application security engineer in financial services

HireHi

Warszawa

Hybrid

PLN 250,000 - 450,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Annual bonus
Generous annual leave policy
Medical insurance and pension fund
Hybrid working model (3 days in office
Remote work days policy 30 additional
Volunteer leave

Job summary

HireHi ищет опытного специалиста по безопасности продуктов для ведения архитектурных обзоров, threat modelling и внедрения автоматизированных процессов безопасности в SDLC. Вы будете интегрировать проверки безопасности в конвейеры CI/CD и развивать инструменты.

Кандидат имеет 5+ лет опыта, знаком с OWASP Top Ten, SAST/DAST/SCA, и владеет Python/Go/JS. Гибридный режим работы в Варшаве, бонусы и возможности обучения.

Qualifications

  • 5+ лет в области безопасности приложений/продукта с явным влиянием на старшие уровни
  • Опыт руководства обзорами архитектуры безопасности и threat modelling
  • Умение автоматизировать процессы безопасности через инструменты, интеграции и self-service
  • Сильные навыки hands-on security testing: обзор кода, тестирование веб/мобильных/API
  • Умение треагировать внешние отчеты об уязвимостях и баг-бауни
  • Сильная разработка на Python/Go/JS
  • Понимание OWASP Top Ten и практик безопасной разработки
  • Опыт работы с SAST/DAST/SCA, системами управления уязвимостями и CI/CD
  • Понимание REST API, микросервисов, облачных систем и контейнеров
  • Опыт применения AI/Llm инструментов в работе безопасности, или способность к ним
  • Отличные коммуникативные навыки и способность влиять без прямых полномочий
  • Самоорганизованность, желание решать сложные задачи и обучать коллег

Responsibilities

  • Вести обзоры архитектуры безопасности и threat modelling для новых и существующих систем
  • Проектировать, развивать и автоматизировать масштабируемые процессы безопасности
  • Интегрировать проверки безопасности по SDLC и CI/CD (SAST, DAST, SCA, секреты, IaC)
  • Владеть и развивать инструменты безопасности (DefectDojo, SAST, DAST, SCA)
  • Применять AI/LLM-инструменты к обзору архитектуры, threat modelling, code review и triage уязвимостей
  • Проводить оценки безопасности веб/мобильных приложений, API и облачной инфраструктуры
  • Запускать сканирования уязвимостей и сопровождать процесс исправления
  • Поддерживать triage Bug Bounty, автоматизируя где возможно
  • Участвовать в red teaming и обучать инженеров

Skills

Архитектура безопасности
threat modelling
Automation
Hands-on security testing
Code review
REST APIs / микросервисы
AI/LLM tooling

Tools

SAST
DAST
SCA
DefectDojo
CI/CD интеграции

Job description

Описание:

Capital.com’s Product Security team protects web and mobile applications, infrastructure, and the external perimeter in a highly regulated environment. It designs and scales security processes that help engineering teams build securely by default.

Задачи:

Lead security architecture reviews and threat modelling for new and existing systems, using AI tools to make reviews faster, more consistent, and scalable across teams Influence standards, patterns, and guardrails that help teams move quickly while staying secure Design, build, and automate scalable, self-service security processes for secure design review, threat modelling, testing, and remediation workflows Integrate and automate security checks across SDLC and CI/CD pipelines, including SAST, DAST, SCA, secrets, and IaC scanning Own and evolve security tooling, including DefectDojo and SAST, DAST, and SCA platforms Apply AI and LLM-based tooling to architecture review, threat modelling, code review, and vulnerability triage, and help define its safe adoption Conduct and oversee security assessments of web and mobile applications, APIs, and cloud infrastructure, including manual testing and PoC development Run vulnerability scans across internal infrastructure and the external perimeter, analyse findings, define remediation, and track issues to closure Support and triage the Bug Bounty Program and external vulnerability reports, automating triage where possible Participate in and help lead red teaming and offensive security exercises Drive knowledge sharing on secure development, mentor engineers, and deliver training for development and QA teams

Требования:
  • 5+ Years in application or product security, or equivalent depth, with a track record of senior- or staff-level impact
  • Experience leading security architecture reviews and threat modelling across multiple teams or products
  • Ability to automate and scale security processes by building tooling, integrations, and self-service workflows
  • Strong hands‑on security testing skills, including code review and web, mobile, and API application security assessments
  • Ability to triage and validate external vulnerability reports and bug bounty submissions
  • Strong software engineering ability in at least one language, such as Python, Go, or JavaScript
  • Deep understanding of the OWASP Top Ten, secure design, and secure coding best practices
  • Experience with SAST, DAST, SCA, vulnerability management platforms, and CI/CD integrations
  • Strong understanding of REST APIs, microservices, cloud-based systems, and containers
  • Practical experience applying AI and LLM tooling to security work, or clear enthusiasm and aptitude to do so
  • Excellent communication and influencing skills; able to explain security concepts to technical and non-technical stakeholders and drive change without direct authority
  • Self‑starter who enjoys solving complex problems, building leverage through automation, mentoring others, and strengthening security culture
  • Будет плюсом: securing LLM and agent pipelines, prompts, tool and MCP integrations, and model endpoints; securing Kubernetes and AWS infrastructure; building AI‑assisted security tooling or internal self‑service security platforms; mentoring or technically leading a security team; OSAI, OSEP, OSCP, or OSWE certifications
Условия:
  • Annual bonus based on the performance review cycle
  • Generous annual leave policy
  • Medical insurance and pension fund, with additional benefit packages based on location
  • Hybrid working model with 3 days from the office and 2 days fully remotely
  • Comprehensive Workation Policy with 30 more remote days available
  • Possibility of taking two additional days of paid leave per year for volunteering
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

security engineer in fintech
security engineer in fintech

Enfint • Warszawa

On-site
PLN 180,000 - 320,000
Competitive salary
Annual leave
Employee referral program
+3
Senior Application Security Engineer
Senior Application Security Engineer

Lever, Inc. • Warszawa

On-site
PLN 260,000 - 380,000
Annual bonus
Medical Insurance
Hybrid work model
Senior Application Security Engineer
Senior Application Security Engineer

Capital • Warszawa

Hybrid
PLN 320,000 - 460,000
Hybrid work model
Medical insurance
Pension fund
+4
security engineer in fintech
security engineer in fintech

HireHi • Polska

On-site
PLN 180,000 - 260,000
Конкурентная зарплата
Гибкий график
Медицинское страхование
+5
IAM specialist in trading
IAM specialist in trading

HireHi • Polska

On-site
PLN 140,000 - 220,000
Annual leave
Employee referral program
Medical insurance and pension plans
+2
security engineer in sports technology
security engineer in sports technology

HireHi • Warszawa

On-site
PLN 260,000 - 380,000
Office in Warsaw
Career development
ai engineer in payment security
ai engineer in payment security

HireHi • Polska

On-site
PLN 180,000 - 240,000
Competitive salary
Flexible schedule
Medical insurance and sports
Application Security Architect
Application Security Architect

Capital • Warszawa

Hybrid
PLN 250,000 - 400,000
Annual bonus
Generous annual leave
Medical insurance
+4
security engineer AI and Automation
security engineer AI and Automation

Enfint • Warszawa

On-site
PLN 240,000 - 320,000
Application Security Engineer
Application Security Engineer

AXA IT Solutions • Poland

On-site
PLN 180,000 - 240,000
Personal development
International environment
English work environment
+9