Senior App Security Architect & Threat Modeling Lead

Papaya Global

Kraków

On-site

PLN 150,000 - 190,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Papaya Global is seeking an experienced Application Security / Security Architect to embed security across the application lifecycle. You will partner with R&D, DevOps/Cloud, product, and cybersecurity to improve security of applications, APIs, repositories, and cloud services.

You will combine architecture, threat modeling, secure software development, vulnerability validation, and engineering partnership to translate findings into prioritized remediation for engineering teams.

Qualifications

  • 4+ years of hands-on experience in application security, product security, security architecture, or a closely related role.
  • Strong understanding of secure software development lifecycles, threat modeling, security requirements, architecture reviews, and practical risk assessment.
  • Hands-on experience with web applications, APIs, microservices, authentication, authorization, data protection, secrets management, and service-to-service communication.
  • Practical code-reading or code-review experience in one or more modern programming languages, with the ability to explain security issues clearly to engineers.
  • Background as a software developer, or comparable hands-on experience as a builder — for example in DevOps engineering or software architecture.
  • Experience with application-security tooling or equivalent capabilities, such as vulnerability management, SAST, DAST, SCA, secret scanning, CSPM, or security testing platforms.
  • Experience validating vulnerabilities and managin g remediation from discovery through verified closure.
  • Strong written and verbal communication skills, with the ability to influence R&D, DevOps, product, and business stakeholders without relying on authority alone.
  • Experience using AI tools in day-to-day engineering work, as well as specifically for vulnerability analysis and exploitation, including AI-assisted code review, vulnerability triage, and exploit development.

Responsibilities

  • Own and mature the application-security and security-architecture program across product and internal applications, APIs & services, and data stores.
  • Conduct threat modeling, architecture reviews, security design reviews, and risk assessments for new systems and materially changed services.
  • Define application-security requirements, review triggers, and practical security patterns for authentication, authorization, secrets, data protection, input handling, APIs, service-to-service communication, and security logging.
  • Review source code, high-risk configurations, CI/CD security checks, and application integrations with engineering teams; provide actionable guidance to enhance security posture.
  • Validate and prioritize findings from vulnerability-management and security-assessment tooling, penetration tests, and other security assessments - distinguish true risk from noise, and translate findings into clear engineering tasks and track their status.
  • Own the operating process for penetration testing and bug bounty programs, including scope, intake, triage, communication, remediation tracking, and verification of fixes.
  • Identify recurring vulnerability themes and root causes, then drive preventive improvements in engineering practices, tooling, architecture, and developer enablement.
  • Partner with Security Operations to provide application context, logging requirements, detection opportunities, and context relevant to monitoring and incident response.

Skills

Application Security
Product Security
Security Architecture
Threat Modeling
Secure SDLC
Code Review
Vulnerability Management
Penetration Testing
SAST/DAST
CI/CD Security
Cloud Security
AI Security Tools

Tools

WAS

Job description

Papaya Global is seeking an experienced Application Security / Security Architect to embed security across the application lifecycle. You will partner with R&D, DevOps/Cloud, product, and cybersecurity to improve security of applications, APIs, repositories, and cloud services.

You will combine architecture, threat modeling, secure software development, vulnerability validation, and engineering partnership to translate findings into prioritized remediation for engineering teams.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Architect for Secure Apps & APIs
Application Security Architect for Secure Apps & APIs

Papaya Global • Kraków

On-site
PLN 300,000 - 420,000
Application Security Engineer @ Papaya Global
Application Security Engineer @ Papaya Global

Papaya Global • Kraków

On-site
PLN 150,000 - 190,000
Application Security Engineer
Application Security Engineer

Papaya Global • Kraków

On-site
PLN 300,000 - 420,000
Security Architect: Threat Modeling & Secure-by-Design
Security Architect: Threat Modeling & Secure-by-Design

PepsiCo • Warszawa

On-site
PLN 284,000 - 384,000
Annual bonus 20%
Comprehensive benefits
Senior App Security Engineer: Web & API Security Lead
Senior App Security Engineer: Web & API Security Lead

PepsiCo • Warszawa

On-site
PLN 162,000 - 198,000
Global FinTech Software Architect — AI-Driven, Cross-Domain
Global FinTech Software Architect — AI-Driven, Cross-Domain

Papaya Global • Kraków

On-site
PLN 200,000 - 320,000
Application Security Engineer: Secure SDLC & DevSecOps
Application Security Engineer: Secure SDLC & DevSecOps

emagine Polska • Warszawa

Hybrid
PLN 303,000 - 477,000
Global AppSec Architect: SSDLC & AI Security Leader
Global AppSec Architect: SSDLC & AI Security Leader

Arrive • Łódź

On-site
PLN 260,000 - 360,000
Application Security Engineer
Application Security Engineer

Adecco • Warszawa

Hybrid
PLN 180,000 - 280,000
Employment contract
Hybrid work in Warsaw (2-3 days/week)
Application Security Engineer: Secure DevOps & Threat Modeling
Application Security Engineer: Secure DevOps & Threat Modeling

Starburst Data, Inc. • Warszawa

Hybrid
PLN 180,000 - 260,000
Stock grants
Flexible paid time off
Competitive pay