Unlock Full Resume Report

New offer - be the first one to apply!

September 16, 2026

Application Security Engineer (SAST / DAST / SCA + Penetration Testing)

Mid • Remote

192,000 - 264,000 PLN/yr

Warsaw, Maz, Poland

Quick Facts

  • Role: Application Security Engineer (SAST / DAST / SCA + Penetration Testing) – mid-level

  • Focus: Evidence-based application security assessments (web, API, containers) with SLA-driven workflows and AI-assisted processes

  • Working style: Remote from Poland; occasional travel

Description

You will support a DevSecOps application security program where security opinions for go-live are based on confirmed evidence, not one-off pentest reports. The work includes triaging tickets, running SAST/SCA scans, performing authenticated DAST and API security testing, and executing targeted manual penetration tests when scanners are insufficient. You will onboard applications to the security management platform and produce English reports and closure notes.

Responsibilities

  • Perform security assessments for web, API, and containerized applications from triage through scope clarification, documentation review, and closing reports

  • Run SAST (Fortify SSC / ScanCentral) and SCA (Black Duck, Sonatype) in the customer’s Azure DevOps pipelines; publish results when pipelines are not available

  • Onboard applications into ASPM (CodeDX / Software Risk Manager) with correct identity and environment mapping

  • Configure and execute authenticated DAST (Burp Suite Professional, OpenText DAST / WebInspect) and API scans; support IAST (Seeker) where deployed

  • Triage findings: confirm/reject hits, eliminate false positives, set severity/CWE, and enforce the “Medium and Above” go-live gate with evidence in ASPM

  • Conduct manual penetration testing for logic and authorization issues (e.g., IDOR/BOLA), authentication (OAuth2/OIDC, JWT, sessions), business logic, file uploads, and admin panel flows

  • Review container image and infrastructure findings (Prisma Cloud Compute, Tenable) in the same decision flow for go-live

  • Defend findings with application owners and developers in English; perform retests after remediation and keep ticket status current

  • Automate repeatable tasks using scripts for tools/APIs; contribute skills and connectors for AI agents and team knowledge-base runbooks

Requirements

  • 3+ years in application security, DevSecOps, or application penetration testing

  • Practical experience with at least two of SAST, DAST, SCA (any vendor)

  • Ability to read code to confirm/dismiss SAST findings and identify fixes (C#/.NET, Java, JavaScript/TypeScript, or Python)

  • Familiarity with OWASP Top 10, OWASP API Security Top 10, ASVS, WSTG, and CWE

  • Knowledge of CI/CD (Azure DevOps, GitLab CI, or GitHub Actions) and container/Kubernetes boundaries

  • Basic Azure fundamentals (Entra ID, APIM, Application Gateway/WAF)

  • Strong ticket and evidence discipline: SLA adherence, complete repeatable evidence, and strict client data/environment access via VDI → PAM → jump host

  • English B2+ for written reports/closure notes and client meetings

  • Availability for early meetings aligned to the client time zone; willingness to sign an NDA and pass client verification

Benefits

  • Net 16,000–22,000 PLN per month (B2B) depending on experience

  • Long-term program with stable workload

  • Remote work from Poland; occasional company-paid trips to Abu Dhabi

  • Enterprise security tooling and real impact on go-live decisions at national scale

  • Mentoring and collaboration with pentesters, AI red team, DevSecOps architects, and threat modeling specialists; report reviews and internal runbooks

  • Opportunity to co-develop AI-assisted DevSecOps using internal agents and the FuseAI platform

  • Flexible working hours outside client meeting rhythm; clear growth path toward senior/lane roles

Similar jobs you might like