Senior Vulnerability & Application Security Engineer

EY

Katowice

On-site

PLN 140,000 - 210,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

EY GDS Poland is seeking an Information Security Analyst – Supervising Associate to join the Technology Assurance, Risk, and Policy team. The role involves conducting security reviews, coordinating cyber assessments, and supporting secure product delivery in a hybrid model (2 days in office, 3 days remote) in Wrocław or Katowice.

You will work with experts across application and network security, PCI/ISO frameworks, and third‑party attestations, pushing for secure practices and risk‑driven

Qualifications

  • 5–8 years of experience in application security assessment.
  • Hands-on experience with web, thick client and mobile application security reviews.
  • Knowledge of manual testing methodologies and vulnerability assessment.
  • Understanding of security controls like firewalls, IDS/IPS, and encryption.
  • Ability to communicate risk and remediation to technical and non‑technical stakeholders.

Responsibilities

  • Prepare detailed security review reports and remediation guidance.
  • Research new application security vulnerabilities and attack vectors.
  • Lead strategic initiatives and mentor new team members.
  • Automate scanning processes within the CI/CD pipeline for continuous security testing.
  • Collaborate with development teams to address scan results and prioritize remediations.

Skills

Web security testing
Thick client testing
Mobile security testing
VOIP security testing
Wireless security testing
Manual & automated testing
Security concepts communication

Education

Bachelor's degree in Information Technology or Cyber Security

Tools

Burp Professional
Nmap
Wireshark
Nessus
WebInspect
Qualys WAS
Checkmarx
WhiteSource

Job description

Information Security Analyst – Supervising Associate

Location: Wrocław / Katowice – 2 days in office / 3 days remote

Let us introduce you the job offer by EY GDS Poland – a member of the global integrated service delivery center network by EY.

Today’s world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of over 950 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team helps protect the EY brand and build client trust.

Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.

The opportunity

The Technology Assurance, Risk, and Policy (TARP) function within Information Security strives to create and promote a holistic Governance, Risk, and Compliance (GRC) program by creating a robust, resilient, and proactive governance framework, supported by a strategic risk management approach and stringent compliance structures. It aims to integrate and align its GRC initiatives in line with the global firm’s objectives and emerging threats within the cybersecurity landscape.

The Technology Assurance team develops provides security assurance on EY’s deployed technology to internal and external stakeholders. The team members act as subject matter experts across a number of information and cyber security disciplines that include, among others, application and network penetrating testing and vulnerabilities identification, information security audits, compliance to cyber security and regulatory frameworks, and conducting or coordinating security audits and assessments. All applications must pass through security review prior to EY production usage. Security Certification checks the compliance of the application against EY security standards. The team develops the overall strategy and for implementing various technical attack and penetration assessment, information security audits like HITRUST, SOC 1 and SOC 2 to provide third‑party assurance to EY’s Clients in EY’s senior leadership. The team is responsible of overseeing and leading the technical audit process that includes third‑party external assessments of client‑facing critical business applications, M365 Teams Apps, network, cloud configuration reviews, infrastructure reviews, UK Cyber Essentials Plus Certification and UK IT Health Check Certification. The team manages attack and penetration testing controls based on industry standards and obtain third‑party security attestations/certifications to enable EY Business to win in the market. The team also manages and maintains the firm’s ISO 27001 certifications is responsible for the end‑end delivery of attestation audits like SOC 1 and SOC2. Technical compliance to regulatory framework like International Standard on Quality Management (ISQM) is also a responsibility of the team.

An Information Security Analyst will work closely with team leads to assist with one of the security functional areas described above.

