5 дней назад
Staff Product Security Engineer (Web Application Security)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Staff Product Security Engineer (Web Application Security): Building and maintaining security regression coverage for a cloud-based electronics design platform with an accent on threat modeling, API security, and OWASP Top 10 vulnerability discovery. Focus on manual and automated offensive testing, identifying business-logic flaws, integrating security checks into CI/CD, and validating remediation across multi-tenant cloud systems.
Location: Wrocław, Poland; onsite, remote work is not available
Competitive salary and benefits package; exact compensation is provided during the hiring process.
Company
A global software company within the Group, building Altium 365, a cloud platform for electronics design collaboration and product development.
What you will do
- Build and maintain security regression test suites for authentication, access control, APIs, data flows, and other critical application paths.
- Integrate security regression testing into CI/CD pipelines and define coverage targets for security-critical functionality.
- Lead threat-modeling sessions for existing components, new features, and architectural changes; identify attack surfaces, abuse cases, and trust boundaries.
- Conduct manual and automated offensive security testing, validate exploitability and business impact, and support remediation with engineering teams.
- Continuously assess the platform against the OWASP Top 10, including context-specific vulnerabilities, logic flaws, and abuse paths.
- Partner with engineering, architecture, and SRE/platform teams to scale secure-by-design practices through automation, reusable patterns, and security guidance.
Requirements
- 5+ years of experience in application or product security.
- Bachelor's degree or equivalent experience, including 12 years of professional experience.
- Hands-on experience with web application security testing, API security, threat modeling, manual penetration testing, and security regression testing.
- Deep understanding of the OWASP Top 10 and the ability to identify business-logic vulnerabilities.
- Strong knowledge of authentication, authorization, session management, multi-tenant architectures, and cloud-native systems.
- Ability to read and write code, integrate security into CI/CD, and collaborate with engineering teams on vulnerability remediation.
Nice to have
- Experience with SaaS or multi-tenant platforms, bug bounty programs, red teaming, or security automation frameworks.
- Knowledge of AWS and identity systems, including SSO and MFA.
Culture & Benefits
- Regular employment with a competitive benefits package alongside the salary.
- Opportunity to contribute to a global cloud software platform for electronics innovation.
- Collaboration across engineering, architecture, and SRE/platform functions.
- Work environment focused on innovation, global collaboration, and secure-by-design development.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →