
Senior Application Security Engineer
Posted Jul 24

Posted Jul 24
This is a fully remote position, open to applicants in Poland, +1 more country.
• Collaborate with product teams during the design stage to facilitate threat modeling and risk assessment sessions, converting intricate security threats into clear, actionable security requirements.
• Conduct detailed manual code reviews on critical applications to uncover complex logical vulnerabilities as part of a white-box security evaluation.
• Plan, design, implement, automate, and optionally support AppSec tools.
• Contribute to the establishment of company-wide processes for secure code development and deployment.
• Prioritize identified security vulnerabilities, provide clear and actionable descriptions, and ensure that these findings are appropriately addressed and mitigated.
• Oversee the bug bounty program, collaborating with researchers and internal teams to resolve discovered vulnerabilities.
• Work alongside Dev/QA teams throughout the development lifecycle to improve the application's security posture by offering expert consulting, ongoing knowledge sharing, and actionable security guidance.
• A minimum of 5 years of experience in Application Security.
• Familiarity with secure development processes and best practices.
• Comprehensive understanding of web application security mechanisms (e.g., how the web operates, the significance of SOP, and the necessity of CORS and CSP).
• In-depth knowledge of common web application vulnerabilities (e.g., OWASP Top 10) and the most effective prevention strategies.
• Awareness of secure system/application architecture and design principles.
• Insight into modern threats faced by high-performance web applications utilized by millions of daily users.
• Knowledge of current authentication/authorization patterns (OAuth, OIDC, JWT, etc.).
• Practical hands-on experience in identifying vulnerabilities through security assessments and secure code reviews, combined with the capability to perform comprehensive root-cause analysis to drive systemic fixes.
• A university degree in Computer Science, Information Security, or a related field, or an equivalent blend of education and experience.
• Proficiency in English and Russian at an upper-intermediate level (B2+).
• Private health insurance.
• Sports benefits.
• Comprehensive Mental Health Program.
• Free online English lessons.
• Local language courses.
• Paid time off.
• Maternity leave support.
• Referral program rewards.
• Opportunities for upskilling, internal workshops, and participation in professional conferences and corporate events.
Avnet
Teradyne
Intetics
New Charter Technologies
Get handpicked remote jobs straight to your inbox weekly.