Application Security Engineer (F/M)
Tech Stack / Keywords
Firma i stanowisko
AXA IT Solutions is an international financial organization.
Wymagania
- Strong practical knowledge of the OWASP Top 10 and common web application attack vectors.
- Deep understanding of securing modern web applications, REST APIs, and authentication/authorization mechanisms (OAuth2, OIDC, JWT).
- Experience implementing and managing SAST, DAST, SCA, API security, and penetration testing programmes.
- Experience automating security controls within CI/CD pipelines and software delivery processes.
- Strong knowledge of secure software engineering practices and secure-by-design principles.
- Experience with .NET, Angular, JavaScript, and TypeScript.
- Ability to identify strategic security improvements beyond vulnerability remediation.
- Strong stakeholder management and communication skills.
- Highly motivated, team-oriented, and capable of working independently.
- Exceptional analytical and problem-solving skills with attention to detail.
- Creativity and resourcefulness in presenting solutions to complex security challenges.
Obowiązki
- Own and continuously improve the application security posture of internally developed solutions.
- Monitor, assess, prioritise, and manage application security vulnerabilities from multiple sources ensuring remediation within SLAs.
- Triage security findings to determine business risk and provide technical justification.
- Design and implement scalable security controls and automation to reduce vulnerabilities and manual intervention.
- Integrate automated security testing, policy enforcement, and secure development practices into CI/CD pipelines.
- Identify recurring vulnerability patterns and implement preventative controls and coding standards.
- Serve as liaison with external penetration testing providers ensuring timely and actionable assessments.
- Partner with Group Security teams to maintain shared vulnerability data and resolve disputes.
- Provide expert guidance on securing modern web applications, APIs, authentication mechanisms, with focus on .NET and Angular.
- Act as the Application Security expert promoting secure design principles and security-by-default practices.
- Maintain and enhance secure development standards, application security policies, and processes in line with OWASP, NIST and industry best practices.
- Monitor emerging threats, OWASP Top 10 trends, attack techniques, and security tooling innovations.
- Deliver security awareness and secure coding guidance to developers, technical leads, architects, and delivery teams.
- Update governance forums on application security posture, vulnerability trends, remediation performance, and risk initiatives.
Benefity
- Opportunity to influence technological solutions and product direction in an international financial organization.
- Ambitious projects with high autonomy and responsibility.
- Stable, long-term assignment with flexible working hours.
- Hybrid work model.
Inne informacje
Na podstawie art. 13 ust. 1 i 2 Rozporządzenia Parlamentu Europejskiego i Rady (UE) 2016/679 z dnia 27 kwietnia 2016 r. w sprawie ochrony osób fizycznych w związku z przetwarzaniem danych osobowych i w sprawie swobodnego przepływu takich danych oraz uchylenia dyrektywy 95/46/WE (ogólne rozporządzenie o ochronie danych) z dnia 27 kwietnia 2016 r. w związku z art. 221 § 1 oraz art. 222 §1 Kodeksu pracy, informujemy, iż administrator danych tak jak opisano w ogłoszeniu. Pana/Pani dane nie będą przekazywane do innych państw ani do organizacji międzynarodowych, nie będą wykorzystywane w procesach automatycznego przetwarzania danych, w szczególności do profilowania.
AXA IT Solutions
2 aktywne oferty