Applications Engineer III (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Applications Engineer III (Cybersecurity): Driving the strategy, implementation, and maturity of the application security program with an accent on secure SDLC and CI/CD integration. Focus on scaling security across product teams, overseeing SAST/DAST tooling, and implementing secure coding practices.
Location: Hybrid in Warsaw, Poland
Salary: 145,196 – 223,379 PLN
Company
Brightstar is a global leader in lottery technology, providing secure retail and digital solutions to governments and regulators worldwide.
What you will do
- Drive the application security program, including tool selection, policy enforcement, and risk reporting.
- Integrate AppSec tooling (SAST, SCA, DAST, IaC scanning) into CI/CD pipelines for scalable security controls.
- Provide secure architectural guidance and design recommendations during the development planning phase.
- Partner with product teams to review threat models and triage high-impact vulnerabilities.
- Collaborate with GRC teams to ensure alignment with standards such as OWASP and FedRAMP.
- Mentor other AppSec engineers and champion a security-first development culture.
Requirements
- 5–10 years of experience in Application Security or Secure Software Development.
- Proven experience leading AppSec programs in CI/CD-heavy engineering environments.
- Deep expertise in securing cloud-native applications and tools like Semgrep, Mend, or GitHub Advanced Security.
- Hands-on experience with GitHub Actions, GitLab CI, or Jenkins.
- Knowledge of DAST tools (e.g., Tenable Web App Scanning) and Pentest methodologies (Burp Suite, Kali Linux).
- Experience with containers, microservices, and APIs in modern SDLC environments.
Nice to have
- Experience with IAST and runtime protections.
Culture & Benefits
- Comprehensive insurance package including health, life, and disability insurance.
- Paid time off and retirement benefits.
- Variety of well-being programs.
- Opportunities to participate in company-driven initiatives and employee networks.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →