Application Security Engineer

AXA IT Solutions

Poland

In loco

PLN 180.000 - 240.000

Tempo pieno

14 giorni+
Generatore di candidature

Distinguiti per questa posizione — genera un curriculum e una lettera di presentazione personalizzati in circa un minuto.

Supera i filtri ATS

Vantaggi offerti da questo lavoro

Personal development
International environment
English work environment
Flexible hours
Hybrid work
Supportive team
Conferences in Poland
External training
E-learning platforms
In-company training
Leadership support
Knowledge exchange

Descrizione del lavoro

AXA IT Solutions is seeking an Application Security Engineer to reinforce secure development practices across the SDLC. You will work with engineers, architects, DevOps and security teams to automate controls and embed security into CI/CD pipelines.

Responsibilities include prioritising vulnerabilities, driving long-term security controls, and supporting secure-by-default practices across modern .NET/Angular apps in a hybrid work environment.

Competenze

  • Strong practical knowledge of OWASP Top 10 and web attack vectors.
  • Experience securing web apps, APIs and authentication mechanisms.
  • Experience with security testing in CI/CD pipelines.

Mansioni

  • Own and improve the application security posture across SDLC.
  • Triage findings from penetration tests and automated tooling with risk-based focus.
  • Automate security controls to reduce recurring vulnerabilities.
  • Integrate secure testing into CI/CD and development workflows.
  • Collaborate with security and engineering teams to promote secure design.

Conoscenze

OWASP Top 10
Web API security
CI/CD security
Secure-by-design
Threat modeling
Stakeholder management

Strumenti

SAST tools
DAST tools
SCA tools

Descrizione del lavoro

We are looking for an Application Security Engineer (F/M) to join our engineering team and help us build security into the software development lifecycle.This role is an opportunity to move beyond traditional vulnerability management and drive a proactive approach to application security. You will work closely with software engineers, architects, DevOps and security teams to automate security controls, integrate security into CI/CD pipelines, improve secure development practices and help teams build secure-by-design applications.

Your responsibilities
  • Own and continuously improve the application security posture of internally developed solutions, ensuring security is embedded throughout the software development lifecycle (SDLC).
  • Monitor, assess, prioritise, and manage application security vulnerabilities identified through penetration testing, SAST, DAST, dependency scanning, bug bounty programmes, and other security assessment activities, ensuring remediation within agreed SLAs.
  • Triage security findings to determine business risk, remediation requirements, and false positives, providing clear technical justification for all decisions.
  • Design, recommend and implement long-term, scalable security controls and automation to reduce recurring vulnerabilities, minimise manual intervention, and improve remediation efficiency across development teams.
  • Drive a shift-left security approach by integrating automated security testing, policy enforcement, and secure development practices into CI/CD pipelines and engineering workflows.
  • Identify recurring vulnerability patterns and implement preventative controls, secure frameworks, coding standards, and developer guardrails that eliminate classes of vulnerabilities at source.
  • Serve as the primary liaison with external penetration testing providers, ensuring security assessments are completed in a timely manner and findings are actionable, risk-based, and aligned with business priorities.
  • Partner with Group Security teams to maintain a single source of truth for vulnerabilities, consult, agree risk ratings, and resolve disputes relating to remediation requirements or false-positive findings.
  • Provide expert guidance on securing modern web applications, APIs, authentication mechanisms, and cloud-native architectures, with particular focus on .NET and Angular solutions.
  • Act as the Application Security subject matter expert for the Solution Delivery organisation, promoting secure design principles and security-by-default practices across all stages of solution delivery.
  • Maintain and enhance secure development standards, application security policies, and security engineering processes in line with OWASP, NIST, and industry best practices.
  • Proactively monitor emerging threats, OWASP Top 10 trends, attack techniques, and security tooling innovations, ensuring the organisation remains ahead of evolving application security risks.
  • Deliver security awareness and secure coding guidance to developers, technical leads, architects, and delivery teams to improve organisational security maturity.
  • Update on application security posture, vulnerability trends, remediation performance, and risk reduction initiatives to governance forums and steering groups, providing data-driven insights and recommendations.
Requirements
  • Strong practical knowledge of the OWASP Top 10 and common web application attack vectors.
  • Deep understanding of securing modern web applications, REST APIs, authentication and authorisation mechanisms (OAuth2, OIDC, JWT).
  • Experience implementing and managing SAST, DAST, SCA, API security and penetration testing programmes.
  • Experience automating security controls within CI/CD pipelines and software delivery processes.
  • Strong knowledge of secure software engineering practices and secure-by-design principles.
  • Ability to identify strategic security improvements rather than focusing solely on vulnerability remediation.
  • Strong stakeholder management skills, with the ability to influence development teams, architects, and security functions.
  • Highly motivated, enthusiastic, and capable of working both independently and collaboratively in a team-oriented environment.
  • Exceptional analytical and problem-solving skills, with attention to detail and a business-focused approach.
  • Strong interpersonal skills, with the ability to influence technical decisions and communicate effectively in a fast-paced environment.
  • Demonstrates creativity and resourcefulness in presenting solutions to complex security challenges.
What we offer:
  • Opportunities for personal development in an international environment
  • Working with modern technologies and constant occasion to learn something new
  • Work in English on an everyday basis
  • Flexible working hours and home office (hybrid work)
  • Work in a good atmosphere, supportive teams, among employees who are willing to share their knowledge, among others as part of internal development initiatives
  • conferences in Poland
  • external training
  • industry e-learning platforms
  • in-company training
  • substantive support from technology leaders
  • exchange of technical knowledge within the company
Ottieni la revisione del curriculum gratis e riservata.

