Ernst and Young

Senior Vulnerability & Application Security Engineer

Ernst and Young
Apply
25 days ago
Wrocław, PolandSenior

Responsibilities

  • Prepare detailed security review reports and remediation guidance.
  • Research application security vulnerabilities and attack vectors.
  • Configure, manage, and update vulnerability assessment tools.
  • Support development teams in configuring and using self-scan tools effectively.
  • Interpret scan results, identify false positives, and prioritize remediation efforts.
  • Automate application security scanning within CI/CD pipelines.
  • Perform manual and automated security testing across web, thick-client, mobile, VoIP, wireless, Android, iOS, and AI-integrated applications.
  • Conduct manual code reviews and assess secure coding practices.
  • Lead strategic initiatives, mentor new team members, and drive continuous service improvement.
  • Explain security policies and implementation guidance to developers, architects, and non-technical stakeholders.
  • Communicate risk and mitigation status to executives, developers, and other relevant teams.
  • Collaborate with security consulting, development, project management, DevOps, vendors, and product management teams.

Requirements

  • 5 to 8 years of experience in application security assessment.
  • Hands-on experience with web, thick-client, and mobile application security reviews.
  • Experience with manual and automated application security testing methodologies.
  • Proficiency with Burp Professional, Nmap, Wireshark, Nessus, and echomirage.
  • Experience with WebInspect, Qualys WAS, Checkmarx, WhiteSource, or similar automated application scanning tools.
  • Basic knowledge of C/C++, C#, Java, ASP.NET, Perl, and Python scripting.
  • Understanding of secure coding principles, common coding vulnerabilities, and the OWASP Top Ten.
  • Knowledge of security requirements for ASP.NET and Java applications.
  • Knowledge of TCP/IP and network security, including firewalls, IDS/IPS, and encryption.
  • Ability to test Android and iOS applications and AI-integrated projects.
  • Knowledge of manual code review and application, network, and system security architecture.
  • Strong problem-solving, multitasking, prioritization, communication, and learning abilities.
  • Ability to work with vendors and diverse cross-functional teams and align security goals with business objectives.
  • A bachelor’s degree or higher in Information Technology, Cyber Security, or a related field is ideally preferred.
  • Interest in relevant certifications such as CEH, OSCP, CISSP, CISM, CISA, Microsoft Azure, AWS, or GCP.

Benefits

  • Hybrid work arrangement in Wrocław or Katowice with 2 days in the office and 3 days remote.
  • Continuous learning, coaching, and opportunities to develop skills and insights.
  • Inclusive and diverse culture with flexibility to make a meaningful impact.
  • Work with global teams, projects, and well-known brands across EY’s international delivery network.
Ernst and Young

About Ernst and Young

10,000+ employees
Contact me