Senior AppSec Engineer — CI/CD Security Leader

Brightstar Lottery

Warszawa

On-site

PLN 145,000 - 223,000

Full time

10 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Paid time off
Health insurance
Life insurance
Disability insurance
Volunteer time
Well-being programs
Retirement benefits
Additional benefits based on seniority

Job summary

Brightstar Lottery is seeking an Application Security Engineer in Warsaw to lead the strategy, implementation, and maturity of our AppSec program across the SDLC. You will integrate security tooling into engineering workflows and partner with security, DevOps, and engineering leadership to scale security across product teams.

This high-impact role requires hands-on expertise with SAST/DAST, cloud-native security, and CI/CD integrations, plus a passion for building a security-first development

Qualifications

  • 5-10 years of experience in Application Security or Secure Software Development.
  • Proven experience leading application security programs in CI/CD-heavy engineering environments.
  • Deep expertise in securing cloud-native applications and integrating AppSec tools such as Semgrep, Mend, GitHub Advanced Security, HCL AppScan.
  • Hands-on experience with CI/CD integrations using GitHub Actions, GitLab CI, Jenkins, or similar.
  • Strong communication and influencing skills; able to drive security adoption across diverse teams.
  • Knowledge of DAST tools (Tenable Web App Scanning) and Pentest methodologies (Burp Suite, Kali Linux).
  • Experience with security in modern SDLC environments using containers, microservices, and APIs.
  • IAST experience is a plus.

Responsibilities

  • Participate in application security program, including tool selection, policy enforcement, developer engagement, and risk reporting.
  • Own integration of AppSec tooling into CI/CD pipelines to enable scalable, developer-friendly security controls.
  • Provide architectural guidance and secure design recommendations during development planning.
  • Oversee deployment and tuning of tools for SAST, SCA, secrets management, IaC scanning, and DAST (e.g., Tenable Web App Scanning).
  • Partner with product teams to embed secure coding practices, review threat models, and triage high-impact vulnerabilities.
  • Collaborate with GRC/compliance teams to ensure alignment with relevant standards (e.g., OWASP, FedRAMP).
  • Mentor and support other AppSec engineers and champion a security-first development culture.
  • Evaluate IAST and runtime protections as part of continuous improvement efforts.
  • Develop KPIs to measure security posture and tooling efficacy.

Skills

Security leadership
AppSec program management
CI/CD security integration
Cloud-native security
Communication
Threat modeling
Security tooling

Tools

Semgrep
Mend
GitHub Advanced Security
HCL AppScan
Tenable Web App Scanning
Burp Suite
Kali Linux

Job description

Brightstar Lottery is seeking an Application Security Engineer in Warsaw to lead the strategy, implementation, and maturity of our AppSec program across the SDLC. You will integrate security tooling into engineering workflows and partner with security, DevOps, and engineering leadership to scale security across product teams.

This high-impact role requires hands-on expertise with SAST/DAST, cloud-native security, and CI/CD integrations, plus a passion for building a security-first development

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior AppSec Engineer – CI/CD Security Leader (Hybrid)
Senior AppSec Engineer – CI/CD Security Leader (Hybrid)

Brightstar Lottery • Warszawa

Hybrid
PLN 145,000 - 223,000
Paid time off
Health insurance
Life insurance
+4
Senior AppSec Engineer: Secure CI/CD in Cloud-Native Warsaw
Senior AppSec Engineer: Secure CI/CD in Cloud-Native Warsaw

Adecco • Warszawa

Hybrid
PLN 210,000 - 270,000
Private medical care
Life insurance
Hybrid work model
Application Security Engineer: Secure DevOps & Threat Modeling
Application Security Engineer: Secure DevOps & Threat Modeling

Starburst Data, Inc. • Warszawa

Hybrid
PLN 180,000 - 260,000
Stock grants
Flexible paid time off
Competitive pay
Application Security Engineer
Application Security Engineer

Adecco • Warszawa

On-site
PLN 180,000 - 280,000
Employment contract
Hybrid work in Warsaw (2-3 days/week)
Senior AppSec Engineer — Lead Secure SDLC (Hybrid Warsaw)
Senior AppSec Engineer — Lead Secure SDLC (Hybrid Warsaw)

Adecco • Warszawa

Hybrid
PLN 180,000 - 280,000
Employment contract
Hybrid work in Warsaw (2-3 days/week)
App & Product Security Engineer (Hybrid, Warsaw)
App & Product Security Engineer (Hybrid, Warsaw)

Starburst • Warszawa

Hybrid
PLN 180,000 - 260,000
Principal AppSec Engineer - Java, AI-Driven Security, CI/CD
Principal AppSec Engineer - Java, AI-Driven Security, CI/CD

3003 Sabre Polska Sp. z o.o. • Kraków

On-site
PLN 220,000 - 320,000
Paid time off
Parental leave
Volunteer time off
+4
Application Security Engineer: DevSecOps & CI/CD Automation
Application Security Engineer: DevSecOps & CI/CD Automation

AgileEngine • Kraków

Hybrid
PLN 180,000 - 240,000
Professional growth
Competitive compensation (USD-based)
Exciting projects
+1
Principal AppSec Engineer — Java, AI & Cloud Security
Principal AppSec Engineer — Java, AI & Cloud Security

Sabre Corporation • Poland

Hybrid
PLN 320,000 - 420,000
Hybrid work model
Office Kraków
No dress code
+1
Security Engineer
Security Engineer

Brightstar Lottery • Warszawa

Hybrid
PLN 145,000 - 223,000
Paid time off
Health insurance
Life insurance
+4