Application Security Specialist (regular/senior) (She/He/They)
Tech Stack / Keywords
Firma i stanowisko
The Cyber Security team at Accenture Security supports organizations in building secure, resilient, and scalable security capabilities across complex enterprise technology landscapes. They act as trusted advisors to leading organizations across industries such as banking, manufacturing, healthcare, retail, and public sector, addressing complex security challenges and regulatory contexts. The team operates globally with a focus on embedding security into software development, cloud adoption, and digital transformation.
Wymagania
- Engineering or IT background with practical experience in software development, architecture, or IT operations.
- Foundational understanding of security principles including confidentiality, integrity, availability, encryption, hashing, and key management.
- Knowledge of software development lifecycle and experience engaging with development and engineering teams.
- Hands-on experience with DevOps and CI/CD platforms such as GitHub, GitLab, Azure DevOps, Bitbucket, or Jenkins.
- Practical experience with at least one public cloud platform: AWS, Azure, or GCP, including core services and security controls.
- Ability to read code and identify common vulnerabilities like SQL injection, XSS, command injection, and CSRF in languages such as Java, C#/.NET, JavaScript, Go, or Python.
- Professional proficiency in English and Polish (at least B2 level for both).
- Strong communication skills to translate technical findings into actionable recommendations.
- Proactive and ownership mindset with adaptability and commitment to continuous learning.
Nice to have:
- Experience with OWASP Top 10, OWASP ASVS, OWASP API Top 10, CWE Top 25, and secure coding best practices.
- Threat modelling experience considering business logic, architecture, and deployment.
- Knowledge of authentication and authorization standards like OAuth 2.0, OpenID Connect, and SAML.
- Experience with securing CI/CD pipelines, Infrastructure as Code, container platforms, and software supply chains including dependency scanning, SBOM, and SLSA.
- Experience securing AI-enabled applications and LLM-based systems.
- Use of AI-powered security tooling for code analysis and vulnerability detection.
- Knowledge of governance, risk, and compliance around AI security.
- Prior consulting or client-facing experience.
- Security certifications with willingness for co-financing certifications.
Obowiązki
- Assess client security posture using frameworks such as OWASP ASVS, OWASP Top 10, OWASP API Top 10, and CWE Top 25, creating prioritized roadmaps.
- Conduct threat modelling and secure design reviews with client architects and developers across various architecture styles including hybrid, cloud-native, containerized, microservices, event-driven, and monolithic systems.
- Review code, APIs, Infrastructure as Code, and CI/CD pipelines from a security perspective and assist teams in remediation.
- Select, implement, and tune Application Security tooling such as SAST, DAST, SCA, and secrets scanning to ensure effective security gating and automated testing.
- Address security of AI-enabled systems including LLM-based applications, AI agents, model and data pipelines, focusing on risks like prompt injection, data poisoning, and model exposure.
- Develop secure coding standards, design guidance, security champions programs, and conduct hands-on developer training.
- Present findings and recommendations to client teams and senior stakeholders including CISOs.
Benefity
- Permanent employment contract.
- Individual support from a People Lead and access to coaching.
- Extensive training package including soft skills, technical, language, GenAI training, e-learning platforms, and co-financing of courses and certifications.
- Employee Assistance Program offering legal, financial, and psychological consultations.
- Eligibility for Employee share purchase plan and quarterly dividends.
- Paid employee referral program.
- Private medical care and life insurance.
- Access to the Worksmile platform including the Multisport card.
Inne informacje
Accenture ensures equal employment opportunity regardless of race, religion, color, sex, age, disability, national origin, political beliefs, trade union membership, ethnicity, denomination, sexual orientation, or any other basis impermissible under Polish law. Consent is given by applicants for personal data processing under GDPR for recruitment purposes. Data is administered by Accenture sp. z o.o. in Warsaw, with rights for access, correction, deletion, restriction, objection, and data transfer as per applicable laws.
Accenture
194 aktywne oferty