WHO WE ARE
Accenture Security’s Cyber Security team helps clients secure hybrid environments and applications throughout the software development lifecycle, ensuring that security is built in by design and by default.
THE WORK
- Collaborate with architecture, product, and development teams to embed security principles from the earliest stages of the Software Development Life Cycle (SDLC), following a security‑by‑design and shift‑left approach.
- Perform application and system security assessments in accordance with recognized industry standards and frameworks, including OWASP ASVS, OWASP Top 10, OWASP API Top 10, CWE Top 25, and other relevant security best practices.
- Design, implement, and govern security controls across the SDLC and SSDLC, ensuring consistent application of secure coding standards, security gates, and automated security testing.
- Conduct security architecture reviews for end‑to‑end solutions, including hybrid, cloud‑native, containerized, microservices‑based, and event‑driven architectures.
- Analyze and assess the security of application code, APIs, infrastructure‑as‑code (IaC), CI/CD pipelines, and supporting platforms.
- Support the design of modern, secure development environments, including secure CI/CD pipelines, hardened build environments, secure artifact repositories, and developer tooling.
- Define and drive Secure Software Development Lifecycle (SSDLC) processes, from security requirements definition and prioritization to software supply chain security, including dependency management, third‑party risk, and SBOM analysis.
- Perform threat modeling for applications and systems, focusing on hybrid, distributed, and cloud‑based environments to identify risks and propose mitigation strategies.
- Provide hands‑on support to development teams in analyzing, prioritizing, and mitigating identified vulnerabilities with pragmatic and scalable solutions.
- Assess and secure AI‑enabled systems and platforms, including applications based on machine learning, large language models (LLMs), and AI agents, covering the full lifecycle.
- Identify and mitigate AI‑specific security risks such as model abuse, prompt injection, data poisoning, training data leakage, insecure model deployment, and unauthorized model access.
- Define security requirements and controls for AI pipelines, including data ingestion, model training, model storage, inference APIs, and integration with existing systems.
- Leverage AI‑based security tools and automation to enhance vulnerability detection, code analysis, threat detection, and security operations efficiency.
- Support governance and compliance related to responsible and secure use of AI, including risk assessment, security controls, and alignment with internal and external regulations.
LOCATION
The work location may be a mix of remote, onsite at a client, or in an Accenture office, depending on specific project circumstances. Some in‑person time is expected for collaboration, learning, and building relationships with clients, peers, leaders, and communities.
WHAT’S IN IT FOR YOU
- Work on international projects, collaborating with top global organizations to solve complex security challenges.
- Lead and drive innovation, helping clients transform their businesses with cutting‑edge security technologies and frameworks.
- Grow your expertise in a dynamic environment, gaining exposure to the latest trends, tools, and best practices.
HERE’S WHAT YOU’LL NEED
- Strong motivation to develop in Application Security and a mindset of continuous learning and skill development in cybersecurity, secure software engineering, and emerging technologies.
- Solid background in IT or software development, with proven experience in engineering, architecture, or operational roles, combined with hands‑on or growing expertise in cybersecurity.
- Good understanding of end‑to‑end application and system architectures, including layered, monolithic, microservices‑based, event‑driven, and service‑oriented (SOA) architectures.
- Basic knowledge of application security fundamentals such as OWASP Top 10, OWASP ASVS, OWASP API Top 10, secure coding best practices, common vulnerability classes, and exploitation techniques.
- Practical understanding of attack techniques (XSS, CSRF, SQL Injection, deserialization issues, authentication bypasses, privilege escalation) and familiarity with MITRE ATT&CK / CAPEC frameworks.
- Knowledge of authentication, authorization, and session management concepts, including OAuth 2.0, OpenID Connect, SAML, SSO, and modern identity‑centric security models.
- Good understanding of cryptographic concepts and best practices (encryption, hashing, key management, secure use of cryptographic libraries).
- Knowledge of Secure Software Development Lifecycle (SSDLC) principles, including requirements, secure design, secure coding, testing, vulnerability management, and release governance.
- Experience or knowledge of REST APIs, API security concepts, and API Gateway architectures.
- Ability to analyze source code, APIs, and Infrastructure‑as‑Code (IaC) from a security perspective.
- Interest in securing AI‑enabled applications, platforms, or services, including LLM‑based systems.
- Proficiency in at least one programming language (Java, .NET/C#, JavaScript, Go, or Python).
- Experience with or strong understanding of static application security testing (SAST) and code review from a security perspective.
- Ability to perform or support threat modeling for applications and systems, considering business logic, architecture, and deployment models.
- Knowledge of reverse engineering and malware analysis concepts and techniques.
- Strong communication skills and ability to support development teams in vulnerability analysis and remediation.
- Fluency in English and Polish, spoken and written, due to collaboration with international teams and clients.
BONUS POINTS IF YOU HAVE
- Hands‑on experience with at least one major cloud platform: Azure, AWS, or Google Cloud Platform (GCP).
- Experience securing CI/CD pipelines, build systems, and artifact repositories.
- Familiarity with software supply chain security, including dependency scanning, SBOMs, third‑party risk, and open‑source security.
- Experience working with Git, Jira, and Agile/DevSecOps methodologies.
- Understanding of AI/ML system architectures, including data pipelines, model training, model storage, inference services, and API‑based integration.
- Ability to leverage AI‑powered security tools for code analysis, vulnerability detection, threat analysis, or security automation.
- Understanding of governance, risk, and compliance aspects related to the secure and responsible use of AI.
- Awareness of AI‑specific security risks, such as prompt injection, model manipulation, data poisoning, training data leakage, insecure model exposure, and unauthorized inference.
WHAT WE OFFER
- Permanent employment contract.
- Individual support from a People Lead and a defined professional development path, including opportunities for coaching.
- A broad training package (soft, technical, language training, access to e‑learning platforms, Gallup test, GenAI training, potential tuition reimbursement, and certifications).
- Employee Assistance Program – legal, financial, and psychological consultations.
- Eligibility for Accenture’s Employee Share Purchase Plan and quarterly dividends for share holders.
- Paid employee referral program.
- Private medical care and life insurance.
- Access to the Worksmile platform (wide range of products and services, including the Multisport card).
WHAT WE BELIEVE
Accenture does not discriminate employment candidates on the basis of race, religion, color, sex, age, disability, national origin, political beliefs, trade union membership, ethnicity, denomination, sexual orientation or any other basis impermissible under Polish law. Inclusion and diversity are fundamental to our culture and core values. Our diverse workforce fuels innovation and creativity, allowing us to better serve clients and communities. We are committed to sustainability, embedding this responsibility into all our work.
Clicking apply I hereby express my consent to process my personal data included in my job offer by Accenture Sp. z o.o. or any other entity of the Accenture group for recruitment purposes, and that it is a data controller within the meaning of GDPR. More information about Accenture (and if necessary also its representative) can be found here: https://www.accenture.com/pl-pl/privacy-policy
#PLSEC