Vulnerability & Application Security Engineer

EY

Katowice

On-site

PLN 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Continuous learning
Career growth
Flexible work options
Diversity & inclusion

Job summary

EY GDS Poland is hiring an Information Security Analyst – Associate/Senior Associate to join the security team in Poland. The role involves supporting security reviews, vulnerability management, and risk-based assessments across EY’s technology landscape from Wrocław or Katowice, with a hybrid work model (2 days in office, 3 days remote).

You will work on application and network security testing, compliance with standards, and third‑party assurance activities.

Qualifications

  • Bachelor’s degree in Information Technology or Cyber Security.
  • Hands-on security testing across web, mobile, and thick client apps.
  • Familiarity with security controls and incident response concepts.

Responsibilities

  • Prepare detailed security review reports and remediation guidance.
  • Research new application security vulnerabilities and attack vectors.
  • Lead strategic initiatives and mentor new team members.
  • Configure, manage, and update vulnerability assessment tools for accurate results.

Skills

Web security testing
Manual testing methodologies
Security incident awareness
Excellent communication

Education

Bachelor’s degree in Information Technology or Cyber Security

Tools

Burp Suite Pro
Nmap
Wireshark
Nessus
Echomirage
WebInspect/Qualys WAS
Checkmarx
WhiteSource
Python scripting

Job description

Information Security Analyst – Associate/Senior Associate

Location: Wrocław / Katowice – 2 days in office, 3 days remote

Let us introduce you to the job offer by EY GDS Poland – a member of the global integrated service delivery center network by EY. Today’s world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of over 950 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team help protect the EY brand and build client trust.

Within Information Security we blend risk strategy, digital identity, cyber defense, application security, and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.

The opportunity

The Technology Assurance, Risk, and Policy (TARP) function within Information Security strives to create and promote a holistic Governance, Risk, and Compliance (GRC) program by building a robust, resilient, and proactive governance framework, supported by a strategic risk‑management approach and stringent compliance structures. It aims to integrate and align its GRC initiatives with the global firm’s objectives and emerging threats within the cybersecurity landscape.

The Technology Assurance team provides security assurance on EY’s deployed technology to internal and external stakeholders. Team members act as subject‑matter experts across a number of information and cyber‑security disciplines that include application and network penetration testing, vulnerability identification, information security audits, compliance with cyber‑security and regulatory frameworks, and coordination of security audits and assessments. All applications must pass through a security review prior to EY production usage. Security certification checks the compliance of the application against EY security standards. The team develops overall strategy and implements various technical attacks and penetration assessments, information security audits such as HITRUST, SOC 1 and SOC 2, to provide third‑party assurance to EY’s clients and senior leadership. It oversees and leads the technical audit process, including third‑party external assessments of client‑facing critical business applications, M365 Teams Apps, network, cloud configuration reviews, infrastructure reviews, UK Cyber Essentials Plus Certification and UK IT Health Check Certification. The team also manages and maintains the firm’s ISO 27001 certifications and is responsible for end‑to‑end delivery of attestation audits like SOC 1 and SOC 2. Technical compliance to regulatory frameworks such as International Standard on Quality Management (ISQM) is also a responsibility of the team.

An Information Security Analyst will work closely with team leads to assist with one of the security functional areas described above.

