Senior Application Security Engineer

Adecco — Poland · Posted ~11 hours ago

Senior Full-time Onsite Visa History ✓

Skills

Application Security Secure Software Development CI/CD Security Tool Integration Secure Architecture Cloud-Native Security Risk Reporting DevSecOps Cloud-Native Application Security Tools DevOps

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A global technology organization is building a new application security capability and is seeking a hands-on senior engineer to mature security across the software development lifecycle. You will guide secure architecture, integrate security tooling into CI/CD pipelines, develop policies and risk reporting, and partner with engineering and DevOps teams to make secure development scalable.

Highlights

Build and shape a new application security capability while working closely with security, DevOps, and engineering teams. The role offers strong technical ownership, influence over secure architecture, and the opportunity to embed scalable security practices across the software lifecycle.

Description

Our client is a global technology company operating in the lottery sector and delivering secure retail and digital solutions for government and regulated customers worldwide. The company is establishing a new Application Security capability in Warsaw to strengthen secure software development across its cloud-native products. ABOUT THE ROLE We are looking for a hands-on Senior Application Security Engineer who will help develop and mature the Application Security programme across the software development lifecycle. You will work closely with Security, DevOps and engineering teams, provide secure architecture guidance and integrate scalable security controls into CI/CD workflows. KEY RESPONSIBILITIES • Participate in developing the Application Security programme, including tooling, policies, developer engagement and risk reporting. • Own integrations between Application Security tools and CI/CD pipelines. • Provide secure design and architecture guidance throughout product development. • Oversee the implementation and optimisation of SAST, SCA, secrets scanning, Infrastructure-as-Code scanning and DAST solutions. • Partner with development teams on secure coding practices, threat modelling and vulnerability triage. • Collaborate with GRC and compliance teams on requirements and standards, including OWASP and FedRAMP. • Mentor and support Application Security engineers and help develop a security-first engineering culture. • Evaluate IAST and runtime application protection capabilities. • Develop meaningful Application Security KPIs and reporting. CANDIDATE PROFILE • 5–10 years of experience in Application Security or secure software development. • Experience supporting or developing an Application Security programme in a CI/CD-heavy engineering environment. • Strong understanding of cloud-native applications, containers, microservices and APIs. • Practical experience with SAST, SCA, DAST, secrets management and Infrastructure-as-Code scanning. • Experience with CI/CD platforms such as GitHub Actions, GitLab CI or Jenkins. • Familiarity with penetration-testing methodologies and tools such as Burp Suite or Kali Linux. • Strong stakeholder communication, decision-making and cross-team collaboration skills. • Ability to mentor others and take ownership of security initiatives. • English at B2/C1 level and Polish language skills. Nice to have • Experience with IAST or runtime application protection. • Knowledge of tools such as Semgrep, Mend, GitHub Advanced Security or HCL AppScan. WHAT IS OFFERED • Employment contract directly with the client. • Hybrid work in Warsaw, with 50% of working time from the office. • Private medical care for the employee. • Employer-funded life insurance. • Flexible start between 7:00 and 10:00. • Three-month probation period followed by an indefinite employment contract.