Unlock Full Resume Report
ATS Pass
Missing keywords
Tailored AI suggestions
Job match analysis
Interview-focused insights
New offer - be the first one to apply!
September 1, 2026
Mid Cybersecurity Engineer - AppSec/SecDev
Mid • On-site
Warsaw, Poland
Apply now
Benefits
- Flexible working hours in a hybrid 4/1 model, with start times between 7:00 a.m. and 9:00 a.m.
- 30 days of occasional remote work.
- Annual bonus based on individual performance and company results.
About the job
- Secure, test, and optimize a high-availability cloud and on-premises environment handling thousands of requests per minute.
- Work with offensive and defensive security tools, automated SAST/DAST pipelines, C2 frameworks, cryptography, and security for production AI models.
- Take ownership of security services from threat modeling and attack simulation through deployment of protective guardrails.
- Solve security challenges across distributed systems, AI vulnerabilities, and a large real-time marketplace.
Skills required
- Proven experience in deep-dive manual penetration testing of web and mobile applications, APIs, and AI-driven features, with strong secure code review skills.
- Solid knowledge of fintech security standards and regulations, including PCI-DSS, PSD3/DORA, OWASP Top 10, OWASP API Top 10, and secure handling of PII and banking data.
- Practical experience embedding security into the SDLC, analyzing software architectures, reviewing feature proposals, and leading threat-modeling sessions.
- Hands-on experience designing, tuning, and deploying SAST, DAST, and SCA solutions in fast-paced CI/CD pipelines without blocking deployment velocity.
- Ability to independently triage, risk-score, and manage vulnerabilities across APIs, microservices, and financial infrastructure.
- Familiarity with microservices architectures, cloud security, containerization, and secure system configuration.
- Self-starter mindset, task ownership, effort estimation, and clear communication of actionable security guidance to engineering and product teams.
Your main responsibilities
- Design, execute, and report manual and automated security tests across APIs, microservices, and fintech infrastructure; identify vulnerabilities and assess business risks.
- Manage the vulnerability lifecycle, from identification and financial-impact-based risk scoring to remediation tracking with engineering teams.
- Review architectural designs and financial feature proposals; act as the primary security liaison for engineering teams and lead collaborative threat-modeling sessions.
- Integrate and fine-tune SAST, DAST, and SCA mechanisms in CI/CD pipelines while maintaining release velocity.
- Support secure system configurations, monitor cloud applications, and implement preventive measures for emerging fintech threats.
- Consult product and technology teams on security improvements and verify implementation during design and grooming ceremonies.
- Own security initiatives from design through delivery, including estimation, prioritization, and independent problem resolution.
- Improve security maturity through documentation, knowledge-sharing sessions, mentoring, and support for technical hiring.
What's in it for you
- Well-equipped offices with kitchens, bicycle parking, green terraces, raised desks, ergonomic chairs, and interactive conference rooms.
- A 16-inch or 14-inch MacBook Pro, or a Dell Windows laptop, with necessary accessories.
- Cafeteria-plan benefits such as medical, sports, lunch, insurance, and purchase-voucher packages.
- Employer-funded English classes related to the role.
- Training budget, inter-team tourism, hackathons, and an internal learning platform.
- An additional day off for volunteering.
- Social events, including Spin Kilometers, Family Day, Fat Thursday, and Advent of Code.
Additional working environment
- Work in a collaborative team focused on knowledge and experience sharing.
- High autonomy in team organization, continuous development, technology selection, and ownership of delivered solutions.
- Modern AI tools for automating repetitive work, enabling focus on complex threat analysis, security automation, and secure architecture.
- Work at scale with more than 1,000 microservices, an open-source data bus processing 300K+ requests per second, a service mesh handling 1M+ requests per second, tens of petabytes of data, and production machine learning.
Similar jobs you might like
Software Engineer 1 (Java / Kotlin) - Allegro Ads
Allegro
Junior
Technology
Poznan, WP, Poland · Hybrid
134K zł - 183K zł/yr
24 days ago
Senior Software Engineer (Java / Kotlin) - Product Page
Allegro
Senior
Technology
Torun, KP, Poland · Hybrid
226K zł - 311K zł/yr
24 days ago
Software Engineer 1 (.NET) - Allegro Pay
Allegro
Junior
Technology
Krakow, MA, Poland · Hybrid
134K zł - 183K zł/yr
24 days ago
Junior Test Automation Engineer
Allegro
Junior
Technology
Poznan, WP, Poland · Hybrid
134K zł - 183K zł/yr
24 days ago
Mobile Software Engineer 2 (iOS)
Allegro
Mid
Technology
Warsaw, MZ, Poland · Hybrid
175K zł - 250K zł/yr
24 days ago