Application Security Engineer: Secure DevOps & Threat Modeling

Starburst Data, Inc.

Warszawa

Hybrid

PLN 180,000 - 260,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Stock grants
Flexible paid time off
Competitive pay

Job summary

Starburst Data, Inc. is seeking a Security Engineer focused on Application and Product Security in a Warsaw-based hybrid role. You will partner with engineering to embed security into the SDLC, implement secure-by-default patterns, and guide remediation across services. Travel up to 25% for onboarding, offsites, and customer engagements.

You will lead secure coding practices, threat modeling, and secure design reviews while maintaining security tooling and standards across the product landscape.

Qualifications

  • 2–5 years of application security experience.
  • Knowledge of OWASP Top 10 and CWE.
  • Experience with CI/CD tooling and Git workflows.
  • Cloud security concepts and hands-on experience with AWS/Azure/GCP.
  • Experience with security tools such as OWASP ZAP, Burp Suite, SAST/DAST.

Responsibilities

  • Integrate security into the development lifecycle and CI/CD pipelines.
  • Maintain Application Security tooling (SAST, DAST, SCA, secrets scanning).
  • Conduct secure code reviews, threat modeling, and architecture assessments.
  • Develop security automation, guardrails, and reusable components.
  • Assist in defining secure coding standards and application hardening practices.
  • Support monitoring, telemetry, and alerting for applications.
  • Assist in incident response related to application vulnerabilities.
  • Stay current on emerging threats and practices in app security.
  • Contribute to security documentation and remediation playbooks.
  • Participate in internal security reviews and architectural walkthroughs.
  • Develop and maintain security tools, pipelines, and workflows.
  • Collaborate with engineering/product teams for secure deployments.

Skills

OWASP Top 10
CI/CD tooling
Cloud security
Security tooling (SAST/DAST/SCA)
Secure coding principles
Threat modeling
Communication with developers

Education

Bachelor’s degree in Computer Science or equivalent

Tools

OWASP ZAP
Burp Suite
SAST/DAST tools
SCA
Dependency scanning

Job description

Starburst Data, Inc. is seeking a Security Engineer focused on Application and Product Security in a Warsaw-based hybrid role. You will partner with engineering to embed security into the SDLC, implement secure-by-default patterns, and guide remediation across services. Travel up to 25% for onboarding, offsites, and customer engagements.

You will lead secure coding practices, threat modeling, and secure design reviews while maintaining security tooling and standards across the product landscape.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Starburst Data, Inc. • Warszawa

Hybrid
PLN 180,000 - 260,000
Stock grants
Flexible paid time off
Competitive pay
Senior Application Security Engineer: Threat Modeling & Pentests
Senior Application Security Engineer: Threat Modeling & Pentests

HeadHR • Warszawa

On-site
PLN 250,000 - 350,000
Private healthcare with rehabilitation
Extra parental days (6/yr)
Cafeteria
+1
Senior Application Security Analyst | Secure DevSecOps
Senior Application Security Analyst | Secure DevSecOps

Bunge • Warszawa

On-site
PLN 180,000 - 300,000
Application Security Engineer - Warsaw Hybrid
Application Security Engineer - Warsaw Hybrid

Asana • Warszawa

Hybrid
Health insurance
Meal allowances
Office-centric hybrid schedule
+1
Senior Application Security Engineer — CI/CD Security Leader
Senior Application Security Engineer — CI/CD Security Leader

Brightstar Lottery • Poland

On-site
PLN 145,000 - 224,000
Paid time off
Health insurance
Life insurance
+5
Application Security Engineer: Secure SDLC & DevSecOps
Application Security Engineer: Secure SDLC & DevSecOps

emagine Polska • Warszawa

Hybrid
PLN 303,000 - 477,000
Senior Lead App Security Engineer — Remote DevSecOps
Senior Lead App Security Engineer — Remote DevSecOps

AgileEngine, LLC. • Warszawa

On-site
PLN 180,000 - 240,000
Growth without limits
Competitive compensation
Flexibility - 100% remote with flexed,
+3
Security Engineer: Threat Defender & Automation
Security Engineer: Threat Defender & Automation

Bending Spoons • Warszawa

On-site
PLN 285,000 - 467,000
Flexible hours
Remote working
Health insurance
+4
Senior Application Security Analyst — SDLC & DevSecOps
Senior Application Security Analyst — SDLC & DevSecOps

Bunge • Poland

On-site
PLN 120,000 - 180,000
Principal AppSec Engineer - Java, AI-Driven Security, CI/CD
Principal AppSec Engineer - Java, AI-Driven Security, CI/CD

3003 Sabre Polska Sp. z o.o. • Kraków

On-site
PLN 220,000 - 320,000
Paid time off
Parental leave
Volunteer time off
+4