Application Security Engineer

Pepsico — Poland · Posted ~12 hours ago

Visa History ✓

Skills

Application security SAST SCA Secrets scanning DAST API security Security finding triage Vulnerability management Security remediation Backend automation CI/CD security integration API Security CI/CD

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

An application security engineer will help reduce security risk across enterprise applications and APIs. The role focuses heavily on SAST, SCA, secrets detection, DAST, and API security, including tool operation and tuning, manual finding triage, developer remediation support, vulnerability management, and backend automation integrated with CI/CD workflows.

Highlights

Security engineering role with strong exposure to application and API security, automated scanning, vulnerability triage, developer remediation, and security workflow automation. The position also provides opportunities to contribute to mobile application security.

Description

Overview PepsiCo’s Global Application Security Program partners with development teams to identify and reduce security risk across enterprise applications and APIs. Approximately 80% of this role focuses on SAST/SCA/Secrets/DAST and API security scanning technology. The engineer will support the operation and tuning of tools, manually triage security findings, perform targeted reviews using established procedures, assist developers with remediation, and manage findings through centralized vulnerability-management workflows. The engineer will also help develop and maintain backend automation that initiates scans, monitors scan status, processes results, handles common failures, and integrates security tools into CI/CD and developer workflows. The remaining capacity will support mobile application-security tooling and integrations as needed. Working knowledge of mobile security reviews is preferred but not required. This may include assisting with specific mobile-application security tooling scanning automation and CI/CD integrations under the guidance of senior engineers. Responsibilities Operate and support SAST/SCA/Secret/DAST and API security scanning tools.Review, validate, and manually triage security findings, identify false positives, reproduce common issues, assess potential impact, and escalate complex findings when appropriate.Perform targeted web application and API security reviews using established tools, standards, procedures, and test cases.Assist with configuring and tuning SAST/SCA and Secret rules, policies, exclusions, severity mappings, and quality gates.Assist with configuring DAST and API scan profiles, authentication workflows, crawl settings, scan scopes, schedules, and policies.Support the integration of security tools into source-control, pull-request, build, CI/CD, ticketing, and developer workflows.Contribute to backend scanning automation that initiates scans, monitors scan state, handles retries, retrieves results, and routes findings to downstream systems.Process findings through centralized application-security or vulnerability-management platforms, including normalization, deduplication, ownership assignment, remediation tracking, suppression, and exception workflows.Provide developers with clear remediation guidance and support validation and tracking of vulnerabilities through closure.Monitor scan execution and integration health, troubleshoot common authentication, connectivity, configuration, timeout, and result-processing issues, and escalate platform problems as needed.As needed, support mobile security finding triage and tooling, including assisting with backend automation and CI/CD integrations for mobile security scans.Document findings, remediation guidance, scan configurations, integration procedures, troubleshooting steps, metrics, and operational activities while participating in Agile ceremonies and team support processes.Support team incident rotation through on-call hours, including weekends and holidays as needed. Qualifications Years of Experience Bachelor’s degree in Computer Science, Engineering, or a related technical field, with 1-3 years of relevant professional experience in application security, security engineering, secure software development, or vulnerability management. Mandatory Technical Skills Foundational understanding of web application, mobile application, and API security concepts.Experience with or exposure to SAST/SCA and Secret, including rules, policies, findings, exclusions, and CI/CD integrations.Experience with or exposure to DAST and API scanning platforms, including scan configuration, scope management, authenticated scanning, and finding review.Experience manually reviewing and triaging SAST/SCA/Secret, DAST, Mobile, and API-security findings.Ability to reproduce common findings, recognize likely false positives, gather supporting evidence, and document remediation recommendations.Familiarity with web, mobile and API testing tools such as Burp Suite, Postman, MobSF, curl, browser developer tools, or comparable technologies.Familiarity with the OWASP Top 10 and common web vulnerabilities, including injection, cross-site scripting, broken access control, authentication weaknesses, SSRF, security misconfiguration, and sensitive-data exposure.Familiarity with the OWASP API Security Top 10, including BOLA/IDOR, broken authentication, authorization failures, resource-consumption issues, mass assignment, and API inventory weaknesses.Basic understanding of API authentication and authorization, including OAuth 2.0, OpenID Connect, JWT, API keys, service accounts, and role-based access control.Ability to read and understand application code written in at least one language such as Java, JavaScript, TypeScript, Python, Go, or C#.Experience working with centralized findings-management, ASPM, or vulnerability-management platforms.Familiarity with finding ingestion, normalization, deduplication, ownership assignment, remediation status, suppressions, exceptions, and SLA tracking.Exposure to GitHub, GitLab, Azure DevOps, Jenkins, or comparable source-control and CI/CD workflows.Basic scripting experience with Python, Go, PowerShell, or a comparable language.Familiarity with REST APIs, webhooks, JSON, command-line tools, and basic integration concepts.Familiarity with backend automation concepts such as scheduled jobs, workers, queues, polling, retries, timeouts, and result processing.Basic understanding of SAST, DAST, SCA, secrets detection, API security, Mobile security, SBOM, and related software supply-chain controls.Familiarity with cloud or container technologies such as AWS, Azure, GCP, Docker, or Kubernetes.Understanding of secure credential handling, service accounts, access controls, encryption, certificates, and audit logging.Ability to create clear technical documentation, findings summaries, remediation guidance, troubleshooting notes, and operational procedures. Non-technical Skills Strong written and verbal communication skills.High integrity with sound judgment and accountability.Excellent analytical, problem-solving, and critical thinking abilities.Self-motivated, curious, and committed to continuous learning, including willingness to skill up in mobile application security.Strong collaboration, relationship-building, and influencing skills.Comfortable working in a fast-paced, global environment with changing priorities and ambiguity.Ability to perform effectively under pressure. Differentiating Behaviors Demonstrates curiosity, innovation, and a continuous improvement mindset, including a willingness to develop mobile application security expertise.Makes sound decisions by balancing technical, business, and operational trade-offs.Remains calm, organized, and methodical in high-pressure situations.Effectively prioritizes work and manages competing commitments.