Application Security Engineer (SAST / DAST / SCA + Pentest) - Mid
Tech Stack / Keywords
Firma i stanowisko
CyCommSec is a Warsaw-based cybersecurity company operating since 2015, certified ISO/IEC 27001:2022. They provide penetration testing, vulnerability management as a service (VMaaS), SOC / MDR, NIS2 / DORA advisory, and ISO 27001 and ISO 42001 audits for banks, insurers, e-commerce, industry, and energy sectors in Poland and abroad. A related company, GET FuseAI, develops an autonomous penetration testing platform based on LLM agents used in this program. The program team consists of about 15 specialists including pentesters, AppSec analysts, DevSecOps engineers, AI red team members, threat modeling experts, and PMO.
Wymagania
- Over 3 years of experience in application security, DevSecOps, or penetration testing, with practical use of at least two of three tool classes: SAST, DAST, SCA from any vendor.
- Ability to read code to confirm or reject SAST findings and suggest fixes in at least one of: C# / .NET, Java, JavaScript / TypeScript, Python.
- Familiarity with OWASP Top 10, API Security Top 10, ASVS, WSTG, and CWE as daily tools.
- Knowledge of CI/CD (Azure DevOps, GitLab CI, or GitHub Actions), containers, and Kubernetes, understanding scan boundaries and basic Azure services (Entra ID, APIM, Application Gateway / WAF).
- Discipline in ticketing and evidence management: SLA adherence, complete evidence, updated status, client data access only via designated secure environments (VDI → PAM → jump host).
- English proficiency at least B2+ in writing and speaking for reports and client meetings.
- Willingness to attend morning meetings aligned with client timezone (Persian Gulf, +2h CET), sign NDA, and pass standard client verification.
Obowiązki
- Conduct security assessments of web, API, and container applications from triage through documentation analysis (SDD / HLD), reporting, and closure notes in English.
- Execute SAST scans using Fortify SSC / ScanCentral and SCA scans using Black Duck, Sonatype in client Azure DevOps pipelines or locally.
- Configure and perform authenticated DAST scans with Burp Suite Professional, OpenText DAST / WebInspect, and support IAST (Seeker) where deployed.
- Validate scan results by confirming or rejecting findings, filtering false positives, setting severity and CWE, and enforce "Medium and Above" go-live gate with evidence in ASPM.
- Perform manual pentesting on authorization (IDOR / BOLA), authentication (OAuth2 / OIDC, JWT), business logic, file uploads, and admin panels.
- Review container image vulnerability scan results (Prisma Cloud Compute) and infrastructure vulnerabilities (Tenable) affecting go-live decisions.
- Defend findings with application owners and developers in English, conduct retests after remediation, and maintain accurate status.
- Automate repetitive tasks with scripts for processing results, API integrations, AI agent skills and connectors, and create runbooks in team knowledge base.
Benefity
- Salary 16,000 – 22,000 PLN net + VAT per month (B2B), depending on experience; ongoing multi-year program with stable workload.
- Remote work from Poland with occasional business trips to Abu Dhabi covered by the company.
- Access to enterprise licenses including Fortify, Black Duck, Burp Suite Pro, Prisma Cloud, ASPM with real impact on national-scale system go-live.
- A knowledgeable team including pentesters, AI red team, DevSecOps architects, and threat modeling specialists; senior review of reports; internal knowledge base and runbooks.
- Daily use and co-creation of AI-assisted DevSecOps with LLM agents on the FuseAI platform.
- Flexible working hours outside of client meeting rhythms; clear career path to senior or team lead for SAST, DAST, SCA lanes.
- Benefits: flexible working hours.
Inne informacje
Data controller is CYCOMMSEC sp. z o.o. based in Warsaw, processing recruitment data in compliance with GDPR including mandatory and voluntary data, retention periods, and rights according to the Privacy Policy. No profiling is performed.
CYCOMMSEC
7 aktywnych ofert