Application Security Engineer

OANDA

Kraków

On-site

PLN 180,000 - 240,000

Full time

11 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

OANDA seeks a Senior Application Security Engineer to join our global team and drive security left across our product ecosystem. You will collaborate with cross-functional engineering teams, work across a multi-language stack, and tackle security challenges from DevSecOps to AI tooling.

In this role, you will lead threat modelling, build security-critical components, review code in languages like JS, Go, Python, C++, and Java, and push defense-in-depth across cloud and IaC environments.

Qualifications

  • 2–5 years in security, with 1–2+ years in application security.
  • Expert-level knowledge of web vulnerabilities (OWASP Top 10) and secure code reviews.
  • Proficient in at least one primary language: Python, Go, Java, C#, JavaScript or C++.
  • Hands-on experience with SAST/DAST/IAST/SCA and pentest frameworks.
  • Cloud experience (AWS, Azure or GCP), networking, databases, and IaC/containers.
  • Ability to simplify security challenges and work with urgency, energy and teamwork.

Responsibilities

  • Lead & Advocate: provide technical leadership in application security and secure coding practices.
  • Build & Remediate: develop security-critical components and fix vulnerabilities across languages.
  • Apply Defense-in-Depth: review cloud security, crypto, and secrets management.
  • Automate DevSecOps: implement static analysis, fuzzing, composition analysis.
  • Threat Modelling: lead threat modelling exercises to identify risks in development.
  • Pioneer AI Security: identify secure AI development practices and tooling.
  • Secure Supply Chains: remediate third-party/library risks.

Skills

OWASP Top 10
Threat modelling
Secure coding
DevSecOps tooling
Cloud platforms

Tools

SAST
DAST
IAST
SCA
Penetration testing frameworks

Job description

Fancy helping to shape the future of FinTech?

We have always been innovators. In 1996 we were the first company to share exchange rate information, free of charge on the internet. Today, we are a world leading online trading group.

Join us to:
  • Help build the future of online trading
  • Be part of a culture driven by integrity and global impact
  • Become part of an award-winning company - check out our full list of awards here
We are only as good as our people. Luckily, our people are the best. Join us!
How do we work?

We are looking for a Senior Application Security Engineer to join our global Team and help us "push security left" across our entire product ecosystem. At OANDA, we believe security is everyone's responsibility, so we focus on developer education, continuous automation and building defense-in-depth rather than just checking compliance boxes.

You will work directly with cross-functional engineering teams in hands-on coding engagements to demonstrate secure design principles in action. Operating across a modern, multi-language stack and cloud environments, you’ll tackle security challenges at every layer. From automating DevSecOps pipelines to pioneering AI security tooling, we foster a high-energy environment focused on continuous growth and partnership.

In this role, you will:
  • Lead & Advocate: Provide technical leadership in application security, conduct threat modeling, lead design reviews, and establish secure coding practices.
  • Build & Remediate: Directly build security-critical components and fix vulnerabilities across multiple languages (JS, Go, Python, C++, Java).
  • Apply Defense-in-Depth: Touch every layer of our stack — from system hardening and Terraform (IaC) cloud security to reviewing C++ code and applying modern cryptography/secrets management (PKI, hashing).
  • Automate DevSecOps: Implement static code analysis, fuzzing, composition analysis, to make security proactive and effortless for developers.
  • Threat Modelling: Develop and lead on Threat Modelling exercises to identify risk, threats and vulnerabilities in the development phase of our applications
  • Pioneer AI Security: Identify and implement best practices for secure AI development and AI security tooling.
  • Secure Supply Chains: Work with dev teams to identify, track, and remediate third-party library vulnerabilities and supply-chain risks.
What skillset you need, to be successful in this role:
  • 2 - 5 years of relevant technical experience, with 1-2+ years focused specifically on application security / security engineering.
  • Expert-level knowledge of web application vulnerabilities (OWASP Top 10), attack vectors and secure code review.
  • Strong ability to develop in and navigate security pitfalls in at least one primary programming language (e.g., Python, Go, Java, C#, or JavaScript/C++).
  • Hands-on experience with modern testing tools (SAST, DAST, IAST, SCA, penetration testing frameworks).
  • Working knowledge of cloud platforms (AWS, Azure, or GCP), networking, databases, and containerized/IaC environments.
  • Ability to simplify complex security challenges and drive proactive solutions with urgency, high energy, and teamwork.
Nice to have:
  • Experience in Fintech / Financial Services (or familiarity with financial security threat models & regulations).
  • Hands-on experience writing Terraform (Infrastructure as Code) and managing cloud secrets.
  • Exposure to AI development frameworks, AI tooling security, or LLM vulnerability vectors.
  • Knowledge of industry compliance standards & privacy regulations (SOC2, ISO27001, NIST, GDPR).
  • Active involvement in the wider cybersecurity community (conferences, open-source security projects).

___

At OANDA, to help us efficiently process applications, we use AI-driven tools to help source and rank candidates based on professional experience and skills. While these tools provide recommendations, our recruitment process remains human-centric: all final shortlisting and hiring decisions are made by OANDA team. You have the right to request a human review of your application.

OANDA Global Corporation is a diverse and global team with offices around the world. We value the unique skills and experiences each individual brings to OANDA. We are committed to creating and sustaining a collegial work environment in which all individuals are treated with dignity and respect and one which reflects the diversity of the community in which we operate. We provide an inclusive and accessible environment for everyone. Candidates selected for an interview will be contacted directly. If you require accommodation during the recruitment and selection process, please let us know. We will work with you to provide as seamless a recruitment experience as possible.

Learn more about our culture here.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer
Senior Application Security Engineer

oanda • Kraków

On-site
PLN 180,000 - 230,000
Senior Application Security Engineer
Senior Application Security Engineer

OANDA Corporation • Kraków

On-site
PLN 180,000 - 260,000
Senior Application Security Engineer
Senior Application Security Engineer

OANDA Poland sp. z o.o. • Kraków

On-site
PLN 180,000 - 300,000
Senior GRC Analyst
Senior GRC Analyst

OANDA • Kraków

On-site
PLN 180,000 - 280,000
Lead Security Engineer
Lead Security Engineer

OANDA Corporation • Kraków

On-site
PLN 200,000 - 320,000
Team Lead Security Engineer
Team Lead Security Engineer

OANDA Poland sp. z o.o. • Kraków

On-site
PLN 250,000 - 420,000
GRC Analyst
GRC Analyst

OANDA Corporation • Warszawa

Hybrid
PLN 140,000 - 180,000
Senior GRC Analyst
Senior GRC Analyst

OANDA Poland sp. z o.o. • Kraków

On-site
PLN 180,000 - 270,000
Customer Experience Agent (Americas)
Customer Experience Agent (Americas)

OANDA Corporation • Polska

Remote
PLN 89,000 - 134,000
Fully remote
Associate Software Engineer (React.js, Python)
Associate Software Engineer (React.js, Python)

OANDA • Kraków

On-site
PLN 110,000 - 150,000