Senior Application Security Engineer (Java)
Softserve โ Poland ยท Posted ~4 hours ago
๐ Log in to save this job, tailor your resume & track your apply process โ 7 days free, no card needed.
Log in to add to target listDescription
About The Role
In this role you will strengthen the organization's security posture by supporting and developing solutions in close collaboration with multiple development teams.
You will guide the SSDLC process on the client's side, working with development teams across all SSDLC stages โ especially the vulnerability management process (remediation recommendations and re-testing) โ and support solution design changes from a security perspective.
A development background in Java is required, with proficiency in C# (.NET), Go, or Perl considered a plus.
Responsibilities
Lead and grow the SSDLC together with the development teamReview code and lead the vulnerability management processAssess client security maturity and define improvement roadmaps at a strategic levelOwn the technical direction for embedding security into CI/CD pipelines and engineering workflows across multiple projectsGuide clients in adopting a risk-based vulnerability management processLead threat modeling and secure architecture workshopsDefine secure development standards and guardrails across projects and teamsDrive developer security adoption and awareness at scaleAct as a trusted advisor and thought leader in security transformation initiativesLead negotiations with clients to understand business and technical requirementsMentor development team members and support the bug discovery and fixing process
Requirements
5+ years of experience as an Application Security Engineer in SSDLC and application security assessment, including hands-on experience implementing Secure SDLC practices and leading or mentoring development teams within a product development environmentAdvanced skills in threat modeling, secure architecture reviews, and design-level security validationHands-on experience with SAST and DAST tools and their integration into CI/CD pipelinesFluency in modern cloud-native stacks (microservices, APIs, containers, Kubernetes, public cloud platforms)Comfortable reviewing source code in at least one of: Java, .NET (C#), GoLang, PerlStrategic mindset in aligning security architecture and initiatives with business priorities, delivery timelines, compliance requirements, and risk management strategyProven experience leading teams, mentoring engineers, and managing practice-level priorities and growthStrong influence in leading discussions with engineering managers, architects, and security leadershipFluent in spoken and written EnglishOSCP, OSWE, OSEP, OSCE, CREST, eCPPT, eCPTX, eWPT, or eWPTX certification (nice to have)
SoftServe is an equal opportunity employer.
Qualified applicants will receive consideration regardless of race, color, ancestry, ethnicity, national origin, religion, sex, sexual orientation, gender identity or expression, age, citizenship, disability, health condition, marital or family status, veteran status, or any other characteristic protected by applicable law.
We have 153,189 jobs that might be an even better fit for you
DontApply's real value goes far beyond a single job link or company name. Just upload your resume โ in under a minute we'll analyze all 153,189 jobs and tell you exactly which ones you should apply to right now.
Upload My Resume