Application Security Engineer

Emagine — Poland · Posted ~6 hours ago

Contract Remote

Skills

application security vulnerability assessment vulnerability remediation DefectDojo GitLab Ultimate SonarQube SCA secrets management DevOps security Power BI

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

Join a fully remote application security initiative focused on improving an organization's security posture. You will analyze vulnerabilities, coordinate remediation with development and technical leadership, support DevOps, establish secrets management practices, deploy software composition analysis capabilities, and build security dashboards.

Highlights

Fully remote, English-language security engineering assignment with a 12-month contract and extension potential. Drive vulnerability remediation, strengthen application security processes, support DevOps teams, and implement modern security tooling and reporting.

Description

PROJECT INFORMATION: Industry: telecommunication Remote work: 100% Project language: English Business trips: n/a Project length: 12 months contracts + prolongations. Start: ASAP / 1 month notice Assignment type: B2B Summary: This role aims to strengthen the organization's application security posture by analyzing existing vulnerabilities, driving their remediation, and implementing modern security processes and tools. Technical Environment: DefectDojo, GitLab Ultimate, SonarQube / SCA, Power BI. Responsibilities: Analyze the current state component by component using DefectDojo.Collaborate with development teams on vulnerability mitigation.Present a remediation plan in coordination with Tech Leads and security profiles.Drive the execution of the remediation plan.Provide technical support to the DevOps team.Define and implement secrets management procedures.Leverage GitLab Ultimate security features.Contribute to the deployment of SCA solutions (SonarQube).Set up Power BI dashboards for high-level security reporting.Produce reports for the security team and developers.Ensure visibility on the evolution of the security posture. Must Haves: Experience with vulnerability management tools (DefectDojo or equivalent).Knowledge of DevSecOps practices and CI/CD pipelines.Knowledge of secure secrets management procedures.Proficiency with GitLab and its security features.Familiarity with SCA and SAST tools (SonarQube).Reporting and data visualization skills (Power BI).Experience using Jira/Confluence.Experience with Agile Scrum methodology.Experience with OWASP security recommendations and NIS2 compliance.Proven experience with major development languages: Java, Angular, Python, Drupal, etc. Nice to Haves: Strong analytical and synthesis skills.Ability to collaborate with diverse technical teams.Ability to communicate security topics to non-experts.Autonomy and proactivity.