Security Engineer (Application Security)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Security Engineer (Application Security): Conduct security architecture reviews, penetration testing, and vulnerability remediation for product and internal applications with an accent on application security and threat modeling. Focus on designing secure software, investigating security incidents, and educating engineers on secure coding practices.
Location: Warsaw office, hybrid schedule (Monday, Tuesday, Thursday in office)
Salary: 25,604 - 35,854 PLN gross monthly (Contract of Employment, UoP)
Company
Asana helps teams orchestrate their work globally, recognized as a top workplace with 11+ offices worldwide.
What you will do
- Conduct security architecture reviews, threat modeling, and penetration testing for new features and services.
- Test software for application security vulnerabilities using various assessment methodologies.
- Investigate and drive remediation of vulnerabilities from bug bounty, penetration tests, and automated tools.
- Influence engineering initiatives by communicating security constraints and assisting in trade-offs.
- Investigate product security incidents using logs and monitoring tools.
- Develop and deliver training on secure coding best practices and emerging threats.
Requirements
- Must have 5+ years experience in application or product security with penetration testing expertise.
- Strong software engineering background with Python, JavaScript/TypeScript, or Scala.
- Deep knowledge of OWASP Top 10 and common web vulnerabilities (XSS, CSRF, SSRF, SQL injection).
- Experience with SAST, DAST, SCA, and vulnerability management tools.
- Excellent communication skills for collaboration with technical and non-technical partners.
- Curiosity about AI tools and emerging technologies to enhance productivity.
Culture & Benefits
- Generous compensation including base salary and RSUs.
- Contract of Employment with tax benefits for engineers.
- Health insurance with dental and travel coverage.
- Lunch catering on office days and home office setup budget.
- Career growth and fitness reimbursement budgets.
- Fertility healthcare, family support, and mental health resources.
- Group life insurance and MacBook with accessories provided.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →