16 часов назад
Senior Application Security Engineer (Java)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Application Security Engineer (Java) (Cybersecurity): Strengthening application security by embedding SSDLC practices, vulnerability management, and secure architecture across multiple development projects with an accent on Java code review, threat modeling, and CI/CD security integration. Focus on defining security guardrails, leading risk-based remediation, and driving developer security adoption across cloud-native environments.
Location: Poland; remote or office work
Company
provides engineering and technology services, including cybersecurity and application security transformation.
What you will do
- Lead and expand SSDLC practices in collaboration with development teams across all lifecycle stages.
- Review Java source code and lead vulnerability discovery, remediation recommendations, re-testing, and bug fixing.
- Assess client security maturity and define strategic improvement roadmaps aligned with business and risk priorities.
- Embed security into CI/CD pipelines and engineering workflows across multiple projects.
- Lead threat modeling, secure architecture workshops, and the definition of secure development standards and guardrails.
- Advise clients, mentor engineers, negotiate technical requirements, and drive security awareness at scale.
Requirements
- 5+ years of experience in application security engineering, SSDLC, security assessments, and secure SDLC implementation.
- Advanced skills in threat modeling, secure architecture reviews, and design-level security validation.
- Hands-on experience with SAST and DAST tools and integrating them into CI/CD pipelines.
- Experience with microservices, APIs, containers, Kubernetes, and public cloud platforms.
- Ability to review source code in Java and experience leading teams, mentoring engineers, and managing practice-level priorities.
- Fluent spoken and written English required.
Nice to have
- Proficiency in C#/.NET, Go, or Perl.
- OSCP, OSWE, OSEP, OSCE, CREST, eCPPT, eCPTX, eWPT, or eWPTX certification.
Culture & Benefits
- Remote or office-based work arrangement in Poland.
- Collaboration with multiple development teams and client stakeholders.
- Opportunity to influence security transformation initiatives and engineering practices across projects.
Hiring process
- Apply through the application form; the recruiting team will follow up.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →