Application Security Engineer (F/M)

AXA IT Solutions

Warszawa

Hybrid

PLN 180,000 - 240,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

The opportunity to influence product方向
Ambitious projects with high autonomy
Hybrid work model

Job summary

AXA IT Solutions is seeking an Application Security Engineer to embed security across the software development lifecycle. You will partner with engineers, DevOps and security teams to automate controls, improve secure-by-design practices, and strengthen CI/CD security for modern web apps and APIs.

In this role you’ll drive security posture, triage findings, and design scalable protections while aligning with OWASP/NIST standards.

Qualifications

  • Deep knowledge of OWASP Top 10 and common web attack vectors.
  • Experience securing modern web apps, REST APIs, and auth mechanisms.
  • Experience implementing SAST, DAST, SCA and pen-testing programs.
  • Ability to automate security controls in CI/CD pipelines.
  • Strong secure-by-design practices and software engineering know-how.
  • Ability to drive strategic security improvements over remediation-only tasks.
  • Excellent stakeholder management and communication skills.
  • Motivated, collaborative, and able to work independently.
  • Analytical thinker with attention to detail and business focus.
  • Influence technical decisions in fast-paced environments.

Responsibilities

  • Own and improve application security posture across SDLC.
  • Monitor, assess, prioritise, and manage vulnerabilities from testing and scanning.
  • Triages findings with justified remediation and risk assessment.
  • Design and implement scalable security controls and automation.
  • Shift-left security by integrating automated testing into CI/CD.
  • Identify recurring patterns and implement preventative guardrails.
  • Liaise with external pen-test providers and ensure timely remediation.
  • Collaborate with Group Security to align risk ratings and actions.
  • Provide guidance on securing web apps, APIs, and cloud-native architectures.
  • Promote secure design principles across delivery teams.
  • Maintain OWASP/NIST-aligned security standards and processes.
  • Monitor threats and share data-driven insights with governance groups.
  • Deliver secure coding guidance to developers and architects.
  • Report posture, trends, and risk reduction to leadership forums.

Skills

OWASP Top 10
Web security
CI/CD security
Vulnerability management
SAST/DAST
OAuth2/JWT

Job description

We are an internal software house operating within the international insurance group AXA. We provide IT solutions for the needs of AXA companies in Europe. We work in English on a daily basis, in close-knit teams, carrying out international development projects.

About the project:

We are looking for an Application Security Engineer (F/M) to join our engineering team and help us build security into the software development lifecycle.

This role is an opportunity to move beyond traditional vulnerability management and drive a proactive approach to application security. You will work closely with software engineers, architects, DevOps and security teams to automate security controls, integrate security into CI/CD pipelines, improve secure development practices and help teams build secure-by-design applications.

