Application Security Engineer

SOFTSWISS

Poland

On-site

PLN 218,579 - 327,869

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Full-time remote work opportunities
Private insurance
Sports program compensation
Comprehensive Mental Health Programme
Free online English lessons

Job summary

A technology company is seeking an experienced Application Security Engineer to ensure secure software development and mitigate security vulnerabilities. You will collaborate with product teams and oversee security practices throughout the development lifecycle. The ideal candidate has at least 2 years of experience in application security and a university degree in a related field. This position offers full-time remote work with benefits like private insurance and flexible hours.

Qualifications

  • 2+ years of experience in application security.
  • Knowledge of secure development processes and best practices.
  • Deep understanding of common web application vulnerabilities.

Responsibilities

  • Lead threat modeling and risk assessments.
  • Perform in-depth manual code reviews.
  • Manage the bug bounty program.

Skills

Application security
Web application security mechanisms
Understanding of OWASP Top 10
Secure development processes
Root-cause analysis
Intermediate English level

Education

University degree in Computer Science, Information Security, or related field

Tools

SAST/DAST tools

Job description

Overview

SOFTSWISS is looking for Application Security Engineer to join our team. SOFTSWISS security team takes care of iGaming services protection, data privacy, and business continuity to ensure that nothing distracts satisfied customers from using our products. We work closely with the IT team that develops and supports our services, and together we create genuinely excellent and secure iGaming products.

Purpose of the role

Our goal is to make sure that we deploy secure software to production without unnecessary bottlenecks, that applications are properly hardened, and security vulnerabilities, once discovered, are fixed by the developers.

As an Application Security Engineer, you will play a crucial role in ensuring the security of our applications throughout the entire software development lifecycle (SDLC). You will partner closely with the product teams to identify, analyze, and mitigate security vulnerabilities, contributing to the creation of trustworthy and robust products.

Key responsibilities
  • Partner with product teams during the design phase to lead threat modeling and risk assessments sessions, translating complex security threats into clear, actionable security requirements.
  • Perform in-depth manual code reviews on critical applications to identify complex logical vulnerabilities as part of white-box security assessment.
  • Plan, design, implement, automate and (if you wish) support AppSec tools.
  • Contribute to building a company-wide processes for secure code development and deployment.
  • Triage identified security vulnerabilities, provide clear and actionable descriptions and ensure these findings are properly addressed and mitigated.
  • Manage the bug bounty program, collaborate with researches and internal teams to resolve the discovered vulnerabilities.
  • Partner with Dev/QA teams throughout the development lifecycle to enhance the application's security posture by providing expert consulting, continuous knowledge sharing, and actionable security guidance.
Required Experience
  • 2+ years of experience in application security.
  • Knowledge of secure development processes and best practices.
  • Deep understanding of web application security mechanisms (i.e., how the web actually works? What is SOP and why do we need CORS? What is CSP?).
  • Deep understanding of common web application vulnerabilities (i.e., OWASP Top 10), and the most effective ways to prevent them.
  • Knowledge of secure system/application architecture and design principles.
  • Understanding of modern threats to high-performance web applications that is used by millions of users daily.
  • Understanding of modern authentication/authorisation patterns (OAuth, OIDC, JWT, etc.)
  • Practical hands‑on expertise in identifying vulnerabilities through security assessment and secure code review, coupled with the ability to perform deep root‑cause analysis to drive systemic fixes.
  • University degree in Computer Science, Information Security, or related field, or equivalent combination of education and experience.
  • Intermediate or higher English level.
Nice to have
  • Passion about programming.
  • Technical knowledge of network and operating systems security.
  • Hands‑on DevSecOps experience.
  • Practice of participation in bug bounty programs and/or CTFs.
  • Deep knowledge of SAST/DAST tools, including customisation.
  • Relevant certifications (i.e., OSWE, GWEB, etc.).
Our Benefits
  • Full‑time remote work opportunities and flexible working hours
  • Private insurance
  • Additional 1 Day Off per calendar year
  • Sports program compensation
  • Comprehensive Mental Health Programme
  • Free online English lessons with a native speaker
  • Generous referral program
  • Training, internal workshops, and participation in international professional conferences and corporate events.

Locations: Warsaw, Poland; Poznan, Poland; T'bilisi, Georgia; Belgrade, Serbia; Valletta, Malta. Remote status: Fully Remote. Employment type: Full-time.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer
Senior Application Security Engineer

Adecco • Warszawa

Hybrid
PLN 210,000 - 270,000
Private medical care
Life insurance
Hybrid work model
Application Security Engineer
Application Security Engineer

AXA IT Solutions • Poland

On-site
PLN 180,000 - 240,000
Personal development
International environment
English work environment
+9
Application Security Engineer (F/M)
Application Security Engineer (F/M)

AXA IT Solutions • Warszawa

Hybrid
PLN 180,000 - 240,000
The opportunity to influence product方向
Ambitious projects with high autonomy
Hybrid work model
Application Security Engineer | Senior
Application Security Engineer | Senior

Nord Security • Poland

On-site
PLN 191,952 - 334,800
Private health insurance
Flexible work arrangements
Physical well-being programs
+3
Application Security Architect
Application Security Architect

Capital • Warszawa

On-site
PLN 250,000 - 400,000
Annual bonus
Generous annual leave
Medical insurance
+4
Senior Application Security Engineer
Senior Application Security Engineer

Capital • Warszawa

On-site
PLN 320,000 - 460,000
Hybrid work model
Medical insurance
Pension fund
+4
Application Security Engineer
Application Security Engineer

Adecco • Warszawa

On-site
PLN 180,000 - 280,000
Employment contract
Hybrid work in Warsaw (2-3 days/week)
Information Security Engineer (AppSec)
Information Security Engineer (AppSec)

Revolut • Polska

On-site
PLN 180,000 - 240,000
Principal Application Security Software Engineer
Principal Application Security Software Engineer

Sabre Corporation • Poland

On-site
PLN 320,000 - 420,000
Hybrid work model
Office Kraków
No dress code
+1
Application Security Engineer
Application Security Engineer

Amadeus • Warszawa

Hybrid
PLN 180,000 - 240,000