Application Security Engineer - Senior

SOFTSWISS

Warszawa

On-site

PLN 210,000 - 270,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Private health insurance
Sports benefits
Mental Health Program
English lessons
Local language courses
Paid time off
Maternity leave support
Referral program
Upskilling

Job summary

SOFTSWISS is expanding its Application Security team and seeks a Senior Application Security Engineer who will secure our software across the SDLC. You will partner with product teams to identify threats and translate them into actionable security requirements, helping us deliver trustworthy products used by our customers.

You will conduct in-depth code reviews, support secure development practices, triage vulnerabilities, and help manage bug bounty programs.

Qualifications

  • 5+ years of experience in Application Security.
  • Knowledge of secure development processes and best practices.
  • Understanding of OAuth, OIDC, JWT and modern auth patterns.
  • Familiarity with OWASP Top 10 and vulnerability prevention.
  • Experience in secure architecture and design principles.

Responsibilities

  • Lead threat modeling and risk assessments with product teams.
  • Perform in-depth manual code reviews for critical apps.
  • Plan, design, implement and automate AppSec tooling.
  • Foster company-wide secure coding and deployment practices.
  • Triage vulnerabilities with clear, actionable fixes and mitigate risks.
  • Manage bug bounty collaborations with researchers and teams.
  • Provide consulting to Dev/QA to strengthen security posture.

Skills

Application Security
Threat modeling
Code review
Security testing
DevSecOps
OAuth/JWT

Education

Computer Science / Information Security degree

Tools

SAST/DAST tools
Bug bounty programs
DevSecOps tools

Job description

Overview:

We are expanding our Application Security team and need someone who is not only experienced but also shares our commitment to excellence.

Purpose of the role:

Our goal is to make sure that we deploy secure software to production without unnecessary bottlenecks, that applications are properly hardened, and security vulnerabilities, once discovered, are fixed by the developers.

As a Senior Application Security Engineer, you will play a crucial role in ensuring the security of our applications throughout the entire software development lifecycle (SDLC). You will partner closely with the product teams to identify, analyze, and mitigate security vulnerabilities, contributing to the creation of trustworthy and robust products.

Key responsibilities:
  • Partner with product teams during the design phase to lead threat modeling and risk assessments sessions, translating complex security threats into clear, actionable security requirements.
  • Perform in-depth manual code reviews on critical applications to identify complex logical vulnerabilities as part of white-box security assessment.
  • Plan, design, implement, automate and (if you wish) support AppSec tools.
  • Contribute to building a company-wide processes for secure code development and deployment.
  • Triage identified security vulnerabilities, provide clear and actionable descriptions and ensure these findings are properly addressed and mitigated.
  • Manage the bug bounty program, collaborate with researches and internal teams to resolve the discovered vulnerabilities.
  • Partner with Dev/QA teams throughout the development lifecycle to enhance the application's security posture by providing expert consulting, continuous knowledge sharing, and actionable security guidance.
Required Experience:
  • 5+ years of experience in Application Security.
  • Knowledge of secure development processes and best practices.
  • Deep understanding of web application security mechanisms (i.e., how the web actually works? What is SOP and why do we need CORS? What is CSP?).
  • Deep understanding of common web application vulnerabilities (i.e., OWASP Top 10), and the most effective ways to prevent them.
  • Knowledge of secure system/application architecture and design principles.
  • Understanding of modern threats to high-performance web applications that are used by millions of users daily.
  • Understanding of modern authentication/authorisation patterns (OAuth, OIDC, JWT, etc.)
  • Practical hands-on expertise in identifying vulnerabilities through security assessment and secure code review, coupled with the ability to perform deep root-cause analysis to drive systemic fixes.
  • University degree in Computer Science, Information Security, or related field, or equivalent combination of education and experience.
  • English and Russian proficiency at an upper-intermediate level (B2+)
Nice to have:
  • Passion about programming.
  • Technical knowledge of network and operating systems security.
  • Hands-on DevSecOps experience.
  • Practice of participation in bug bounty programs and/or CTFs.
  • Deep knowledge of SAST/DAST tools, including customisation.
  • Relevant certifications (i.e., OSWE, GWEB, etc.).
Our Benefits:
  • Private health insurance
  • Sports benefits
  • Comprehensive Mental Health Program
  • Free English lessons (online)
  • Local language courses
  • Paid time off
  • Maternity leave support
  • Referral program rewards
  • Upskilling, internal workshops, and participation in professional conferences and corporate events
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

SOFTSWISS • Warszawa

Hybrid
PLN 60,000 - 90,000
Full-time remote work opportunities
Private insurance
Additional 1 Day Off per calendar year
+5
Application Security Engineer
Application Security Engineer

SOFTSWISS • Poland

On-site
PLN 218,000 - 328,000
Full-time remote work opportunities
Private insurance
Sports program compensation
+2
Application Security Engineer
Application Security Engineer

AXA IT Solutions • Poland

Hybrid
PLN 180,000 - 240,000
Personal development
International environment
English work environment
+9
Application Security Engineer | Senior
Application Security Engineer | Senior

Nord Security • Poland

On-site
Private health insurance
Flexible work arrangements
Physical well-being programs
+3
Application Security Engineer
Application Security Engineer

Starburst • Poland

Hybrid
PLN 120,000 - 180,000
Competitive pay
Attractive stock grants
Flexible paid time off
Senior Pentester (Security Engineer)
Senior Pentester (Security Engineer)

DEVTALENTS Sp. z o.o. • Województwo mazowieckie

On-site
PLN 80,000 - 100,000
Influence over security architecture
Supportive culture for professional growth
Application Security Engineer – Penetration Tester
Application Security Engineer – Penetration Tester

Jobtailor • Warszawa

On-site
PLN 120,000 - 180,000
Application Security Engineer
Application Security Engineer

Solidgate • Województwo mazowieckie

On-site
30+ days off
Unlimited sick leave
Free office meals
+2
Application Security Research Engineer
Application Security Research Engineer

Commit • Warszawa

On-site
PLN 517,000 - 775,000
Senior Java Developer with strong Application Security Focus (m/f/d)
Senior Java Developer with strong Application Security Focus (m/f/d)

Commerzbank AG - Poland • Poland

Hybrid
PLN 180,000 - 300,000
Development plans
Life insurance
Flexible hours
+1