Senior Application Security Engineer

Capital.comWarsaw, MazoviaHybridFull-timeSenior, 5–8 yearsListed 2 hours ago

Apply now

About this role

Responsibilities:

Security Architecture & Threat Modelling:

- Lead security architecture reviews and threat modelling for new and existing systems, using AI tools to make reviews faster, more consistent, and scalable across teams

- Act as a security force multiplier by influencing the standards, patterns, and guardrails that let teams move fast and stay secure

Security Automation & Tooling:

- Design, build, and automate scalable security processes that engineering teams can self-serve, covering secure design review, threat modelling, testing, and remediation workflows

- Integrate and automate security checks across the SDLC and CI/CD pipelines (SAST, DAST, SCA, secrets, and IaC scanning), tuned for strong signal and low friction

- Own and evolve security tooling such as DefectDojo and SAST, DAST, and SCA platforms, maximising automation, coverage, and integration

- Apply AI and LLM-based tooling to architecture review, threat modelling, code review, and vulnerability triage, and help define how the team adopts these tools safely

Security Testing & Vulnerability Management:

- Conduct and oversee security assessments of web and mobile applications, APIs, and cloud infrastructure, including manual testing and PoC development

- Run vulnerability scans across internal infrastructure and the external perimeter, then analyse findings, define remediation, and track issues to closure

- Support and triage the Bug Bounty Program and external vulnerability reports, automating triage where possible

- Participate in and help lead red teaming and offensive security exercises

Enablement:

- Drive knowledge sharing on secure development, mentor engineers, and deliver training for development and QA teams

Requirements:

Experience:

- 5+ years in application or product security, or equivalent depth, with a track record of senior or staff-level impact

- Demonstrable experience leading security architecture reviews and threat modelling (e.g. STRIDE, attack trees, data-flow analysis) across multiple teams or products

- Proven ability to automate and scale security processes by building tooling, integrations, and self-service workflows that reduce manual effort

Technical:

- Strong hands-on security testing skills, including code review and web, mobile, and API application security assessments, as well as the ability to triage and validate external vulnerability reports and bug bounty submissions

- Strong software engineering ability in at least one language (e.g. Python, Go, JavaScript), with the ability to build automation, not just scripts

- Deep understanding of the OWASP Top Ten, secure design, and secure coding best practices

- Experience with SAST, DAST, SCA, and vulnerability management platforms, and integrating them into CI/CD

- Strong understanding of modern application architectures: REST APIs, microservices, cloud-based systems, and containers

- Practical experience applying AI and LLM tooling to security work, or clear enthusiasm and aptitude to do so

Collaboration:

- Excellent communication and influencing skills: you can explain security concepts to technical and non-technical stakeholders and drive change without direct authority

- A self-starter who enjoys solving complex problems, building leverage through automation, mentoring others, and strengthening security culture

Nice to have:

- Experience securing the AI harness: hardening LLM and agent pipelines, prompts, tool and MCP integrations, and model endpoints against prompt injection, data leakage, and insecure agent actions

- Experience securing Kubernetes, including cluster hardening, RBAC, network policies, admission control, workload isolation, and image and supply-chain security

- Experience securing AWS infrastructure, including IAM, network and account architecture, key and secret management, and CSPM

- Experience building AI-assisted security tooling or internal self-service security platforms

- Experience mentoring or technically leading a security team

- Offensive or advanced security certifications such as OSAI, OSEP, OSCP, or OSWE

What you'll get in return:

- You will join the company, that cares about work and life balance

- Annual Bonus based on the performance review cycle

- Generous Annual Leave Policy

- Medical Insurance and Pension fund, with additional benefit packages based on the location

- Hybrid working model (3 days from our modern office and 2 days fully remotely)

- Comprehensive Workation Policy with 30 more remote days available.

- Possibility of taking two additional days of paid leave per year to dedicate to volunteering efforts.