Application Security Engineer

PepsiCo

Warszawa

On-site

PLN 120,000 - 180,000

Full time

7 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

PepsiCo is seeking an Application Security Engineer in Warsaw to partner with development teams to reduce risk across applications and APIs.

The role focuses on SAST/SCA/Secrets/DAST and API security tooling, with automation for scans, results processing, and CI/CD integration. Mobile security tooling support is optional but encouraged.

Qualifications

  • Foundational understanding of web, mobile, and API security concepts.
  • Experience with SAST/SCA, Secrets, and CI/CD integrations.
  • Experience with DAST and API scanning platforms and config.
  • Ability to triage findings, reproduce issues, and document remediation.
  • Familiarity with OWASP Top 10, API Security Top 10, and common vulnerabilities.
  • Reading code in Java, JavaScript, TypeScript, Python, Go, or C#.
  • Experience with centralized findings-management platforms and CI/CD workflows.
  • Basic scripting in Python, Go, PowerShell, or similar.
  • Cloud/containers like AWS, Azure, GCP, Docker, Kubernetes.

Responsibilities

  • Operate and support SAST/SCA/Secret/DAST and API security scanning tools.
  • Review, validate, triage findings, identify false positives, reproduce issues.
  • Perform targeted security reviews for web apps and API.
  • Configure and tune SAST/SCA, rules, policies, exclusions, and quality gates.
  • Configure DAST and API scan profiles, authentication workflows, and scopes.
  • Support integration of security tools into CI/CD and developer workflows.
  • Develop backend automation that initiates scans and processes results.
  • Document findings, remediation guidance, and operational procedures.

Skills

SAST/SCA/Secret
DAST
API security
Web/mobile/app security
CI/CD integration
Burp Suite
Postman
MobSF
Curl
Python/Go/PowerShell

Education

Bachelor’s degree in Computer Science/Engineering

Tools

Burp Suite
Postman
MobSF
Curl
GitHub
GitLab
Azure DevOps
Jenkins

Job description

Overview

PepsiCo’s Global Application Security Program partners with development teams to identify and reduce security risk across enterprise applications and APIs.

Approximately 80% of this role focuses on SAST/SCA/Secrets/DAST and API security scanning technology. The engineer will support the operation and tuning of tools, manually triage security findings, perform targeted reviews using established procedures, assist developers with remediation, and manage findings through centralized vulnerability-management workflows.

The engineer will also help develop and maintain backend automation that initiates scans, monitors scan status, processes results, handles common failures, and integrates security tools into CI/CD and developer workflows.

The remaining capacity will support mobile application-security tooling and integrations as needed. Working knowledge of mobile security reviews is preferred but not required. This may include assisting with specific mobile-application security tooling scanning automation and CI/CD integrations under the guidance of senior engineers.

Responsibilities
  • Operate and support SAST/SCA/Secret/DAST and API security scanning tools.
  • Review, validate, and manually triage security findings, identify false positives, reproduce common issues, assess potential impact, and escalation complex findings when appropriate.
  • Perform targeted web application and API security reviews using established tools, standards, procedures, and test cases.
  • Assist with configuring and tuning SAST/SCA and Secret rules, policies, exclusions, severity mappings, and quality gates.
  • Assist with configuring DAST and API scan profiles, authentication workflows, crawl settings, scan scopes, schedules, and policies.
  • Support the integration of security tools into source-control, pull-request, build, CI/CD, ticketing, and developer workflows.
  • Contribute to backend scanning automation that initiates scans, monitors scan state, handles retries, retrieves results, and routes findings to downstream systems.
  • Process findings through centralized application-security or vulnerability-management platforms, including normalization, deduplication, ownership assignment, remediation tracking, suppression, and exception workflows.
  • Provide developers with clear remediation guidance and support validation and tracking of vulnerabilities through closure.
  • Monitor scan execution and integration health, troubleshoot common authentication, connectivity, configuration, timeout, and result-processing issues, and escalation platform problems as needed.
  • As needed, support mobile security finding triage and tooling, including assisting with backend automation and CI/CD integrations for mobile security scans.
  • Document findings, remediation guidance, scan configurations, integration procedures, troubleshooting steps, metrics, and operational activities while participating in Agile ceremonies and team support processes.
  • Support team incident rotation through on-call hours, including weekends and holidays as needed.
Qualifications

Years of Experience

  • Bachelor’s degree in Computer Science, Engineering, or a related technical field, with 1-3 years of relevant professional experience in application security, security engineering, secure software development, or vulnerability management.

