Applied Security Engineer – Web Apps & APIs

Jobtailor

Warszawa

On-site

PLN 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking an Application Security professional to triage and analyze findings from SAST/SCA and secret scans, conduct manual and tool-assisted code reviews, and perform hands-on penetration testing of web apps, microservices, and APIs.

You will audit REST and GraphQL APIs, focusing on authentication, authorization, and business logic, applying OWASP Top 10 and API Security Top 10 principles. Collaboration with engineering and DevOps is essential.

Qualifications

  • 2–4 years of experience in Application Security, Product Security, or Penetration Testing.
  • Hands‑on experience triaging and analyzing findings from Semgrep / OpenGrep, Gitleaks, Trivy, and OSV-Scanner.
  • Experience with Burp Suite (Pro), Nuclei, Subfinder, SQLmap, Metasploit, and NetzScum?
  • Deep understanding of OWASP Top 10 vulnerabilities, including SQLi, XSS, CSRF, broken access control, and security misconfigurations.
  • Solid knowledge of OWASP API Security Top 10 for REST and GraphQL architectures.

Responsibilities

  • Triage, validate, and prioritize security findings from SAST, SCA, and secret scanning tools; filter false positives, assess risks, and track issues through remediation.
  • Conduct manual and tool-assisted code reviews to identify vulnerabilities before production.
  • Perform hands-on penetration testing of web applications, microservices, and APIs.
  • Audit REST and GraphQL APIs and web applications focusing on authentication, authorization, and business logic.

Skills

Security findings triage
Code review
Vulnerability assessment
Risk analysis
Penetration testing
API security
OAuth 2.0
JWT
RBAC/ABAC

Tools

Burp Suite (Pro)
Nuclei
SQLmap
Metasploit
Trivy
Gitleaks
OSV-Scanner
Kubernetes Security
AWS Cloud Security

Job description

Jobtailor is seeking an Application Security professional to triage and analyze findings from SAST/SCA and secret scans, conduct manual and tool-assisted code reviews, and perform hands-on penetration testing of web apps, microservices, and APIs.

You will audit REST and GraphQL APIs, focusing on authentication, authorization, and business logic, applying OWASP Top 10 and API Security Top 10 principles. Collaboration with engineering and DevOps is essential.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer – Penetration Tester
Application Security Engineer – Penetration Tester

Jobtailor • Warszawa

On-site
PLN 120,000 - 180,000
Application Security Engineer - Senior
Application Security Engineer - Senior

SOFTSWISS • Warszawa

On-site
PLN 210,000 - 270,000
Private health insurance
Sports benefits
Mental Health Program
+6
Application Security Engineer - Secure-by-Design & CI/CD
Application Security Engineer - Secure-by-Design & CI/CD

AXA IT Solutions • Poland

Hybrid
PLN 180,000 - 240,000
Personal development
International environment
English work environment
+9
Principal AppSec Engineer - Java, AI-Driven Security, CI/CD
Principal AppSec Engineer - Java, AI-Driven Security, CI/CD

3003 Sabre Polska Sp. z o.o. • Kraków

On-site
PLN 220,000 - 320,000
Paid time off
Parental leave
Volunteer time off
+4
Senior AppSec Engineer - Lead Threat Modeling & Secure SDLC
Senior AppSec Engineer - Lead Threat Modeling & Secure SDLC

SOFTSWISS • Warszawa

On-site
PLN 210,000 - 270,000
Private health insurance
Sports benefits
Mental Health Program
+6
Application Security Engineer
Application Security Engineer

SOFTSWISS • Warszawa

Hybrid
PLN 60,000 - 90,000
Full-time remote work opportunities
Private insurance
Additional 1 Day Off per calendar year
+5
Senior Offensive Security Lead - Cloud & App PenTesting
Senior Offensive Security Lead - Cloud & App PenTesting

S&P Global, Inc. • Poland

On-site
PLN 254,000 - 382,000
Health care coverage
Generous time off
Continuous learning resources
+2
Application Security Engineer
Application Security Engineer

SOFTSWISS • Poland

On-site
PLN 218,000 - 328,000
Full-time remote work opportunities
Private insurance
Sports program compensation
+2
Senior Pentester (Security Engineer)
Senior Pentester (Security Engineer)

DEVTALENTS Sp. z o.o. • Województwo mazowieckie

On-site
PLN 80,000 - 100,000
Influence over security architecture
Supportive culture for professional growth
AI AppSec / AiSec Engineer
AI AppSec / AiSec Engineer

Mindbox Sp. z o.o. • Kraków

On-site
PLN 120,000 - 180,000