Application Security Engineer: Secure SDLC & DevSecOps

emagine Polska

Warszawa

Hybrid

PLN 303,000 - 477,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

emagine is seeking an Application Security Engineer to promote Secure SDLC practices, review architectures, and lead threat modelling across development teams. You will prioritise vulnerabilities from pentests and SAST/DAST, guide remediation, and drive secure coding practices.

You will coordinate external pentests, integrate security into CI/CD, and deliver workshops with Security Champions while collaborating with multiple stakeholders in a hybrid Lisbon-based setup.

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, or a related field.
  • Previous experience in Software Development followed by Application Security responsibilities.
  • Strong knowledge of Secure SDLC methodologies and secure software development principles.
  • Practical experience with OWASP Top 10, OWASP ASVS, Threat Modelling, and Secure Coding practices.
  • Experience analysing vulnerabilities generated through SAST, DAST, Dependency Scanning, Container Scanning, and Penetration Testing.
  • Knowledge of Authentication and Authorization protocols including OAuth2, OpenID Connect, JWT, and API Security.
  • Experience with Java (Spring Boot) and/or C# (.NET Framework / .NET Core / ASP.NET).
  • Experience working with Linux environments and basic shell scripting.
  • Cloud experience, preferably with AWS and/or Azure.
  • Experience integrating security into CI/CD pipelines and supporting DevSecOps initiatives.
  • Strong analytical, communication, mentoring, and stakeholder management skills.
  • Professional level of English.

Responsibilities

  • Promote and implement Secure SDLC practices across software development teams.
  • Review application architectures and participate in threat modelling activities.
  • Analyse and prioritise vulnerabilities identified through Pentests, SAST, DAST, dependency scanning, and container scanning.
  • Support development teams in the remediation of security vulnerabilities and implementation of secure coding practices.
  • Coordinate penetration testing activities with external partners and validate remediation actions.
  • Integrate security controls into CI/CD pipelines and contribute to DevSecOps initiatives.
  • Deliver secure coding workshops, create technical guidelines, and help establish Security Champions across development teams.
  • Collaborate with cross-functional teams to continuously improve application security processes and standards.

Skills

Secure SDLC
Threat Modelling
OWASP Top 10
OWASP ASVS
SAST/DAST
Dependency/Container Scanning
Penetration Testing
OAuth2
OpenID Connect
JWT
API Security
Java (Spring Boot)
C# (.NET)
Linux
Shell Scripting
AWS
Azure
DevSecOps
Communication
Mentoring
Stakeholder Management
English (Professional)

Education

Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, or related field

Tools

SonarQube
Checkmarx
Fortify
Veracode
Snyk
OWASP ZAP
Burp Suite
Trivy
Dependabot

Job description

emagine is seeking an Application Security Engineer to promote Secure SDLC practices, review architectures, and lead threat modelling across development teams. You will prioritise vulnerabilities from pentests and SAST/DAST, guide remediation, and drive secure coding practices.

You will coordinate external pentests, integrate security into CI/CD, and deliver workshops with Security Champions while collaborating with multiple stakeholders in a hybrid Lisbon-based setup.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

emagine Polska • Warszawa

Hybrid
PLN 303,000 - 477,000
Application Security Engineer - Secure-by-Design & CI/CD
Application Security Engineer - Secure-by-Design & CI/CD

AXA IT Solutions • Poland

Hybrid
PLN 180,000 - 240,000
Personal development
International environment
English work environment
+9
Application Security Engineer
Application Security Engineer

Papaya Global • Kraków

On-site
PLN 300,000 - 420,000
Application Security Engineer
Application Security Engineer

LionHires Recruitment • Poland

On-site
PLN 180,000 - 240,000
Remote Application Security Engineer – Secure SDLC Expert
Remote Application Security Engineer – Secure SDLC Expert

SOFTSWISS • Poland

On-site
PLN 218,579 - 327,869
Full-time remote work opportunities
Private insurance
Sports program compensation
+2
Application Security Engineer: Secure DevOps & Threat Modeling
Application Security Engineer: Secure DevOps & Threat Modeling

Starburst Data, Inc. • Warszawa

Hybrid
PLN 180,000 - 260,000
Stock grants
Flexible paid time off
Competitive pay
Application Security Engineer
Application Security Engineer

AXA IT Solutions • Poland

Hybrid
PLN 180,000 - 240,000
Personal development
International environment
English work environment
+9
Application Security Engineer: Vulnerability & Compliance
Application Security Engineer: Vulnerability & Compliance

Accuris • Województwo pomorskie

Hybrid
PLN 318,000 - 393,000
Annual incentive plan
Comprehensive benefits
Senior Lead App Security Engineer — Remote DevSecOps
Senior Lead App Security Engineer — Remote DevSecOps

AgileEngine, LLC. • Warszawa

On-site
PLN 180,000 - 240,000
Growth without limits
Competitive compensation
Flexibility - 100% remote with flexed,
+3
Application Security Research Engineer
Application Security Research Engineer

Commit • Warszawa

On-site
PLN 517,000 - 775,000