Unlock Full Resume Report

New offer - be the first one to apply!

September 4, 2026

Application Security Engineer (F/M)

Senior • On-site

160 - 215 PLN/yr

Warsaw, MZ, Poland

We are looking for an Application Security Engineer (F/M) to join the engineering team and help build security into the software development lifecycle. This role is an opportunity to move beyond traditional vulnerability management and drive a proactive approach to application security. You will work closely with software engineers, architects, DevOps and security teams to automate security controls, integrate security into CI/CD pipelines, improve secure development practices and help teams build secure-by-design applications.

Responsibilities

  • Own and continuously improve the application security posture of internally developed solutions, ensuring security is embedded throughout the software development lifecycle (SDLC).
  • Monitor, assess, prioritise, and manage application security vulnerabilities identified through penetration testing, SAST, DAST, dependency scanning, bug bounty programmes, and other security assessment activities, ensuring remediation within agreed SLAs.
  • Triage security findings to determine business risk, remediation requirements, and false positives, providing clear technical justification for all decisions.
  • Design, recommend and implement long-term, scalable security controls and automation to reduce recurring vulnerabilities, minimise manual intervention, and improve remediation efficiency across development teams.
  • Drive a shift-left security approach by integrating automated security testing, policy enforcement, and secure development practices into CI/CD pipelines and engineering workflows.
  • Identify recurring vulnerability patterns and implement preventative controls, secure frameworks, coding standards, and developer guardrails that eliminate classes of vulnerabilities at source.
  • Serve as the primary liaison with external penetration testing providers, ensuring security assessments are completed in a timely manner and findings are actionable, risk-based, and aligned with business priorities.
  • Partner with Group Security teams to maintain a single source of truth for vulnerabilities, consult, agree risk ratings, and resolve disputes relating to remediation requirements or false-positive findings.
  • Provide expert guidance on securing modern web applications, APIs, authentication mechanisms, and cloud-native architectures, with particular focus on .NET and Angular solutions.
  • Act as the Application Security subject matter expert for the Solution Delivery organisation, promoting secure design principles and security-by-default practices across all stages of solution delivery.
  • Maintain and enhance secure development standards, application security policies, and security engineering processes in line with OWASP, NIST, and industry best practices.
  • Proactively monitor emerging threats, OWASP Top 10 trends, attack techniques, and security tooling innovations, ensuring the organisation remains ahead of evolving application security risks.
  • Deliver security awareness and secure coding guidance to developers, technical leads, architects, and delivery teams to improve organisational security maturity.
  • Update governance forums and steering groups on application security posture, vulnerability trends, remediation performance, and risk reduction initiatives, providing data-driven insights and recommendations.

Requirements

  • Strong practical knowledge of the OWASP Top 10 and common web application attack vectors.
  • Deep understanding of securing modern web applications, REST APIs, authentication and authorisation mechanisms (OAuth2, OIDC, JWT).
  • Experience implementing and managing SAST, DAST, SCA, API security and penetration testing programmes.
  • Experience automating security controls within CI/CD pipelines and software delivery processes.
  • Strong knowledge of secure software engineering practices and secure-by-design principles.
  • Experience with .NET, Angular, JavaScript/TypeScript, and modern web application architectures.
  • Ability to identify strategic security improvements rather than focusing solely on vulnerability remediation.
  • Strong stakeholder management skills, with the ability to influence development teams, architects, and security functions.
  • Highly motivated, enthusiastic, and capable of working both independently and collaboratively in a team-oriented environment.
  • Exceptional analytical and problem-solving skills, with attention to detail and a business-focused approach.
  • Strong interpersonal skills, with the ability to influence technical decisions and communicate effectively in a fast-paced environment.
  • Demonstrates creativity and resourcefulness in presenting solutions to complex security challenges.

What we offer

  • The opportunity to influence technological solutions and product direction in an international financial organization.
  • Ambitious projects with a high degree of autonomy and responsibility.
  • A stable, long-term assignment with flexible working hours and a hybrid work model.

Similar jobs you might like