17 days ago
Kraków, PolandSenior
Responsibilities
- Provide technical leadership in application security, threat modeling, design reviews, and secure coding practices.
- Build security-critical components and remediate vulnerabilities across JavaScript, Go, Python, C++, and Java.
- Apply defense-in-depth through system hardening, Terraform-based cloud security, code review, cryptography, PKI, hashing, and secrets management.
- Automate SAST, DAST, IAST, software composition analysis, fuzzing, and other DevSecOps practices.
- Lead threat-modeling exercises to identify application risks, threats, and vulnerabilities during development.
- Develop secure AI development practices and AI security tooling.
- Identify, track, and remediate third-party library vulnerabilities and software supply-chain risks.
Requirements
- 2–5 years of relevant technical experience, including 1–2+ years focused on application security or security engineering.
- Expert-level knowledge of web application vulnerabilities, OWASP Top 10, attack vectors, and secure code review.
- Ability to develop in and navigate security pitfalls in at least one primary language such as Python, Go, Java, C#, JavaScript, or C++.
- Hands-on experience with SAST, DAST, IAST, SCA, and penetration-testing frameworks.
- Working knowledge of AWS, Azure, or GCP; networking; databases; and containerized or infrastructure-as-code environments.
- Ability to simplify complex security challenges and drive proactive solutions collaboratively.
- Preferred: fintech or financial-services experience, Terraform and cloud-secrets experience, AI security exposure, knowledge of SOC2, ISO27001, NIST, and GDPR, and involvement in the cybersecurity community.
