8 months ago
Warsaw, PolandMid Level
Responsibilities
- Build and maintain secure coding standards and support adoption across development teams.
- Conduct threat modeling during architecture and design stages.
- Implement and improve application security testing, including SAST, DAST, dependency scanning, secrets scanning, and CI/CD security checks.
- Perform application security assessments and maturity evaluations using OWASP ASVS and OWASP SAMM.
- Manage the vulnerability lifecycle from triage and prioritization through remediation support and validation.
- Support external penetration testing and Bug Bounty programs.
- Identify and mitigate security risks in cloud environments and CI/CD pipelines.
Requirements
- At least 2 years of experience in Application Security or Product Security.
- Hands-on experience with OWASP Top 10 vulnerabilities.
- Practical experience with secure code reviews, threat modeling, SAST and DAST tools, and CI/CD integration.
- Strong understanding of web application and API security.
- Ability to communicate clearly with engineers and partner effectively with development teams.
- Preferred experience includes container security, cloud security tooling, DevSecOps, shift-left security practices, automation of application security processes, and a software engineering background or close collaboration with development teams.
Benefits
- 30+ days off and unlimited sick leave.
- Free office meals and health coverage.
- Apple equipment for work.
- Courses, conferences, sports, and wellness benefits.
- Collaborative environment with autonomy to propose and implement security practices and tooling.