Your Key Responsibilities
  • Preparing detailed security review reports and remediation guidance
  • Researching new application security vulnerabilities and attack vectors
  • Support the team in updating their skill and knowledge
  • Leading strategic initiatives and mentoring new team members
  • Continuous improvement to improve quality of service
  • Configure, manage, and update vulnerability assessment tools to ensure they are running optimally and providing accurate results
  • Work closely with development teams to ensure that self‑scan tools are configured and utilized effectively within the development lifecycle
  • Provide guidance and support to developers in interpreting and addressing scan results, including the identification of false positives and prioritization of remediation efforts
  • Automate scanning processes within the CI/CD pipeline to ensure continuous security testing of applications as code is developed, committed, and deployed
Skills And Attributes For Success
  • Hands on experience of Web, thick client, Mobile, VOIP, Wireless application security testing
  • Proficient in automated and manual application testing methodologies
  • Expert in using manual testing tools such as Burp Professional, Nmap, Wireshark, Nessus, echomirage
  • Expert in using automated application scan tool Webinspect / Qualys WAS, CheckMarx, WhiteSource etc.
  • Basic Knowledge of programming language like C/C++, C#, JAVA, ASP.NET and familiar with PERL/Python Scripting
  • Basic understanding of secure coding principles and common coding vulnerabilities (e.g., OWASP Top Ten). This helps in identifying vulnerabilities during code reviews and collaborating with development team
  • Knowledge of common security requirements within ASP.NET & Java application
  • Good knowledge of TCP/IP, Network Security
  • Hands‑on experience in testing AI integrated projects
  • Capable of testing both Android & iOS based applications
  • Knowledge to perform manual code review
  • Good Technical aptitude, problem solving and ability to quickly learn and master new topics and domains
  • Excellent communication skills; written and verbal
  • Ability to explain complex security concepts to non‑technical stakeholders and provide clear guidance to developers and architects
  • Explain SASP (Secure Application & System Policy) and implementation guide
  • Managing customers from different time‑zones and cultures
  • Ability to work closely with security consulting, cross‑functional teams, including development, project managers, DevOps engineers, vendors, and product management
To qualify for the role you must have
  • 5 to 8 years of experience in application security assessment
  • Hands on experience of Web, thick client, Mobile Application security reviews
  • Exposure and good understanding of the various manual testing methodologies
  • Knowledge of how vulnerabilities can lead to incidents and the role of vulnerability assessments in incident detection and response
  • A grasp of how applications, networks, and systems are architected from a security perspective. This includes understanding security controls like firewalls, IDS/IPS, and encryption
  • Must be a strong multi‑tasker and be able to prioritize duties
  • Ability to work with vendors as well as diverse teams across the organization, ensuring alignment of security goals with business objectives
  • Regularly communicate the status of risks and mitigation efforts to key stakeholders, including executives, developers, and other relevant teams
  • Adjust the risk management strategy as the application evolves, new threats emerge, and the business landscape changes
Ideally, you’ll also have
  • Bachelors or above in Information Technology or Cyber Security related Degrees
  • Keen interest in pursuing relevant Information Security Certifications like CEH, OSCP CISSP, CISM, CISA, Microsoft Azure, AWS, GCP etc
What We Offer

EY Global Delivery Services (GDS) is a dynamic and truly global delivery network. We work across nine locations – Argentina, Hungary, India, the Philippines, Poland, Sri Lanka, Mexico, Spain and the United Kingdom – and with teams from all EY service lines, geographies and sectors, playing a vital role in the delivery of the EY growth strategy. From accountants to coders to advisory consultants, we offer a wide variety of fulfilling career opportunities that span all business disciplines. In GDS, you will collaborate with EY teams on exciting projects and work with well‑known brands from across the globe. We’ll introduce you to an ever‑expanding ecosystem of people, learning, skills and insights that will stay with you throughout your career.

  • Continuous learning: You’ll develop the mindset and skills to navigate whatever comes next.
  • Success as defined by you: We’ll provide the tools and flexibility, so you can make a meaningful impact, your way.
  • Transformative leadership: We’ll give you the insights, coaching and confidence to be the leader the world needs.
  • Diverse and inclusive culture: You’ll be embraced for who you are and empowered to use your voice to help others find theirs.
About EY

EY | Building a better working world

EY exists to build a better working world, helping to create long‑term value for clients, people and society and build trust in the capital markets.

Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.

Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.

If you can demonstrate that you meet the criteria above, please contact us as soon as possible.

The Exceptional EY Experience. It’s Yours To Build.

In compliance with the requirements of the Whistleblower Protection Act, our company has established the Procedure for reporting breaches of law and undertaking appropriate follow-up actions. Any misconduct should be reported through the EY Ethics Hotline.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Vulnerability & Application Security Engineer
Senior Vulnerability & Application Security Engineer

EY • Wrocław

Hybrid
PLN 180,000 - 280,000
Senior Vulnerability & Application Security Engineer
Senior Vulnerability & Application Security Engineer

EY • Poland

Hybrid
PLN 150,000 - 210,000
Continuous learning
Diverse and inclusive culture
Leadership development
Vulnerability & Application Security Engineer
Vulnerability & Application Security Engineer

EY • Poland

Hybrid
PLN 150,000 - 210,000
Vulnerability & Application Security Engineer
Vulnerability & Application Security Engineer

EY • Wrocław

Hybrid
PLN 120,000 - 180,000
Vulnerability & Application Security Engineer
Vulnerability & Application Security Engineer

EY • Katowice

Hybrid
PLN 120,000 - 180,000
Continuous learning
Career growth
Flexible work options
+1
Vulnerability & Application Security Engineer
Vulnerability & Application Security Engineer

Ernst & Young Advisory Services Sdn Bhd • Wrocław

On-site
PLN 150,000 - 210,000
Senior Cloud Security Consultant
Senior Cloud Security Consultant

EY • Wrocław

Hybrid
PLN 180,000 - 260,000
CBS Security Consultant - SDLC
CBS Security Consultant - SDLC

Ernst & Young Advisory Services Sdn Bhd • Wrocław

Hybrid
PLN 180,000 - 280,000
IT Security Engineer - Enterprise Security Solutions
IT Security Engineer - Enterprise Security Solutions

EY • Wrocław

Hybrid
Continuous learning opportunities
Diverse and inclusive culture
Transformative leadership coaching
CBS Security Consultant - SDLC
CBS Security Consultant - SDLC

EY • Wrocław

Hybrid
PLN 180,000 - 240,000