Application Security Engineer

Papaya Global

Kraków

On-site

PLN 200,000 - 350,000

Full time

19 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Papaya Global is seeking an Application Security / Security Architect to embed security across the application lifecycle, partnering with R&D, DevOps/Cloud, product, and the cybersecurity team to improve the security of applications, APIs, repositories, data stores, and application‑facing cloud services.

You will combine architecture, threat modeling, secure software development, vulnerability validation, and practical engineering partnership to turn findings into clear remediation work for

Qualifications

  • 4+ years of hands-on experience in application security, product security, or security architecture.
  • Strong understanding of secure software development lifecycles, threat modeling, security requirements, architecture reviews, and practical risk assessment.
  • Hands-on experience with web applications, APIs, microservices, authentication, authorization, data protection, secrets management, and service-to-service communication.
  • Code-reading or code-review experience in modern programming languages and ability to explain security issues clearly to engineers.
  • Background as a software developer or DevOps/software architecture with daily coding exposure.
  • Experience with application-security tooling such as SAST, DAST, SCA, secret scanning, CSPM, or security testing platforms.
  • Experience validating vulnerabilities and managing remediation from discovery through verified closure.
  • Strong written and verbal communication; ability to influence R&D, DevOps, product, and business stakeholders without authority.
  • Experience using AI tools in engineering work for vulnerability analysis, AI-assisted code review, triage, and exploit development.

Responsibilities

  • Own and mature the application-security and security-architecture program across product and internal applications, APIs & services, and data stores.
  • Conduct threat modeling, architecture reviews, security design reviews, and risk assessments for new systems and materially changed services.
  • Define application-security requirements, review triggers, and practical security patterns for authentication, authorization, secrets, data protection, input handling, APIs, service-to-service communication, and security logging.
  • Review source code, high-risk configurations, CI/CD security checks, and application integrations with engineering teams; provide actionable guidance to enhance security posture.
  • Validate and prioritize findings from vulnerability-management and security-assessment tooling, penetration tests, and other security assessments - distinguish true risk from noise, and translate findings into clear engineering tasks and track their status.
  • Own the operating process for penetration testing and bug bounty programs, including scope, intake, triage, communication, remediation tracking, and verification of fixes.
  • Identify recurring vulnerability themes and root causes, then drive preventive improvements in engineering practices, tooling, architecture, and developer enablement.
  • Partner with Security Operations to provide application context, logging requirements, detection opportunities, and context relevant to monitoring and incident response.

Skills

Application security
Threat modeling
Secure SDLC
Security architecture
API security
Code review
CI/CD security

Tools

SAST
DAST
SCA
CSPM
Vulnerability management
Bug bounty tooling

Job description

Papaya Global is a rapidly growing, award-winning B2B tech unicorn with an ambitious mission to revolutionize the payroll & payments industry. With over $400M raised from multiple tier-one investors, our innovative technology provides a comprehensive solution for managing global workforces, encompassing everything from hiring and onboarding to managing and paying employees in over 160 countries.

We are looking for an Application Security / Security Architect to help embed security across the application lifecycle. In this role, you will partner with R&D, DevOps/Cloud, product, and the cybersecurity team to improve the security of applications, APIs, repositories, data stores, and application‑facing cloud services.

You will combine architecture, threat modeling, secure software development, vulnerability validation, and practical engineering partnership. You will review designs and high‑risk changes, define security requirements and reusable patterns, validate findings from vulnerability‑management and security‑assessment tooling, penetration tests, and bug‑bounty activity, and turn those findings into clear, prioritized remediation work for engineering teams.

This role is ideal for someone who can move comfortably between architecture discussions, code and configuration reviews, security testing, and executive‑level risk communication. The goal is to help the company build secure applications by design while making application‑security decisions faster, clearer, and more measurable.

