Application Security Engineer (F/M) w Warszawa, Poland - Jobeax
Opis oferty
Application Security Engineer (F/M) w Poland, Warszawa
AXA IT Solutions
ZdalniePraca z dowolnego miejsca
HybrydowoPołączenie biura i pracy zdalnej
160 - 215 zł / stawka godzinowa
Poland, Warszawa
Application Security Engineer (F/M)
Miejsce pracy: Warszawa
Technologies we use
Expected
.NET
Angular
JavaScript
TypeScript
CI/CD
Optional
SonarQube
Checkmarx
Operating system
Windows
About the project
We are looking for an Application Security Engineer (F/M) to join our engineering team and help us build security into the software development lifecycle.
This role is an opportunity to move beyond traditional vulnerability management and drive a proactive approach to application security. You will work closely with software engineers, architects, DevOps and security teams to automate security controls, integrate security into CI/CD pipelines, improve secure development practices and help teams build secure-by-design applications.
This is how we organize our work
This is how we work
in house
you have influence on the technological solutions applied
you have influence on the product
you focus on product development
agile
scrum
Your responsibilities
Own and continuously improve the application security posture of internally developed solutions, ensuring security is embedded throughout the software development lifecycle (SDLC).
Monitor, assess, prioritise, and manage application security vulnerabilities identified through penetration testing, SAST, DAST, dependency scanning, bug bounty programmes, and other security assessment activities, ensuring remediation within agreed SLAs.
Triage security findings to determine business risk, remediation requirements, and false positives, providing clear technical justification for all decisions.
Design, recommend and implement long-term, scalable security controls and automation to reduce recurring vulnerabilities, minimise manual intervention, and improve remediation efficiency across development teams.
Drive a shift-left security approach by integrating automated security testing, policy enforcement, and secure development practices into CI/CD pipelines and engineering workflows.
Identify recurring vulnerability patterns and implement preventative controls, secure frameworks, coding standards, and developer guardrails that eliminate classes of vulnerabilities at source.
Serve as the primary liaison with external penetration testing providers, ensuring security assessments are completed in a timely manner and findings are actionable, risk-based, and aligned with business priorities.
Partner with Group Security teams to maintain a single source of truth for vulnerabilities, consult, agree risk ratings, and resolve disputes relating to remediation requirements or false-positive findings.
Provide expert guidance on securing modern web applications, APIs, authentication mechanisms, and cloud-native architectures, with particular focus on .NET and Angular solutions.
Act as the Application Security subject matter expert for the Solution Delivery organisation, promoting secure design principles and security-by-default practices across all stages of solution delivery.
Maintain and enhance secure development standards, application security policies, and security engineering processes in line with OWASP, NIST, and industry best practices.
Proactively monitor emerging threats, OWASP Top 10 trends, attack techniques, and security tooling innovations, ensuring the organisation remains ahead of evolving application security risks.
Deliver security awareness and secure coding guidance to developers, technical leads, architects, and delivery teams to improve organisational security maturity.
Update on application security posture, vulnerability trends, remediation performance, and risk reduction initiatives to governance forums and steering groups, providing data-driven insights and recommendations.
Our requirements
Strong practical knowledge of the OWASP Top 10 and common web application attack vectors.
Deep understanding of securing modern web applications, REST APIs, authentication and authorisation mechanisms (OAuth2, OIDC, JWT).
Experience implementing and managing SAST, DAST, SCA, API security and penetration testing programmes.
Experience automating security controls within CI/CD pipelines and software delivery processes.
Strong knowledge of secure software engineering practices and secure-by-design principles.
Experience with .NET, Angular, JavaScript/TypeScript, and modern web application architectures.
Ability to identify strategic security improvements rather than focusing solely on vulnerability remediation.
Strong stakeholder management skills, with the ability to influence development teams, architects, and security functions.
Highly motivated, enthusiastic, and capable of working both independently and collaboratively in a team-oriented environment.
Exceptional analytical and problem-solving skills, with attention to detail and a business-focused approach.
