Application Security Engineer (relocation to Barcelona)

Commit

Warszawa

On-site

PLN 60,000 - 90,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Commit in Warsaw is on the lookout for a talented security researcher specializing in offensive security. In this hands-on role, you will work with a team of experts conducting penetration testing, developing innovative security tools, and addressing vulnerabilities in products. You will be integral to shaping the security posture of the company.

The position requires strong technical skills across multiple domains, including web and cloud technologies. Ideal candidates will have 4+ years of experience in security testing and be familiar with modern architectures.

Qualifications

  • 4+ years of experience in research and penetration testing.
  • Deep technical understanding of web, API, cloud-native, and backend technologies.
  • Ability to report technical findings effectively.

Responsibilities

  • Help to reshape JFrog Product Security.
  • Plan and execute advanced penetration testing campaigns.
  • Develop tools and frameworks for scalable security testing.

Skills

Research and penetration testing
Strong coding skills
Experience with penetration testing tools
Knowledge of AI and LLM penetration testing
Understanding of secure software architecture
Experience with CI/CD pipelines

Tools

Burp Suite
Metasploit

Job description

We’re running the software that runs the world – and we want you along for the ride. The company is a special place with a unique combination of brilliance, spirit, and great people. Here, if you’re willing to do more, your career can take off. And since software plays a central role in everyone’s lives, you’ll be part of a critical mission.

In this role, you will work with a team of researchers and ethical hackers focused on offensive security testing, automated exploit discovery, and advanced application security research. Your work will directly influence the security posture of the company's products and help scale secure-by-design principles.

This is a hands‑on technical role with a strong emphasis on offensive security, code exploitation, automation, and innovation.

Responsibilities
  • Help to reshape JFrog Product Security
  • Plan and execute advanced penetration testing campaigns.
  • Develop tools and frameworks for scalable security testing and fuzzing.
  • Lead Security innovation by building and managing penetration testing tools \ AI Agents
  • Analyze vulnerabilities, perform root cause analysis, and develop proofs of concept.
  • Identify systemic product weaknesses and help define long‑term mitigations.
  • Collaborate with engineering teams to reproduce, triage, and fix vulnerabilities.
  • Contribute to security research publications, CVE submissions, and industry knowledge sharing.
  • Continuously evolve internal testing capabilities using modern tooling and AI‑assisted approaches.
Requirements
  • 4+ year experience in Research and penetration testing.
  • Strong coding skills and deep technical understanding of web, API, cloud‑native, and backend technologies.
  • AI and LLM penetration testing knowledge and experience.
  • Experience with penetration testing tools (Burp Suite, Metasploit, etc.) and custom security tools development.
  • Familiarity with modern architectures (e.g., Cloud, microservices, containers, Kubernetes).
  • Familiarity with secure software architecture and typical attack vectors.
  • Demonstrated ability to do security testing engagements and report technical findings effectively.
  • Experience building or integrating automated PT or fuzzing pipelines is a strong advantage.
  • Knowledge and hands‑on experience with SSDLC tools and CI/CD pipelines.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Offensive Security Engineer: AI App Security & Fuzzing
Offensive Security Engineer: AI App Security & Fuzzing

Commit • Warszawa

On-site
PLN 60,000 - 90,000
Senior Application Security Engineer (Java)
Senior Application Security Engineer (Java)

SoftServe • Polska

On-site
PLN 180,000 - 240,000
Application Security Engineer
Application Security Engineer

Softswiss • Warszawa

On-site
PLN 60,000 - 90,000
Full-time remote work opportunities
Private insurance
Additional 1 Day Off per calendar year
+5
Application Security Engineer
Application Security Engineer

Adecco • Warszawa

On-site
PLN 180,000 - 280,000
Employment contract
Hybrid work in Warsaw (2-3 days/week)
Senior Pentester (Security Engineer)
Senior Pentester (Security Engineer)

DEVTALENTS Sp. z o.o. • Województwo mazowieckie

On-site
PLN 80,000 - 100,000
Influence over security architecture
Supportive culture for professional growth
Application Security Engineer
Application Security Engineer

emagine Polska • Warszawa

On-site
PLN 303,000 - 477,000
Application Security Engineer
Application Security Engineer

SOFTSWISS • Poland

On-site
PLN 218,579 - 327,869
Full-time remote work opportunities
Private insurance
Sports program compensation
+2
Application Security Engineer
Application Security Engineer

Papaya Global • Kraków

On-site
PLN 300,000 - 420,000
Penetration Tester Team Lead
Penetration Tester Team Lead

Terra Security • Poland

On-site
PLN 297,999 - 383,141
Penetration Tester
Penetration Tester

Atos • Bydgoszcz

On-site
PLN 120,000 - 170,000
Hybrid work model
Private medical care
Benefits platform
+4