pracaon.plpracaon.pl

Senior Application Security Engineer

Remote, Polska
EPAM
Partner
сьогодні
Зарплата за домовленістю
Повна зайнятість • Дистанційна робота • IT, дані та AI

Основні характеристики вакансії

  • Потрібні спеціалісти - старший/експерт

  • Повний робочий день

  • Віддалена робота - без поїздок

Description

We are looking for a Senior Application Security Engineer to reduce security risk across web applications and APIs throughout the software development lifecycle. You will partner closely with engineering teams to assess application security, perform secure design and code reviews, validate and prioritize findings, and drive remediation to closure. This role focuses on practical application security outcomes: identifying real risk, reducing false positives, and helping teams build and ship secure software efficiently. Responsibilities Perform security assessments of web applications, APIs, services, and supporting components Facilitate threat modeling and review architectures and technical designs from a security perspective Conduct secure code reviews and identify vulnerabilities and insecure implementation patterns Validate findings from automated tools, reduce false positives, and prioritize issues based on exploitability and business impact Provide clear, actionable remediation guidance and secure implementation recommendations Track findings through remediation and retesting in collaboration with development teams Advise teams on authentication, authorization, session management, input validation, data protection, cryptography, secrets handling, and API security controls Contribute to secure SDLC practices, security standards, guidelines, and reusable security patterns Communicate security risks and recommendations to technical and non-technical stakeholders Requirements Hands-on experience in application security or product security Strong knowledge of web application and API security, including OWASP Top 10 and common vulnerability classes Practical experience with security assessments, secure design reviews, and/or secure code reviews Understanding of threat modeling and secure software design principles Strong knowledge of authentication, authorization, session management, input validation, cryptography, secrets handling, and data protection Proficiency in English at a B2+ level

Requirements

  • Hands-on experience in application security or product security

  • Strong knowledge of web application and API security, including OWASP Top 10 and common vulnerability classes

  • Practical experience with security assessments, secure design reviews, and/or secure code reviews

  • Understanding of threat modeling and secure software design principles

  • Strong knowledge of authentication, authorization, session management, input validation, cryptography, secrets handling, and data protection

  • Proficiency in English at a B2+ level

Responsibilities

  • Perform security assessments of web applications, APIs, services, and supporting components

  • Facilitate threat modeling and review architectures and technical designs from a security perspective

  • Conduct secure code reviews and identify vulnerabilities and insecure implementation patterns

  • Validate findings from automated tools, reduce false positives, and prioritize issues based on exploitability and business impact

  • Provide clear, actionable remediation guidance and secure implementation recommendations

  • Track findings through remediation and retesting in collaboration with development teams

  • Advise teams on authentication, authorization, session management, input validation, data protection, cryptography, secrets handling, and API security controls

  • Contribute to secure SDLC practices, security standards, guidelines, and reusable security patterns

  • Communicate security risks and recommendations to technical and non-technical stakeholders

Seniority

  • Senior

Ключові слова / Навички

Security.Development
Цю пропозицію імпортовано із зовнішнього порталу.Джерело оголошення

Більше схожих вакансій