Application Security Engineer | Mid-Senior | Low-level

Nord Security

Poland

On-site

PLN 180,000 - 260,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Training & mentorship
Extra vacation days
Private healthcare in Lithuania and, (
Mindfulness trainings
In-house gyms and sport cards
Workation opportunities
Work from anywhere

Job summary

Nord Security is seeking a security engineer to conduct security reviews of mobile and desktop apps, perform vulnerability assessments, and collaborate with development teams to design secure architectures. You will maintain security tooling, stay current on threats, and help deliver security trainings.

The role emphasizes hands-on testing, tooling, and cross-team collaboration. You will also help identify internal security gaps and ensure tests align with audits, while applying best practices

Qualifications

  • Proven experience in mobile/desktop application security assessment planning, testing, methodologies, and vulnerability reporting.
  • Strong understanding of secure coding practices.
  • Ability to perform manual security code audit.
  • Proficiency in at least one low-level programming language (e.g. C, C++, Rust, Go).
  • Solid understanding of networking protocols such as TCP, UDP and the HTTP protocol.
  • Familiarity with debuggers (e.g. GDB, LLDB, WinDbg).
  • Familiarity with reverse engineering tools (e.g. Ghidra, IDA).
  • Solid understanding of memory corruption issues, buffer overflows and related vulnerability classes.
  • Familiarity with common authentication and authorization protocols (OAuth, SAML, JWT, etc.).
  • Ability to work with networking tools such as Wireshark, tcpdump.

Responsibilities

  • Conduct security reviews of application designs, source code, and third-party libraries.
  • Perform regular application vulnerability assessments using both automated tools and manual testing techniques (e.g., SAST, DAST, SCA, penetration testing).
  • Collaborate with development teams to design secure architectures and implement security controls.
  • Help maintain security tools, scripts, and processes to support secure development.
  • Stay current with industry trends, zero-day vulnerabilities, and best practices in application security.
  • Develop scripts, security automation tools to enhance application security testing processes.
  • Design and deliver training for security engineering awareness & adoption.
  • Actively look for internal security gaps within the product or organization overall.
  • Ensure mobile/desktop applications are sufficiently tested and support internal and external audits.

Skills

App security testing
Secure coding
Manual security audit
Low-level languages (C/C++/Rust/Go)
Networking protocols TCP/UDP/HTTP
Debuggers (GDB/LLDB/WinDbg)
Reverse engineering tools (Ghidra/IDA)
OAuth/SAML/JWT
Wireshark/tcpdump
Problem solving & ownership

Tools

Ghidra
IDA
Wireshark
tcpdump
GDB
LLDB
WinDbg

Job description

At Nord Security, we’re creating a safer cyber future.

We help people and businesses take back control of their online security, privacy, and data. From VPNs to password managers, threat intelligence to eSIMs for travel—our teams turn complex problems into solutions trusted by millions worldwide.

Life is online. In this role, you’ll help people own it.

Main Responsibilities
  • Conduct security reviews of application designs, source code, and third-party libraries;

  • Perform regular application vulnerability assessments using both automated tools and manual testing techniques (e.g., SAST, DAST, SCA, penetration testing);

  • Collaborate with development teams to design secure architectures and implement security controls;

  • Help maintain security tools, scripts, and processes to support secure development;

  • Stay current with industry trends, zero-day vulnerabilities, and best practices in application security;

  • Develop scripts, security automation tools to enhance application security testing processes;

  • Design and deliver training for security engineering awareness & adoption;

  • Actively look for internal security gaps within the product or organization overall.

  • Ensure mobile/desktop applications are sufficiently tested and support internal and external audits;

Core Requirements
    • Proven experience in mobile/desktop application security assessment planning, testing, methodologies, and vulnerability reporting;
    • Strong understanding of secure coding practices;
    • Ability to perform manual security code audit;
    • Proficiency in at least one low-level programming language (e.g. C, C++, Rust, Go).
    • Solid understanding of networking protocols such as TCP, UDP and the HTTP protocol.
    • Familiarity with debuggers (e.g. GDB, LLDB, WinDbg).
    • Familiarity with reverse engineering tools (e.g. Ghidra, IDA).
    • Solid understanding of memory corruption issues, buffer overflows and related vulnerability classes.
    • Familiarity with common authentication and authorization protocols (OAuth, SAML, JWT, etc.).
    • Ability to work with networking tools such as Wireshark, tcpdump.
    • Ability to quickly assimilate new technologies and tools;
    • Sense of ownership with strong problem solving and investigation skills;
    • Ability to build and maintain relationships, influence key stakeholders across the business;
    • Bonus points for community contributions like public CVEs, bug bounty recognition, open-source tools, blogs, etc.
What We Offer
  • Sharpen your edge: training, mentorship, and room to grow — always.