Responsibilities
  • Own and mature the application-security and security-architecture program across product and internal applications, APIs & services, and data stores.
  • Conduct threat modeling, architecture reviews, security design reviews, and risk assessments for new systems and materially changed services.
  • Define application-security requirements, review triggers, and practical security patterns for authentication, authorization, secrets, data protection, input handling, APIs, service-to-service communication, and security logging.
  • Review source code, high-risk configurations, CI/CD security checks, and application integrations with engineering teams; provide actionable guidance to enhance security posture.
  • Validate and prioritize findings from vulnerability‑management and security‑assessment tooling, penetration tests, and other security assessments - distinguish true risk from noise, and translate findings into clear engineering tasks and track their status.
  • Own the operating process for penetration testing and bug bounty programs, including scope, intake, triage, communication, remediation tracking, and verification of fixes.
  • Identify recurring vulnerability themes and root causes, then drive preventive improvements in engineering practices, tooling, architecture, and developer enablement.
  • Partner with Security Operations to provide application context, logging requirements, detection opportunities, and context relevant to monitoring and incident response.
Requirements:
  • 4+ years of hands‑on experience in application security, product security, security architecture, or a closely related role.
  • Strong understanding of secure software development lifecycles, threat modeling, security requirements, architecture reviews, and practical risk assessment.
  • Hands‑on experience with web applications, APIs, microservices, authentication, authorization, data protection, secrets management, and service-to-service communication.
  • Practical code‑reading or code‑review experience in one or more modern programming languages, with the ability to explain security issues clearly to engineers.
  • Background as a software developer, or comparable hands‑on experience as a builder — for example in DevOps engineering or software architecture — working with code on a daily basis.
  • Experience with application‑security tooling or equivalent capabilities, such as vulnerability management, SAST, DAST, SCA, secret scanning, CSPM, or security testing platforms.
  • Experience validating vulnerabilities and managin g remediation from discovery through verified closure.
  • Strong written and verbal communication skills, with the ability to influence R&D, DevOps, product, and business stakeholders without relying on authority alone.
  • Experience using AI tools in day-to-day engineering work, as well as specifically for vulnerability analysis and exploitation, including AI-assisted code review, vulnerability triage, and exploit development.
Nice to have:
  • Experience building or maturing an application‑security program in a cloud‑native or fast‑growing technology environment.
  • Experience with security architecture for APIs, distributed systems, containerized or cloud‑native workloads, data stores, CI/CD pipelines, and third‑party integrations.
  • Experience coordinating penetration testing, bug‑bounty programs, responsible disclosure, and external security researchers.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Architect
Application Security Architect

Papaya Global • Kraków

On-site
PLN 200,000 - 350,000
Application Security Engineer
Application Security Engineer

LionHires Recruitment • Poland

On-site
PLN 180,000 - 240,000
Application Security Engineer
Application Security Engineer

Solidgate • Województwo mazowieckie

On-site
30+ days off
Unlimited sick leave
Free office meals
+2
Software Architect
Software Architect

Papaya Global • Kraków

On-site
PLN 200,000 - 320,000
Application Security Engineer
Application Security Engineer

SOFTSWISS • Warszawa

Hybrid
PLN 60,000 - 90,000
Full-time remote work opportunities
Private insurance
Additional 1 Day Off per calendar year
+5
Application Security Research Engineer
Application Security Research Engineer

Commit • Warszawa

On-site
PLN 517,000 - 775,000
Application Security Engineer
Application Security Engineer

Starburst • Poland

Hybrid
PLN 120,000 - 180,000
Competitive pay
Attractive stock grants
Flexible paid time off
Application Security Engineer – Penetration Tester
Application Security Engineer – Penetration Tester

Jobtailor • Warszawa

On-site
PLN 120,000 - 180,000
AppSec Expert
AppSec Expert

IDEMIA • Łódź

On-site
PLN 180,000 - 240,000
Application Security Engineer
Application Security Engineer

SOFTSWISS • Poland

On-site
PLN 218,579 - 327,869
Full-time remote work opportunities
Private insurance
Sports program compensation
+2