o trascina qui il file.

Similar jobs

Offerte di lavoro simili che vale la pena confrontare

Senior Application Security Engineer
Senior Application Security Engineer

Adecco • Warszawa

Ibrido
PLN 210.000 - 270.000
Private medical care
Life insurance
Hybrid work model
Application Security Engineer (F/M)
Application Security Engineer (F/M)

AXA IT Solutions • Warszawa

Ibrido
PLN 180.000 - 240.000
The opportunity to influence product方向
Ambitious projects with high autonomy
Hybrid work model
Application Security Engineer
Application Security Engineer

Adecco • Warszawa

In loco
PLN 180.000 - 280.000
Employment contract
Hybrid work in Warsaw (2-3 days/week)
Application Security Engineer
Application Security Engineer

SOFTSWISS • Polonia

In loco
PLN 218.579 - 327.869
Full-time remote work opportunities
Private insurance
Sports program compensation
+2
Application Security Engineer
Application Security Engineer

emagine Polska • Warszawa

In loco
PLN 303.000 - 477.000
Application Security Specialist (regular/senior) (She/He/They)
Application Security Specialist (regular/senior) (She/He/They)

Accenture Poland • Województwo mazowieckie

In loco
PLN 80.000 - 120.000
Permanent employment contract
Private medical care
Employee Assistance Program
+2
Security Engineer (SecOps)
Security Engineer (SecOps)

inFakt • Kraków

In loco
PLN 111.600 - 167.400
Private medical care for you and your family/partner
MultiSport Benefit card for you and a loved one
Daily lunches, fresh fruit, and good coffee
+2
Security Transformation Consultant (regular/senior) (She/He/They)
Security Transformation Consultant (regular/senior) (She/He/They)

Accenture Poland • Warszawa

In loco
PLN 180.000 - 240.000
Permanent employment contract
Private medical care
Life insurance
+2
Application Security Engineer | Senior
Application Security Engineer | Senior

Nord Security • Polonia

In loco
PLN 191.952 - 334.800
Private health insurance
Flexible work arrangements
Physical well-being programs
+3
Application Security Specialist (regular/senior) (She/He/They)
Application Security Specialist (regular/senior) (She/He/They)

Accenture • Polonia

In loco
PLN 267.840 - 334.800
Permanent employment contract
Individual support and coaching
Wide training package
+3