Application Security Engineer
IT
Client Description:
Our client is a global technology company operating in the lottery sector and delivering secure retail and digital solutions for government and regulated customers worldwide. The company is establishing a new Application Security capability in Warsaw to strengthen secure software development across its cloud-native products.
We are looking for a hands-on Senior Application Security Engineer who will help develop and mature the Application Security programme across the software development lifecycle. You will work closely with Security, DevOps and engineering teams, provide secure architecture guidance and integrate scalable security controls into CI/CD workflows.
Candidate Profile:
• 5–10 years of experience in Application Security or secure software development.
• Experience supporting or developing an Application Security programme in a CI/CD-heavy engineering environment.
• Strong understanding of cloud-native applications, containers, microservices and APIs.
• Practical experience with SAST, SCA, DAST, secrets management and Infrastructure-as-Code scanning.
• Experience with CI/CD platforms such as GitHub Actions, GitLab CI or Jenkins.
• Familiarity with penetration-testing methodologies and tools such as Burp Suite or Kali Linux.
• Strong stakeholder communication, decision-making and cross-team collaboration skills.
• Ability to mentor others and take ownership of security initiatives.
• English at B2/C1 level and Polish language skills.
Responsibilities:
• Participate in developing the Application Security programme, including tooling, policies, developer engagement and risk reporting.
• Own integrations between Application Security tools and CI/CD pipelines.
• Provide secure design and architecture guidance throughout product development.
• Oversee the implementation and optimisation of SAST, SCA, secrets scanning, Infrastructure-as-Code scanning and DAST solutions.
• Partner with development teams on secure coding practices, threat modelling and vulnerability triage.
• Collaborate with GRC and compliance teams on requirements and standards, including OWASP and FedRAMP.
• Mentor and support Application Security engineers and help develop a security-first engineering culture.
• Evaluate IAST and runtime application protection capabilities.
• Develop meaningful Application Security KPIs and reporting.
Ref: JN-092026-1163339