
Application Security Engineer – Penetration Tester
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in Poland.
• Evaluate, validate, and prioritize security findings from SAST, SCA, and Secret scanning tools; eliminate false positives, assess risks, and monitor issues through to resolution.
• Execute manual and tool-assisted code reviews to detect security vulnerabilities, logical flaws, and insecure implementation choices prior to production deployment.
• Carry out hands-on penetration testing of web applications, microservices, and APIs.
• Conduct audits of REST and GraphQL APIs and web applications, concentrating on application security risks, as well as authentication, authorization, and business logic vulnerabilities.
• Minimum of 3 years of experience in Application Security, Product Security, or Penetration Testing.
• Practical experience in triaging and analyzing findings from tools such as Semgrep / OpenGrep, Gitleaks, Trivy, and OSV-Scanner.
• Proficiency with tools like Burp Suite (Pro), Nuclei, Subfinder, SQLmap, Metasploit, and NetExec.
• Comprehensive understanding of OWASP Top 10 vulnerabilities, including SQL injection, Command Injection, SSRF, Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), IDOR/BOLA, security misconfigurations, cryptographic failures, insecure deserialization, and mass assignment.
• Solid grasp of OWASP API Security Top 10 for REST and GraphQL architectures.
• In-depth knowledge of OAuth 2.0, OIDC, JWT, SAML, and RBAC/ABAC.
• Capability to identify complex authorization bypasses, session management issues, and business logic errors.
• Proficient in reading and analyzing modern application code to uncover security flaws.
• Basic understanding of AWS cloud security principles and Kubernetes security fundamentals.
• Practical approach to security and risk management.
• Intermediate proficiency in English, both spoken and written.
• Excellent communication skills for effective collaboration with engineering, product, and DevOps teams.
• Results-oriented mindset.
• Strong multitasking and time management abilities.
• Focus on Health & Wellness.
• Global Medical Coverage.
• Opportunities for Growth.
• Comprehensive Benefits Programs (compensation for gym, dental, psychological services, etc.).
• Performance-Driven Rewards.
• A Dynamic Work Environment.
Henkel
Pepperl+Fuchs Group
Win Systems
Intel Corporation
Get handpicked remote jobs straight to your inbox weekly.