Senior Application Security Engineer (Java)

SoftServe

Polska

Presencial

PLN 180 000 - 240 000

Tempo integral

há 8 horas
Torna-te num dos primeiros candidatos
Gerador de candidaturas

Destaca-te nesta função — gera um currículo e uma carta de apresentação personalizados em cerca de um minuto.

Ultrapassa os filtros ATS

Resumo da oferta

SoftServe is seeking a senior security professional to lead application-focused penetration testing across web apps, APIs, and services. You will collaborate with Engineering to validate security controls, model threats early in development, and guide remediation with concrete fixes.

Ideal candidates have hands-on experience with Java, C#, Perl, and scripting, plus strong OWASP knowledge and tool proficiencies. You will mentor junior staff and contribute to secure-by-design initiatives.

Qualificações

  • At least 6 years in penetration testing or application security with broad tech exposure.
  • Hands-on with Java, Struts, C#, and Perl in development environments.
  • Experience with Alpine Linux, Envoy Proxy, Jetty and container hardening.
  • Familiarity with threat modeling methods such as STRIDE or PASTA.
  • Strong knowledge of OWASP Top 10, API Security Top 10, and ASVS guidance.

Responsabilidades

  • Lead application-focused penetration tests for web apps, APIs, services, and supporting infra.
  • Advise development teams on security issues and practical fixes; demonstrate and guide remediation.
  • Perform threat modeling and design reviews early in the SDLC to identify risks.
  • Conduct source reviews across Java, Struts, C#, Perl, and related tech.
  • Translate findings into business risk and present to engineers and execs.
  • Develop reports and presentations for technical and executive audiences.
  • Develop scripts, tools, and methodologies to mature the assessment program.
  • Collaborate with security leadership to define standards and goals for testing.
  • Support bug bounty triage, validate findings, and retest fixes.
  • Mentor junior team members and security champions.

Conhecimentos

Java
C#
Perl
Python
Bash
PowerShell
Threat modeling
OWASP Top 10
Communication

Ferramentas

Burp Suite Pro
SAST tooling
DAST tooling
SCA tooling

Descrição da oferta de emprego

About The Role

In this role you will lead application-focused penetration testing in support of products, validating that security controls work as intended. You will partner with our Engineering teams through threat modeling and software design reviews, and you will act as a trusted advisor on security issues and fixes across our development organization.



Responsibilities


  • Lead and perform application-focused penetration tests, including web applications, APIs, services, and supporting infrastructure, to validate that security controls are effective

  • Advise Development and Software Engineering teams on security issues and practical, well-researched fixes. Demonstrate vulnerabilities and guide remediation through to closure

  • Conduct threat modeling and software design reviews early in the development lifecycle to identify risks before code ships

  • Perform targeted source code reviews across technologies including Java, Struts, C#, Perl, Jetty, Envoy Proxy, and Alpine Linux based containers

  • Convert technical findings into business risk and communicate it to audiences ranging from engineers to executive leadership

  • Develop accurate, actionable reports and presentations for technical and executive team members

  • Safely use attacker tools, techniques, and procedures within defined rules of engagement

  • Develop scripts, tools, and methodologies to mature the application assessment program and support other teams

  • Help define the standards, methodology, and goals for the application penetration testing program, in partnership with security leadership

  • Collaborate with Application Security, Red Team, Product Management, and Engineering to support a secure by design program

  • Support bug bounty triage and external penetration test engagements, including validating findings and retesting fixes

  • Mentor junior team members and security champions in offensive application security techniques



Requirements


  • 10 years of experience in information technology, with a minimum of 6 years in penetration testing or application security

  • Software development or engineering background, with hands‑on experience in Java, Struts, C#, and Perl

  • Working knowledge of Alpine Linux, Envoy Proxy, and Jetty, including common misconfigurations and hardening practices

  • Proven experience with threat modeling methodologies such as STRIDE, PASTA, or attack trees, and with software design and architecture reviews

  • Expert knowledge of the OWASP Top 10, OWASP API Security Top 10, and the OWASP Testing Guide / ASVS

  • Deep knowledge of web and network protocols, such as HTTP/HTTPS, TLS, TCP/IP, and authentication and authorization frameworks like OAuth2, OIDC, SAML, and JWT

  • Strong command of application testing tools, such as Burp Suite Professional, and familiarity with SAST, DAST, and SCA tooling

  • Detailed knowledge of vulnerabilities and remediation techniques, including deserialization, injection, SSRF, access control, and business logic flaws

  • Experience developing, extending, or modifying exploits or exploit tools

  • Scripting and automation experience using Python, Perl, Bash, or PowerShell

  • Exposure to AWS, Docker, Kubernetes, and CI/CD pipelines

  • OSCP, OSWE, OSEP, GWAPT, or equivalent certification preferred

  • Ability to present ideas and solutions and to communicate clearly, concisely, and accurately at all levels of the organization

  • Able to drive your work to completion within specified timelines



SoftServe is an equal opportunity employer. Qualified applicants will receive consideration regardless of race, color, ancestry, ethnicity, national origin, religion, sex, sexual orientation, gender identity or expression, age, citizenship, disability, health condition, marital or family status, veteran status, or any other characteristic protected by applicable law.

Obtém a tua avaliação gratuita e confidencial do currículo.

ou arrasta e larga o ficheiro aqui.

Similar jobs

Ofertas semelhantes que vale a pena comparar

Senior AppSec Engineer: Pen Tests, Threat Modeling, Java
Senior AppSec Engineer: Pen Tests, Threat Modeling, Java

SoftServe • Polska

Presencial
PLN 180 000 - 240 000
Application Security Engineer
Application Security Engineer

Adecco • Warszawa

Presencial
PLN 180 000 - 280 000
Employment contract
Hybrid work in Warsaw (2-3 days/week)
Senior Pentester (Security Engineer)
Senior Pentester (Security Engineer)

DEVTALENTS Sp. z o.o. • Województwo mazowieckie

Presencial
PLN 80 000 - 100 000
Influence over security architecture
Supportive culture for professional growth
Senior Application Security Engineer
Senior Application Security Engineer

PepsiCo • Warszawa

Presencial
PLN 162 000 - 198 000
Lead Security Engineer
Lead Security Engineer

S&P Global, Inc. • Gdańsk

Híbrido
PLN 180 000 - 360 000
Lead Security Engineer
Lead Security Engineer

S&P Global, Inc. • Polónia

Presencial
PLN 254 022 - 381 033
Health care coverage
Generous time off
Continuous learning resources
+2
Application Security Engineer ID71662
Application Security Engineer ID71662

AgileEngine, LLC. • Szczecin

Híbrido
PLN 352 000 - 587 000
Professional growth
Competitive compensation (USD-based)
Exciting projects
+1
Application Security Engineer
Application Security Engineer

Papaya Global • Kraków

Presencial
PLN 300 000 - 420 000
Application Security Engineer ID71662
Application Security Engineer ID71662

AgileEngine, LLC. • Kraków

Híbrido
PLN 293 000 - 469 000
Professional growth
Competitive compensation
Exciting projects
+1
Application Security Engineer ID71662
Application Security Engineer ID71662

AgileEngine, LLC. • Lublin

Híbrido
PLN 352 000 - 509 000
Professional growth
Competitive USD-based compensation
Exciting projects
+1