Application Security Engineer – Penetration Tester

Jobtailor

Warszawa

On-site

PLN 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking an Application Security professional to triage and analyze findings from SAST/SCA and secret scans, conduct manual and tool-assisted code reviews, and perform hands-on penetration testing of web apps, microservices, and APIs.

You will audit REST and GraphQL APIs, focusing on authentication, authorization, and business logic, applying OWASP Top 10 and API Security Top 10 principles. Collaboration with engineering and DevOps is essential.

Qualifications

  • 2–4 years of experience in Application Security, Product Security, or Penetration Testing.
  • Hands‑on experience triaging and analyzing findings from Semgrep / OpenGrep, Gitleaks, Trivy, and OSV-Scanner.
  • Experience with Burp Suite (Pro), Nuclei, Subfinder, SQLmap, Metasploit, and NetzScum?
  • Deep understanding of OWASP Top 10 vulnerabilities, including SQLi, XSS, CSRF, broken access control, and security misconfigurations.
  • Solid knowledge of OWASP API Security Top 10 for REST and GraphQL architectures.

Responsibilities

  • Triage, validate, and prioritize security findings from SAST, SCA, and secret scanning tools; filter false positives, assess risks, and track issues through remediation.
  • Conduct manual and tool-assisted code reviews to identify vulnerabilities before production.
  • Perform hands-on penetration testing of web applications, microservices, and APIs.
  • Audit REST and GraphQL APIs and web applications focusing on authentication, authorization, and business logic.

Skills

Security findings triage
Code review
Vulnerability assessment
Risk analysis
Penetration testing
API security
OAuth 2.0
JWT
RBAC/ABAC

Tools

Burp Suite (Pro)
Nuclei
SQLmap
Metasploit
Trivy
Gitleaks
OSV-Scanner
Kubernetes Security
AWS Cloud Security

Job description

  • Triage, validate, and prioritize security findings from SAST, SCA, and secret scanning tools; filter false positives, assess risks, and track issues through remediation
  • Conduct manual and tool-assisted code reviews to identify security vulnerabilities, logic flaws, and insecure implementation choices before production
  • Perform hands‑on penetration testing of web applications, microservices, and APIs
  • Audit REST and GraphQL APIs and web applications, focusing on application security risks, authentication, authorization, and business logic
Requirements
  • 2–4 years of experience in Application Security, Product Security, or Penetration Testing
  • Hands‑on experience triaging and analyzing findings from Semgrep / OpenGrep, Gitleaks, Trivy, and OSV-Scanner
  • Experience with Burp Suite (Pro), Nuclei, Subfinder, SQLmap, Metasploit, and NetExec
  • Deep understanding of OWASP Top 10 vulnerabilities, including SQL injection, command injection, SSRF, XSS, CSRF, broken access control, IDOR/BOLA, security misconfigurations, cryptographic failures, insecure deserialization, and mass assignment
  • Solid knowledge of OWASP API Security Top 10 for REST and GraphQL architectures
  • Deep understanding of OAuth 2.0, OIDC, JWT, SAML, RBAC/ABAC, and access control mechanics
  • Ability to identify authorization bypasses, session management flaws, and business logic bugs
  • Intermediate level of spoken and written English
  • Ability to read and analyze modern application code to spot security flaws (a plus)
  • Understanding of AWS cloud security principles and Kubernetes security fundamentals (a plus)
  • Strong communication skills for collaboration with engineering, product, and DevOps teams
  • Result‑oriented mindset
  • Openness to learning
Core Competencies

Demonstrates expertise in Application Security and Penetration Testing, with a strong focus on identifying and remediating vulnerabilities in web applications and APIs. Proficient in using security tools and frameworks to assess risks and ensure compliance with security standards.

Highest-signal resume keywords
  • Application Security
  • Penetration Testing
  • OWASP Top 10 Vulnerabilities
  • Burp Suite (Pro)
  • Semgrep / OpenGrep
ATS Optimization Keywords
Hard Skills
  • Security Findings Triage
  • Code Review
  • Vulnerability Assessment
  • Risk Analysis
  • Penetration Testing
  • API Security
  • OAuth 2.0
  • JWT
  • SQL Injection
  • Business Logic Bugs
Soft Skills
  • Strong Communication Skills
  • Result-Oriented Mindset
  • Openness to Learning
Industry Keywords
  • Application Security
  • Product Security
  • SAST
  • SCA
  • REST APIs
  • GraphQL APIs
  • Access Control
  • Authentication
  • Authorization
Tools & Technologies
  • Burp Suite (Pro)
  • Nuclei
  • SQLmap
  • Metasploit
  • Trivy
  • Gitleaks
  • OSV-Scanner
  • Kubernetes Security
  • AWS Cloud Security
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Applied Security Engineer – Web Apps & APIs
Applied Security Engineer – Web Apps & APIs

Jobtailor • Warszawa

On-site
PLN 120,000 - 180,000
Security Penetration Tester
Security Penetration Tester

DataLock Consulting Group • Poland

Remote
PLN 252,000 - 380,000
Application Security Engineer - Senior
Application Security Engineer - Senior

SOFTSWISS • Warszawa

On-site
PLN 210,000 - 270,000
Private health insurance
Sports benefits
Mental Health Program
+6
Senior Analyst – Attack Surface Management
Senior Analyst – Attack Surface Management

Jobtailor • Kraków

On-site
PLN 180,000 - 250,000
Software Engineer
Software Engineer

Jobtailor • Wrocław

On-site
PLN 120,000 - 190,000
Senior Pentester (Security Engineer)
Senior Pentester (Security Engineer)

DEVTALENTS Sp. z o.o. • Województwo mazowieckie

On-site
PLN 80,000 - 100,000
Influence over security architecture
Supportive culture for professional growth
Offensive Security Engineer, Penetration Testing
Offensive Security Engineer, Penetration Testing

Procter & Gamble • Poland

On-site
PLN 180,000 - 260,000
Senior Penetration Testing Engineer IRC301690
Senior Penetration Testing Engineer IRC301690

GlobalLogic • Kraków

On-site
PLN 180,000 - 280,000
Empowering Projects
Empowering Growth
DE&I Matters
+3
Penetration Tester
Penetration Tester

Atos • Bydgoszcz

Hybrid
PLN 120,000 - 170,000
Hybrid work model
Private medical care
Benefits platform
+4
Software Tester
Software Tester

Jobtailor • Warszawa

On-site
PLN 90,000 - 140,000