Application Security Architect

Papaya Global

Kraków

On-site

PLN 200,000 - 350,000

Full time

18 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Papaya Global is seeking an Application Security / Security Architect to embed security across the application lifecycle, partnering with R&D, DevOps/Cloud, product, and the cybersecurity team to improve the security of applications, APIs, repositories, data stores, and application‑facing cloud services.

You will combine architecture, threat modeling, secure software development, vulnerability validation, and practical engineering partnership to turn findings into clear remediation work for

Qualifications

  • 4+ years of hands-on experience in application security, product security, or security architecture.
  • Strong understanding of secure software development lifecycles, threat modeling, security requirements, architecture reviews, and practical risk assessment.
  • Hands-on experience with web applications, APIs, microservices, authentication, authorization, data protection, secrets management, and service-to-service communication.
  • Code-reading or code-review experience in modern programming languages and ability to explain security issues clearly to engineers.
  • Background as a software developer or DevOps/software architecture with daily coding exposure.
  • Experience with application-security tooling such as SAST, DAST, SCA, secret scanning, CSPM, or security testing platforms.
  • Experience validating vulnerabilities and managing remediation from discovery through verified closure.
  • Strong written and verbal communication; ability to influence R&D, DevOps, product, and business stakeholders without authority.
  • Experience using AI tools in engineering work for vulnerability analysis, AI-assisted code review, triage, and exploit development.

Responsibilities

  • Own and mature the application-security and security-architecture program across product and internal applications, APIs & services, and data stores.
  • Conduct threat modeling, architecture reviews, security design reviews, and risk assessments for new systems and materially changed services.
  • Define application-security requirements, review triggers, and practical security patterns for authentication, authorization, secrets, data protection, input handling, APIs, service-to-service communication, and security logging.
  • Review source code, high-risk configurations, CI/CD security checks, and application integrations with engineering teams; provide actionable guidance to enhance security posture.
  • Validate and prioritize findings from vulnerability-management and security-assessment tooling, penetration tests, and other security assessments - distinguish true risk from noise, and translate findings into clear engineering tasks and track their status.
  • Own the operating process for penetration testing and bug bounty programs, including scope, intake, triage, communication, remediation tracking, and verification of fixes.
  • Identify recurring vulnerability themes and root causes, then drive preventive improvements in engineering practices, tooling, architecture, and developer enablement.
  • Partner with Security Operations to provide application context, logging requirements, detection opportunities, and context relevant to monitoring and incident response.

Skills

Application security
Threat modeling
Secure SDLC
Security architecture
API security
Code review
CI/CD security

Tools

SAST
DAST
SCA
CSPM
Vulnerability management
Bug bounty tooling

Job description

Papaya Global is seeking an Application Security / Security Architect to embed security across the application lifecycle, partnering with R&D, DevOps/Cloud, product, and the cybersecurity team to improve the security of applications, APIs, repositories, data stores, and application‑facing cloud services.

You will combine architecture, threat modeling, secure software development, vulnerability validation, and practical engineering partnership to turn findings into clear remediation work for

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Papaya Global • Kraków

On-site
PLN 200,000 - 350,000
Global FinTech Software Architect — AI-Driven, Cross-Domain
Global FinTech Software Architect — AI-Driven, Cross-Domain

Papaya Global • Kraków

On-site
PLN 200,000 - 320,000
Senior AppSec Architect: Secure Hybrid & Cloud Solutions
Senior AppSec Architect: Secure Hybrid & Cloud Solutions

Billennium • Województwo małopolskie

On-site
PLN 200,000 - 340,000
Udemy for Business
Private medical care
Multisport card
+5
Software Architect
Software Architect

Papaya Global • Kraków

On-site
PLN 200,000 - 320,000
Application Security Engineer - Threat Modeling Champion
Application Security Engineer - Threat Modeling Champion

Decisive Point • Warszawa

On-site
PLN 356,000 - 405,000
Health insurance
Breakfast and lunch catering
Career growth budget
+5
Application Security Engineer - Secure-by-Design & CI/CD
Application Security Engineer - Secure-by-Design & CI/CD

AXA IT Solutions • Poland

Hybrid
PLN 180,000 - 240,000
Personal development
International environment
English work environment
+9
Application Security Engineer
Application Security Engineer

LionHires Recruitment • Poland

On-site
PLN 180,000 - 240,000
Applied Security Engineer – Web Apps & APIs
Applied Security Engineer – Web Apps & APIs

Jobtailor • Warszawa

On-site
PLN 120,000 - 180,000
DevOps Engineer
DevOps Engineer

Papaya Global • Kraków

On-site
PLN 180,000 - 240,000
Senior Application Security Engineer — CI/CD Security Leader
Senior Application Security Engineer — CI/CD Security Leader

Brightstar Lottery • Poland

On-site
PLN 145,000 - 224,000
Paid time off
Health insurance
Life insurance
+5