Назад
Company hidden
обновлено 9 дней назад

Applications Security Engineer III (Cybersecurity)

145 196 - 223 379PLN
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Poland
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Applications Security Engineer III (Cybersecurity): Driving the strategy, implementation, and maturity of the application security program with an accent on integrating security tooling into CI/CD pipelines and fostering a security-first development culture. Focus on architectural guidance, vulnerability management, and ensuring compliance with industry standards like OWASP and FedRAMP.

Location: Hybrid role in Warsaw, Poland

Salary: PLN 145,196–223,379 per year

Company

hirify.global is a global lottery company providing secure technology, lottery operations, retail and digital solutions, and lottery games for governments, regulators, customers, and players.

What you will do

  • Help drive the application security program, including tooling, policies, developer engagement, and risk reporting.
  • Integrate and manage application security tools across CI/CD pipelines.
  • Provide secure architecture guidance and design recommendations during development planning.
  • Deploy and tune SAST, SCA, secrets management, IaC scanning, and DAST solutions.
  • Partner with product teams on secure coding, threat modeling, and high-impact vulnerability triage.
  • Develop security KPIs, mentor AppSec engineers, and support continuous improvement of runtime protections.

Requirements

  • 5–10 years of experience in application security or secure software development.
  • Experience leading application security programs in CI/CD-focused engineering environments.
  • Expertise securing cloud-native applications and integrating tools such as Semgrep, Mend, GitHub Advanced Security, or HCL AppScan.
  • Hands-on experience with GitHub Actions, GitLab CI, Jenkins, or similar CI/CD platforms.
  • Knowledge of DAST and penetration testing methodologies, including Tenable Web App Scanning, Burp Suite, or Kali Linux.
  • Experience securing containers, microservices, APIs, and modern SDLC environments.

Nice to have

  • Experience with IAST and runtime application protection.

Culture & Benefits

  • Paid time off.
  • Health, life, and disability insurance.
  • Retirement benefits and well-being programs.
  • Opportunities to volunteer and participate in employee networks or organizations.
  • Annual information security training and additional benefits based on role seniority.

Hiring process

  • Selection follows pay-transparency and equal-pay principles.
  • Salary history is not requested or used during selection.
  • Employment terms are governed by a collective bargaining agreement.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →