Lead Application Security Engineer
1 week ago
Description We are in search of a Lead Application Security Engineer to become a part of our team. The preferred candidate should possess a background in software development along with substantial experience in application security. In this role, you will be accountable for overseeing the application security program for a worldwide investment company. In addition to enhancing security practices, you will be required to conduct root-cause analyses on identified issues. It is a fully remote position offering you the flexibility to work from any location in Poland, whether it's your home or one of our well-equipped offices in Gdansk, Katowice, Krakow, Lodz, Warsaw, or Wroclaw. Responsibilities Oversee the Application Security program Conduct threat modeling activities Collaborate with teams to prioritize issues and provide explanations regarding the nature of problems Manage processes such as remediation, mitigation, reporting, and cadence Address troubleshooting needs when tools encounter issues or when the team faces onboarding challenges Perform SAST, SCA, IaC, DAST, and API security scans on internally developed code using tools such as Checkmarx, CheckmarxOne, and SonarQube Evaluate scan results to distinguish between true positives and false positives Work closely with developers to understand results and determine optimal patch options Provide guidance on the intricacies of configuring pipelines in Azure DevOps (ADO) for automating the scanning process Requirements 5+ years of experience in Application Security Expertise in OWASP Top 10 Strong understanding of Security Programs Knowledge of Python, which would be considered as a plus Nice to have Familiarity and experience with scripting languages (Bash) Background in Vulnerability Management We offer We gather like-minded people: Engineering community of industry professionals Friendly team and enjoyable working environment Flexible schedule and opportunity to work remotely within Poland Chance to work abroad for up to 60 days annually Relocation within our 50+ offices We provide growth opportunities: Outstanding career roadmap Leadership development, career advising, soft skills, and well-being programs Certification (GCP, Azure, AWS) Unlimited access to LinkedIn Learning, Get Abstract, OReilly, Cloud Guru Language classes in English and Polish for foreigners We cover it all: Stable income (Employment Contract or B2B) Participation in the Employee Stock Purchase Plan Benefits package (health insurance, multisport, shopping vouchers) Strategically located offices featuring entertainment and relaxation zones, table tennis and football, free snacks, fantastic coffee, and more Referral bonuses Corporate, social and well-being events Please, note: The set of bonuses might vary based on the role you apply for specifics will be discussed with our recruiter during the general interview We will reach out to selected candidates exclusively EPAM is a leading global provider of digital platform engineering and development services. We are committed to having a positive impact on our customers, our employees, and our communities. We embrace a dynamic and inclusive culture. Here you will collaborate with multi-national teams, contribute to a myriad of innovative projects that deliver the most creative and cutting-edge solutions, and have an opportunity to continuously learn and grow. No matter where you are located, you will join a dedicated, creative, and diverse community that will help you discover your fullest potential.
-
Remote, Oregon, United States GuidePoint Security Full time $120,000 - $180,000 per yearGuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation's top organizations, such as Fortune 500 companies and U.S. government agencies,...
-
Senior Application Security Engineer
7 days ago
us remote Box Full timeWHAT IS BOX?Box is the world’s leading Content Cloud. We are trusted by more than 115K organizations around the world today, including nearly 70% of the Fortune 500 and leaders across deeply regulated industries (such as AstraZeneca, JLL, and Nationwide), to protect their data, fuel collaboration, and power critical workflows with secure, enterprise AI.By...
-
Data & Application Security Engineer
2 weeks ago
remote, us Louisiana-Pacific Corporation Full timeJob PurposeThe Data and Application Security Engineer will oversee and implement all aspects of data and information security for LP. This role will also serve in a support capacity for our third-party application stack, assisting in providing guidance for the data residing in these applications, and understanding the application’s inline security best...
-
Senior Application Security Engineer
4 days ago
us OpenSea Full timeOpenSea is the first and largest marketplace for NFTs, offering a diverse range of unique and verifiable digital assets backed by blockchain. We're excited about building a platform that supports a brand new economy based on true digital ownership and are proud to be recognized as ranked top private company.When hiring, we look for candidates who can thrive...
-
Application Security Lead
2 weeks ago
Remote, United States Accurate Background Full timeResponsibilities Manage and provide leadership to a team of security engineers, including hiring, training and performance management. Collaborate with Development & DevOps engineers to evaluate and operationalize security tools integrated in development environments. Collaborate with product managers, scrum masters, and application development to identify...
-
Senior Application Security Engineer
5 days ago
Remote, Oregon, United States Abnormal Full time $200,000 - $250,000 per yearAbout the RoleAbnormal AI is looking for a Senior Application Security Engineer to help build the next generation of secure AI-powered cybersecurity applications at scale. This is a senior IC-level role that blends deep application security expertise with strong engineering fundamentals. You'll focus on integrating security into every phase of our software...
-
Application Security Engineer
5 days ago
Remote, Oregon, United States VivSoft technologies Full time $120,000 - $140,000 per yearTitle: Application Security EngineerClearance Required: Public TrustLocation: Remote, USAPosition Type: Full-Time About the company:At VivSoft, we aim to solve complex federal problems using emerging and open technologies in a collaborative and rewarding environment. VivSoft is a diverse team of strategists, engineers, designers, and creators experienced in...
-
Software Engineer, Application Security
2 hours ago
Remote, Oregon, United States Eden Prescott Full time $180,000 - $220,000 per yearAbout the RoleOur client is seeking a Software Engineer specializing in Application Security to strengthen the security posture of their products and services. You'll play a key role in designing and scaling automated security solutions that protect applications from the ground up. This is a highly collaborative position, working alongside engineering,...
-
Application Security Architect
7 days ago
remote, us Epam Full timeDescription If you are looking for a high impact Application Security Architect role with a global leader in digital transformation, EPAM is the perfect next step in your career! As an EPAMer, youll have the opportunity to work with a supportive team, on a variety of interesting projects for some of the biggest brands in the world. Are you ready for the next...
-
Senior Application Security Engineer
4 days ago
Remote, Oregon, United States Rapport IT Services Full time $80,000 - $160,000 per yearEssential Functions:Engineers need to have strong development skills in either any one of Java, GoLang, Python AWS services, and possibly mobile application development.Hands-on development experience is crucial as this role requires active development involvement.Conduct security assessments on applications, including static and dynamic code analysis, to...