Your responsibilities:
  • Own and continuously improve the application security posture of internally developed solutions, ensuring security is embedded throughout the software development lifecycle (SDLC).
  • Monitor, assess, prioritise, and manage application security vulnerabilities identified through penetration testing, SAST, DAST, dependency scanning, bug bounty programmes, and other security assessment activities, ensuring remediation within agreed SLAs.
  • Triage security findings to determine business risk, remediation requirements, and false positives, providing clear technical justification for all decisions.
  • Design, recommend and implement long-term, scalable security controls and automation to reduce recurring vulnerabilities, minimise manual intervention, and improve remediation efficiency across development teams.
  • Drive a shift-left security approach by integrating automated security testing, policy enforcement, and secure development practices into CI/CD pipelines and engineering workflows.
  • Identify recurring vulnerability patterns and implement preventative controls, secure frameworks, coding standards, and developer guardrails that eliminate classes of vulnerabilities at source.
  • Serve as the primary liaison with external penetration testing providers, ensuring security assessments are completed in a timely manner and findings are actionable, risk-based, and aligned with business priorities.
  • Partner with Group Security teams to maintain a single source of truth for vulnerabilities, consult, agree risk ratings, and resolve disputes relating to remediation requirements or false-positive findings.
  • Provide expert guidance on securing modern web applications, APIs, authentication mechanisms, and cloud-native architectures, with particular focus on .NET and Angular solutions.
  • Act as the Application Security subject matter expert for the Solution Delivery organisation, promoting secure design principles and security-by-default practices across all stages of solution delivery.
  • Maintain and enhance secure development standards, application security policies, and security engineering processes in line with OWASP, NIST, and industry best practices.
  • Proactively monitor emerging threats, OWASP Top 10 trends, attack techniques, and security tooling innovations, ensuring the organisation remains ahead of evolving application security risks.
  • Deliver security awareness and secure coding guidance to developers, technical leads, architects, and delivery teams to improve organisational security maturity.
  • Update on application security posture, vulnerability trends, remediation performance, and risk reduction initiatives to governance forums and steering groups, providing data-driven insights and recommendations.
Our requirements:
  • Strong practical knowledge of the OWASP Top 10 and common web application attack vectors.
  • Deep understanding of securing modern web applications, REST APIs, authentication and authorisation mechanisms (OAuth2, OIDC, JWT).
  • Experience implementing and managing SAST, DAST, SCA, API security and penetration testing programmes.
  • Experience automating security controls within CI/CD pipelines and software delivery processes.
  • Strong knowledge of secure software engineering practices and secure-by-design principles.
  • Ability to identify strategic security improvements rather than focusing solely on vulnerability remediation.
  • Strong stakeholder management skills, with the ability to influence development teams, architects, and security functions.
  • Highly motivated, enthusiastic, and capable of working both independently and collaboratively in a team-oriented environment.
  • Exceptional analytical and problem-solving skills, with attention to detail and a business-focused approach.
  • Strong interpersonal skills, with the ability to influence technical decisions and communicate effectively in a fast-paced environment.
  • Demonstrates creativity and resourcefulness in presenting solutions to complex security challenges.
What we offer
  • The opportunity to influence technological solutions and product direction in an international financial organization
  • Ambitious projects with a high degree of autonomy and responsibility
  • A stable, long-term assignment with flexible working hours and a hybrid work model
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

AXA IT Solutions • Poland

Hybrid
PLN 180,000 - 240,000
Personal development
International environment
English work environment
+9
Application Security Engineer
Application Security Engineer

SOFTSWISS • Warszawa

Hybrid
PLN 60,000 - 90,000
Full-time remote work opportunities
Private insurance
Additional 1 Day Off per calendar year
+5
Application Security Engineer
Application Security Engineer

SOFTSWISS • Poland

On-site
PLN 218,579 - 327,869
Full-time remote work opportunities
Private insurance
Sports program compensation
+2
Application Security Engineer
Application Security Engineer

Adecco • Warszawa

Hybrid
PLN 180,000 - 280,000
Employment contract
Hybrid work in Warsaw (2-3 days/week)
Senior Application Security Engineer
Senior Application Security Engineer

Adecco • Warszawa

Hybrid
PLN 210,000 - 270,000
Private medical care
Life insurance
Hybrid work model
Application Security Engineer
Application Security Engineer

emagine Polska • Warszawa

Hybrid
PLN 303,000 - 477,000
Application Security Engineer: Secure-by-Design, CI/CD Focus
Application Security Engineer: Secure-by-Design, CI/CD Focus

AXA IT Solutions • Warszawa

Hybrid
PLN 180,000 - 240,000
The opportunity to influence product方向
Ambitious projects with high autonomy
Hybrid work model
Application Security Engineer ID71662
Application Security Engineer ID71662

AgileEngine • Szczecin

Hybrid
PLN 335,000 - 447,000
Professional growth
Competitive compensation
Exciting projects
+1
Application Security Engineer ID71662
Application Security Engineer ID71662

AgileEngine • Kraków

On-site
PLN 180,000 - 240,000
Professional growth
Competitive compensation (USD-based)
Exciting projects
+1
Application Security Engineer ID71662
Application Security Engineer ID71662

AgileEngine • Poznań

On-site
PLN 261,000 - 410,000
Professional growth
Competitive USD-based pay
Exciting projects
+1