Назад
Company hidden
9 дней назад

Senior Security Engineer (Application Security)

145 196 - 223 379PLN
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Poland
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Engineer (Application Security/CI/CD): Driving the application security program and integrating scalable security controls into engineering workflows with an accent on secure software development, cloud-native applications, and developer-friendly tooling. Focus on configuring SAST, SCA, DAST, secrets management, and IaC scanning, reviewing threat models, and improving vulnerability management across product teams.

Location: Hybrid role in Warsaw, Poland

Salary: 145,196–223,379 PLN

Company

hirify.global is a global lottery technology company delivering lottery operations, retail and digital solutions, and lottery games for customers, governments, and regulators.

What you will do

  • Drive the application security program, including tool selection, policy enforcement, developer engagement, and risk reporting.
  • Integrate application security tooling into CI/CD pipelines and support scalable security controls.
  • Provide secure architecture and design guidance during development planning.
  • Deploy and tune SAST, SCA, secrets management, IaC scanning, and DAST tools.
  • Partner with product teams on secure coding, threat modeling, and high-impact vulnerability triage.
  • Develop security KPIs, mentor AppSec engineers, and promote security-first development practices.

Requirements

  • 5–10 years of experience in application security or secure software development.
  • Experience leading application security programs in CI/CD-focused engineering environments.
  • Strong expertise in securing cloud-native applications and integrating tools such as Semgrep, Mend, GitHub Advanced Security, or HCL AppScan.
  • Hands-on experience with GitHub Actions, GitLab CI, Jenkins, or similar CI/CD platforms.
  • Knowledge of DAST tools and penetration testing methodologies, including Burp Suite and Kali Linux.
  • Experience securing containers, microservices, APIs, and modern SDLC environments.

Nice to have

  • Experience with IAST and runtime protection technologies.

Culture & Benefits

  • Paid time off.
  • Health, life, and disability insurance.
  • Retirement benefits and well-being programs.
  • Opportunities to participate in volunteer initiatives and employee networks.
  • Annual information security training.
  • Additional benefits may depend on role seniority.

Hiring process

  • The process follows pay transparency and equal pay principles.
  • Salary history is not requested or used during selection.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →