracking with engineering teams.
  • Review architectural designs and financial feature proposals; act as the primary security liaison for engineering teams and lead collaborative threat-modeling sessions.
  • Integrate and fine-tune SAST, DAST, and SCA mechanisms in CI/CD pipelines while maintaining release velocity.
  • Support secure system configurations, monitor cloud applications, and implement preventive measures for emerging fintech threats.
  • Consult product and technology teams on security improvements and verify implementation during design and grooming ceremonies.
  • Own security initiatives from design through delivery, including estimation, prioritization, and independent problem resolution.
  • Improve security maturity through documentation, knowledge-sharing sessions, mentoring, and support for technical hiring.

What's in it for you

  • Well-equipped offices with kitchens, bicycle parking, green terraces, raised desks, ergonomic chairs, and interactive conference rooms.
  • A 16-inch or 14-inch MacBook Pro, or a Dell Windows laptop, with necessary accessories.
  • Cafeteria-plan benefits such as medical, sports, lunch, insurance, and purchase-voucher packages.
  • Employer-funded English classes related to the role.
  • Training budget, inter-team tourism, hackathons, and an internal learning platform.
  • An additional day off for volunteering.
  • Social events, including Spin Kilometers, Family Day, Fat Thursday, and Advent of Code.

Additional working environment

  • Work in a collaborative team focused on knowledge and experience sharing.
  • High autonomy in team organization, continuous development, technology selection, and ownership of delivered solutions.
  • Modern AI tools for automating repetitive work, enabling focus on complex threat analysis, security automation, and secure architecture.
  • Work at scale with more than 1,000 microservices, an open-source data bus processing 300K+ requests per second, a service mesh handling 1M+ requests per second, tens of petabytes of data, and production machine learning.

Similar jobs you might like