
Senior Vulnerability & Application Security Engineer
Ernst and Young25 days ago
Wrocław, PolandSenior
Responsibilities
- Prepare detailed security review reports and remediation guidance.
- Research application security vulnerabilities and attack vectors.
- Configure, manage, and update vulnerability assessment tools.
- Support development teams in configuring and using self-scan tools effectively.
- Interpret scan results, identify false positives, and prioritize remediation efforts.
- Automate application security scanning within CI/CD pipelines.
- Perform manual and automated security testing across web, thick-client, mobile, VoIP, wireless, Android, iOS, and AI-integrated applications.
- Conduct manual code reviews and assess secure coding practices.
- Lead strategic initiatives, mentor new team members, and drive continuous service improvement.
- Explain security policies and implementation guidance to developers, architects, and non-technical stakeholders.
- Communicate risk and mitigation status to executives, developers, and other relevant teams.
- Collaborate with security consulting, development, project management, DevOps, vendors, and product management teams.
Requirements
- 5 to 8 years of experience in application security assessment.
- Hands-on experience with web, thick-client, and mobile application security reviews.
- Experience with manual and automated application security testing methodologies.
- Proficiency with Burp Professional, Nmap, Wireshark, Nessus, and echomirage.
- Experience with WebInspect, Qualys WAS, Checkmarx, WhiteSource, or similar automated application scanning tools.
- Basic knowledge of C/C++, C#, Java, ASP.NET, Perl, and Python scripting.
- Understanding of secure coding principles, common coding vulnerabilities, and the OWASP Top Ten.
- Knowledge of security requirements for ASP.NET and Java applications.
- Knowledge of TCP/IP and network security, including firewalls, IDS/IPS, and encryption.
- Ability to test Android and iOS applications and AI-integrated projects.
- Knowledge of manual code review and application, network, and system security architecture.
- Strong problem-solving, multitasking, prioritization, communication, and learning abilities.
- Ability to work with vendors and diverse cross-functional teams and align security goals with business objectives.
- A bachelor’s degree or higher in Information Technology, Cyber Security, or a related field is ideally preferred.
- Interest in relevant certifications such as CEH, OSCP, CISSP, CISM, CISA, Microsoft Azure, AWS, or GCP.
Benefits
- Hybrid work arrangement in Wrocław or Katowice with 2 days in the office and 3 days remote.
- Continuous learning, coaching, and opportunities to develop skills and insights.
- Inclusive and diverse culture with flexibility to make a meaningful impact.
- Work with global teams, projects, and well-known brands across EY’s international delivery network.