Your Key Responsibilities
  • Prepare detailed security review reports and remediation guidance.
  • Research new application security vulnerabilities and attack vectors.
  • Support the team in updating their skill and knowledge.
  • Lead strategic initiatives and mentor new team members.
  • Continuously improve quality of service.
  • Configure, manage, and update vulnerability assessment tools to ensure they run optimally and provide accurate results.
Skills and Attributes for Success
  • Hands‑on experience with web, thick client, mobile, VOIP, and wireless application security testing.
  • Proficiency in automated and manual application testing methodologies.
  • Expertise with manual testing tools such as Burp Professional, Nmap, Wireshark, Nessus, echomirage.
  • Expertise with automated application scan tools such as Webinspect / Qualys WAS, Checkmarx, WhiteSource, etc.
  • Basic knowledge of programming languages such as C/C++, C#, Java, ASP.NET and familiarity with PERL/Python scripting.
  • Basic understanding of secure coding principles and common coding vulnerabilities (e.g., OWASP Top Ten).
  • Knowledge of security requirements within ASP.NET and Java applications.
  • Good knowledge of TCP/IP and network security.
  • Hands‑on experience testing AI‑integrated projects.
  • Capability to test both Android and iOS applications.
  • Ability to perform manual code reviews.
  • Excellent technical aptitude, problem‑solving skills, and the ability to learn and master new topics rapidly.
  • Excellent written and verbal communication skills.
To Qualify for the Role You Must Have
  • 1 to 6 years of experience in application security assessment.
  • Hands‑on experience with web, thick client, and mobile application security reviews.
  • Exposure to and solid understanding of various manual testing methodologies.
  • Knowledge of how vulnerabilities can lead to incidents and the role of vulnerability assessments in incident detection and response.
  • Grasp of how applications, networks, and systems are architected from a security perspective, including security controls such as firewalls, IDS/IPS, and encryption.
  • Strong multitasking ability and prioritization skills.
Ideally, You’ll Also Have
  • Bachelor’s or higher degree in Information Technology or Cyber Security related fields.
  • Interest in pursuing relevant Information Security certifications such as CEH, OSCP, CISSP, CISM, or CISA.
What We Offer
  • Continuous learning – develop the mindset and skills to navigate whatever comes next.
  • Success as defined by you – access tools and flexibility to make a meaningful impact your way.
  • Transformative leadership – insights, coaching, and confidence to be the leader the world needs.
  • Diverse and inclusive culture – be embraced for who you are and empowered to use your voice to help others find theirs.

In compliance with the requirements of the Whistleblower Protection Act, our company has established the Procedure for reporting breaches of law and undertaking appropriate follow-up actions. Any misconduct should be reported through the EY Ethics Hotline.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vulnerability & Application Security Engineer
Vulnerability & Application Security Engineer

EY • Wrocław

Hybrid
PLN 120,000 - 180,000
Senior Vulnerability & Application Security Engineer
Senior Vulnerability & Application Security Engineer

EY • Wrocław

Hybrid
PLN 180,000 - 280,000
Senior Vulnerability & Application Security Engineer
Senior Vulnerability & Application Security Engineer

EY • Katowice

Hybrid
PLN 140,000 - 210,000
Vulnerability & Application Security Engineer
Vulnerability & Application Security Engineer

EY • Poland

Hybrid
PLN 150,000 - 210,000
Senior Vulnerability & Application Security Engineer
Senior Vulnerability & Application Security Engineer

EY • Poland

Hybrid
PLN 150,000 - 210,000
Continuous learning
Diverse and inclusive culture
Leadership development
IT Security Engineer - Enterprise Security Solutions
IT Security Engineer - Enterprise Security Solutions

EY • Wrocław

Hybrid
Continuous learning opportunities
Diverse and inclusive culture
Transformative leadership coaching
Senior Vulnerability Analyst
Senior Vulnerability Analyst

EY • Katowice

Hybrid
PLN 120,000 - 180,000
Senior Vulnerability Analyst
Senior Vulnerability Analyst

EY • Wrocław

Hybrid
PLN 180,000 - 280,000
Continuous learning
Transformative leadership
Diverse and inclusive culture
+1
CBS Security Consultant - SDLC
CBS Security Consultant - SDLC

Ernst & Young Advisory Services Sdn Bhd • Wrocław

Hybrid
PLN 180,000 - 280,000
Attack Surface & Exposure Validation Engineer
Attack Surface & Exposure Validation Engineer

EY • Katowice

Hybrid
PLN 270,000 - 450,000