Senior Application Security Testing Engineer
Remote, PolskaNajważniejsze cechy oferty
DevOps / Cloud: AWS, Azure, Docker, Kubernetes
Backend: Java / .NET / Node / Python
Model hybrydowy - część pracy zdalnie
Szukamy ekspertów - senior/ekspert
Pełny etat
Description
We are looking for a Senior Application Security Testing Engineer to join our ever-growing Security team. In this role, you will assess and strengthen the security posture of applications and systems, working closely with engineering teams to embed security best practices throughout the development lifecycle. Responsibilities Conduct regular scanning and manual security testing of web applications to identify vulnerabilities Track identified issues through to remediation, working closely with development teams to ensure timely fixes Perform code-level reviews to identify insecure coding practices and recommend improvements Support and strengthen IaaS security across cloud environments, with a particular focus on AWS Assess cloud configurations against security best practice and industry benchmarks Work within a hybrid cloud environment to implement and operate appropriate security technologies and controls Research emerging security threats, vulnerabilities, and exploit techniques relevant to the technology stack Respond promptly to newly identified threats and support the implementation of new security requirements Contribute to incident response activities as required, maintaining the confidentiality of all investigation information Provide technical guidance and oversight to developers on secure coding practices and application security standards Champion OWASP principles across the organization, embedding them into the design and development of new solutions Collaborate closely with cross-functional teams, contributing a security-first mindset to product and engineering discussions Requirements Bachelor's Degree, preferably in a technical discipline such as Information Systems, Computer Science, or a related field A minimum of 3 years' demonstrated experience in manual security testing Understanding of security protocols, cryptography, authentication, and authorization, along with general application security requirements Knowledge of at least one object-oriented programming language, such as Node.js or TypeScript Experience implementing and operating security technologies and processes within a hybrid cloud environment, particularly AWS Expertise in OWASP concepts and their practical application across varied solutions Understanding of IT operations and service support processes Excellent communication skills, with the ability to translate technical security concepts for non-technical stakeholders English proficiency at B2 level or higher Nice to have Relevant security certifications, such as CISSP, GIAC, CEH, Security+, or CSSLP Prior experience working within a fast-paced, product-led, or e-commerce technology environment Familiarity with automated security scanning and CI/CD pipeline integration
Requirements
Bachelor's Degree, preferably in a technical discipline such as Information Systems, Computer Science, or a related field
A minimum of 3 years' demonstrated experience in manual security testing
Understanding of security protocols, cryptography, authentication, and authorization, along with general application security requirements
Knowledge of at least one object-oriented programming language, such as Node.js or TypeScript
Experience implementing and operating security technologies and processes within a hybrid cloud environment, particularly AWS
Expertise in OWASP concepts and their practical application across varied solutions
Understanding of IT operations and service support processes
Excellent communication skills, with the ability to translate technical security concepts for non-technical stakeholders
English proficiency at B2 level or higher
Responsibilities
Conduct regular scanning and manual security testing of web applications to identify vulnerabilities
Track identified issues through to remediation, working closely with development teams to ensure timely fixes
Perform code-level reviews to identify insecure coding practices and recommend improvements
Support and strengthen IaaS security across cloud environments, with a particular focus on AWS
Assess cloud configurations against security best practice and industry benchmarks
Work within a hybrid cloud environment to implement and operate appropriate security technologies and controls
Research emerging security threats, vulnerabilities, and exploit techniques relevant to the technology stack
Respond promptly to newly identified threats and support the implementation of new security requirements
Contribute to incident response activities as required, maintaining the confidentiality of all investigation information
Provide technical guidance and oversight to developers on secure coding practices and application security standards
Champion OWASP principles across the organization, embedding them into the design and development of new solutions
Collaborate closely with cross-functional teams, contributing a security-first mindset to product and engineering discussions
Seniority
Senior
Nice to have
Relevant security certifications, such as CISSP, GIAC, CEH, Security+, or CSSLP
Prior experience working within a fast-paced, product-led, or e-commerce technology environment
Familiarity with automated security scanning and CI/CD pipeline integration
Słowa kluczowe / Umiejętności