Strong interpersonal skills, with the ability to influence technical decisions and communicate effectively in a fast-paced environment.
Demonstrates creativity and resourcefulness in presenting solutions to complex security challenges.
What we offer
The opportunity to influence technological solutions and product direction in an international financial organization
Ambitious projects with a high degree of autonomy and responsibility
A stable, long-term assignment with flexible working hours and a hybrid work model
This is how we work on a project
Clean Code
code quality measures
code review
static code analysis
BDD
TDD
architect / technical leader support
Continuous Deployment
Continuous Integration
DevOps
documentation
issue tracking tools
integration tests
pen tests
regression tests
test automation
manual tests
Benefits
remote work opportunities
flexible working time
fruits
integration events
no dress code
video games at work
coffee / tea
drinks
parking space for employees
leisure zone
AXA IT Solutions
We are an internal software house operating within the international insurance group AXA. We provide IT solutions for the needs of AXA companies in Europe. We work in English on a daily basis, in close-knit teams, carrying out international development projects.
Wszystkie informacje o przetwarzaniu danych osobowych w tej rekrutacji znajdziesz w formularzu aplikacyjnym, po kliknięciu w przycisk "Aplikuj Teraz".
... ,[Integrate security practices into development pipelines, including SAST/DAST and CI/CD security controls , Promote secure-by-design principles and “shift-left” engineering practices across teams , Conduct threat modelling for applications and projects, defining mitigation strategies and security requirements , Support teams ...
... ,[Integrate security practices into development pipelines, including SAST/DAST and CI/CD security controls , Promote secure-by-design principles and “shift-left” engineering practices across teams , Conduct threat modelling for applications and projects, defining mitigation strategies and security requirements , Support teams ...
... Junior Application Security Engineer who is passionate about technology, eager to learn, and excited to build a career in secure software development and application security within a supportive and inclusive enterprise environment. In this role, you will work closely with development and security teams to help embed secure-by-design ...
... Junior Application Security Engineer who is passionate about technology, eager to learn, and excited to build a career in secure software development and application security within a supportive and inclusive enterprise environment. In this role, you will work closely with development and security teams to help embed secure-by-design ...
Twój zakres obowiązków - Analiza wymagań klientów oraz wsparcie w rozwiązywaniu problemów technicznych - Identyfikowanie przyczyn źródłowych problemów oraz wdrażanie działań naprawczych - Zapewnianie wsparcia technicznego bezpośrednio u klientów - Prowadzenie demonstracji technicznych produktów oraz wsparcie testów i
... Python, Prisma Cloud, Tenable, Microsoft Azure O projekcie, Dołączysz do ok. 15-osobowego zespołu CyCommSec, który prowadzi wieloletni program DevSecOps i Application Security dla jednej z największych grup energetycznych (ropa i gaz) na Bliskim Wschodzie: kilkanaście spółek, ponad tysiąc aplikacji — systemy przetargowe ...
Operating system, Windows About the project, Join our Team in Kraków and contribute to the future of energy!, , We are looking for an Application Engineer who will play an important role in ensuring stable and efficient software deployment and providing qualified second-level support for client applications. In this role, ...
... troubleshooting across integrated enterprise platforms and connected systems Our requirements - Minimum 5 years of hands-on experience as an SAP Ariba Consultant, Application Engineer, or a similar role with strong functional and configuration expertise - Experience working across multiple SAP Ariba modules, including sourcing, ...
Senior SAP Ariba Application Engineer (f/m/x) Miejsce pracy: Warszawa Technologies we use Expected - SAP Ariba Buying - SAP Ariba Sourcing - SAP Ariba Contracts - SAP MM - P2P (Procure-to-Pay) About the project Join a global technology team responsible for supporting and enhancing enterprise procurement solutions used across ...
... Coordinate troubleshooting across integrated enterprise platforms and connected systems Minimum 5 years of hands-on experience as an SAP Ariba Consultant, Application Engineer, or a similar role with strong functional and configuration expertise, Experience working across multiple SAP Ariba modules, including sourcing, ...