Mandatory Technical Skills

  • Foundational understanding of web application, mobile application, and API security concepts.
  • Experience with or exposure to SAST/SCA and Secret, including rules, policies, findings, exclusions, and CI/CD integrations.
  • Experience with or exposure to DAST and API scanning platforms, including scan configuration, scope management, authenticated scanning, and finding review.
  • Experience manually reviewing and triaging SAST/SCA/Secret, DAST, Mobile, and API-security findings.
  • Ability to reproduce common findings, recognize likely false positives, gather supporting evidence, and document remediation recommendations.
  • Familiarity with web, mobile and API testing tools such as Burp Suite, Postman, MobSF, curl, browser developer tools, or comparable technologies.
  • Familiarity with the OWASP Top 10 and common web vulnerabilities, including injection, cross-site scripting, broken access control, authentication weaknesses, SSRF, security misconfiguration, and sensitive-data exposure.
  • Familiarity with the OWASP API Security Top 10, including BOLA/IDOR, broken authentication, authorization failures, resource-consumption issues, mass assignment, and API inventory weaknesses.
  • Basic understanding of API authentication and authorization, including OAuth 2.0, OpenID Connect, JWT, API keys, service accounts, and role-based access control.
  • Ability to read and understand application code written in at least one language such as Java, JavaScript, TypeScript, Python, Go, or C#.
  • Experience working with centralized findings-management, ASPM, or vulnerability-management platforms.
  • Familiarity with finding ingestion, normalization, deduplication, ownership assignment, remediation status, suppressions, exceptions, and SLA tracking.
  • Exposure to GitHub, GitLab, Azure DevOps, Jenkins, or comparable source-control and CI/CD workflows.
  • Basic scripting experience with Python, Go, PowerShell, or a comparable language.
  • Familiarity with REST APIs, webhooks, JSON, command-line tools, and basic integration concepts.
  • Familiarity with backend automation concepts such as scheduled jobs, workers, queues, polling, retries, timeouts, and result processing.
  • Basic understanding of SAST, DAST, SCA, secrets detection, API security, Mobile security, SBOM, and related software supply-chain controls.
  • Familiarity with cloud or container technologies such as AWS, Azure, GCP, Docker, or Kubernetes.
  • Understanding of secure credential handling, service accounts, access controls, encryption, certificates, and audit logging.
  • Ability to create clear technical documentation, findings summaries, remediation guidance, troubleshooting notes, and operational procedures.

Non-technical Skills

  • Strong written and verbal communication skills.
  • High integrity with sound judgment and accountability.
  • Excellent analytical, problem-solving, and critical thinking abilities.
  • Self-motivated, curious, and committed to continuous learning, including willingness to skill up in mobile application security.
  • Strong collaboration, relationship-building, and influencing skills.
  • Comfortable working in a fast-paced, global environment with changing priorities and ambiguity.
  • Ability to perform effectively under pressure.

Differentiating Behaviors

  • Demonstrates curiosity, innovation, and a continuous improvement mindset, including a willingness to develop mobile application security expertise.
  • Makes sound decisions by balancing technical, business, and operational trade-offs.
  • Remains calm, organized, and methodical in high-pressure situations.
  • Effectively prioritizes work and manages competing commitments.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer
Senior Application Security Engineer

PepsiCo • Warszawa

On-site
PLN 162,000 - 198,000
Application Security Engineer
Application Security Engineer

Papaya Global • Kraków

On-site
PLN 300,000 - 420,000
Application Security Engineer ID71662
Application Security Engineer ID71662

AgileEngine, LLC. • Wrocław

Hybrid
PLN 120,000 - 180,000
Professional growth
Competitive USD-based compensation
Exciting projects
+1
Application Security Engineer ID71662
Application Security Engineer ID71662

AgileEngine, LLC. • Kraków

Hybrid
PLN 297,000 - 445,000
Professional growth
Competitive compensation
Exciting projects
+1
Application Security Engineer ID71662
Application Security Engineer ID71662

AgileEngine, LLC. • Poznań

Hybrid
PLN 180,000 - 240,000
Professional growth
Competitive compensation USD-based pay
Exciting projects
+1
Application Security Engineer ID71662
Application Security Engineer ID71662

AgileEngine, LLC. • Lublin

Hybrid
PLN 334,000 - 483,000
Professional growth
Competitive compensation
Exciting projects
+1
Application Security Engineer ID71662
Application Security Engineer ID71662

AgileEngine, LLC. • Województwo pomorskie

Hybrid
PLN 180,000 - 240,000
Professional growth
Competitive compensation (USD-based)
Exciting projects
+1
Application Security Engineer ID71662
Application Security Engineer ID71662

AgileEngine, LLC. • Województwo zachodniopomorskie

Hybrid
PLN 445,000 - 594,000
Professional growth
Competitive compensation
Exciting projects
+1
Application Security Engineer ID71662
Application Security Engineer ID71662

AgileEngine • Szczecin

Hybrid
PLN 335,000 - 447,000
Professional growth
Competitive compensation
Exciting projects
+1
Application Security Engineer ID71662
Application Security Engineer ID71662

AgileEngine • Wrocław

Hybrid
PLN 317,000 - 447,000
Professional growth
Competitive compensation
Exciting projects
+1