  • Take the time you need: extra vacation days, sick days, and time off when life calls.

  • Get premium healthcare: private health insurance in Lithuania and Poland — fully covered.

  • Protect your peace: enjoy free subscriptions to Calm, Headspace, and Mindletic, and our own resilience and mindfulness trainings.

  • Own your fitness: in-house gyms, sport cards, online workouts, and personal guidance — on us.

  • Pack your bags for workation: experience our company-wide trip abroad to the fullest.

  • Work from anywhere: work from wherever keeps you in the zone.

  • Celebrate your milestones: birthdays, weddings, and new family members — all deserve a gift.

  • Parent with ease: children’s summer camps and flexibility around the schedule — because parenting never pauses.

  • Join the party: team building and company events people talk about for months.

  • Unlock Cyber City: coffee bar, open gyms, kids’ room, music room, massage chairs — our Vilnius HQ is yours to enjoy.

Kindly refer to our Privacy Notice for Recruitment Candidates for comprehensive information regarding our data handling procedures throughout recruitment processes.

We expect all candidates to provide accurate and complete information during the recruitment process. While limited use of AI tools to refine application materials is acceptable, candidates remain fully responsible for ensuring that their submissions reflect their own qualifications, skills, and experience. Any failure to do so may negatively affect participation in the recruitment process. If broader AI assistance is allowed for a particular role or stage, we’ll let you know in advance.

By submitting your application, you acknowledge that it may be processed using automated tools for evaluation purposes. As part of our recruitment process, we may use an AI-based application review tool to help assess applications based on skills and experience relevant to the role. This technology is used to support - not replace - human decision-making, and every application is ultimately reviewed by a recruiter.

If you would like more information about how AI is used in this process or wish to exercise your rights under applicable data privacy laws, please contact us at privacy@nordaccount.com. Should you prefer to opt out of the automated evaluation, please submit your application directly to career@nordsec.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer | Mid - Senior | WebSec Team
Security Engineer | Mid - Senior | WebSec Team

Nord Security • Poland

On-site
Private health insurance
Online workouts with experts
Flexible work from anywhere
+2
Low-level engineer | Mid-Senior | NordVPN
Low-level engineer | Mid-Senior | NordVPN

Nord Security • Poland

Hybrid
PLN 180,000 - 260,000
Hybrid work: 3 office days, 2 remote
Private health insurance
Multisport card
+2
Engineering Manager | NordLayer
Engineering Manager | NordLayer

Nord Security • Warszawa

On-site
USD 120,000 - 160,000
Premium healthcare
Work from anywhere
Mentorship programs
+2
Influencer Marketing Manager | Mid-Senior
Influencer Marketing Manager | Mid-Senior

Nord Security • Kraków

Hybrid
PLN 120,000 - 180,000
Hybrid work
Premium healthcare
Mentorship and growth programs
+1
Influencer Marketing Manager | Mid-Senior
Influencer Marketing Manager | Mid-Senior

Nord Security • Warszawa

On-site
PLN 80,000 - 120,000
Hybrid work arrangement
Multisport card
Premium healthcare
+3
Low-level Engineer | Mid-Senior | C++| Threat Protection Team
Low-level Engineer | Mid-Senior | C++| Threat Protection Team

Nord Security • Poland

Hybrid
PLN 120,000 - 240,000
Hybrid work
Private healthcare
Mentorship
+2
Windows Engineer | Senior | NordLocker
Windows Engineer | Senior | NordLocker

Nord Security • Warszawa

On-site
PLN 170,000 - 250,000
Private healthcare
Work from anywhere
Team events
+1
Senior Site Reliability Engineer — Observability Engineer | NordVPN
Senior Site Reliability Engineer — Observability Engineer | NordVPN

Nord Security • Poland

Hybrid
PLN 200,000 - 320,000
Hybrid work 3 days in the office
Private healthcare
Gym access
+2
Paid Search Specialist | Mid-Senior | NordVPN
Paid Search Specialist | Mid-Senior | NordVPN

Nord Security • Kraków, Warszawa

Hybrid
PLN 180,000 - 240,000
Hybrid work 3/2 schedule
Private healthcare
Team events
Senior Site Reliability Engineer - Traffic Engineering | NordVPN
Senior Site Reliability Engineer - Traffic Engineering | NordVPN

Nord Security • Poland

Hybrid
PLN 180,000 - 280,000
Hybrid work
Private healthcare
Mental health support
+1