Application Security Engineer (F/M)
160 - 215 PLN/ godz.B2B
MidFull-time·B2B
#442941·Dodano wczoraj·0
Źródło: nofluffjobs.comTech Stack / Keywords
OWASPWeb applicationsREST APISASTDASTAPISecurityTestingCD pipelines.NETAngularJavaScriptTypeScriptStakeholder management
Firma i stanowisko
AXA IT Solutions is an internal software house operating within the international insurance group AXA. We provide IT solutions for the needs of AXA companies in Europe. We work in English on a daily basis, in close-knit teams, carrying out international development projects.
Wymagania
- Strong practical knowledge of the OWASP Top 10 and common web application attack vectors.
- Deep understanding of securing modern web applications, REST APIs, authentication and authorisation mechanisms (OAuth2, OIDC, JWT).
- Experience implementing and managing SAST, DAST, SCA, API security and penetration testing programmes.
- Experience automating security controls within CI/CD pipelines and software delivery processes.
- Strong knowledge of secure software engineering practices and secure-by-design principles.
- Experience with .NET, Angular, JavaScript, and TypeScript.
- Ability to identify strategic security improvements beyond vulnerability remediation.
- Strong stakeholder management skills to influence development teams, architects, and security functions.
- Highly motivated, enthusiastic, and capable of working independently and collaboratively.
- Exceptional analytical and problem-solving skills, attention to detail, and a business-focused approach.
- Strong interpersonal skills for effective communication in fast-paced environments.
- Creativity and resourcefulness in addressing complex security challenges.
Obowiązki
- Own and continuously improve the application security posture, embedding security throughout the SDLC.
- Monitor, assess, prioritise, and manage vulnerabilities from penetration testing, SAST, DAST, dependency scanning, bug bounty programmes, and other security assessments, ensuring remediation within agreed SLAs.
- Triage security findings, assess business risk, identify false positives, and provide clear technical justification for decisions.
- Design and implement scalable security controls, automation, and preventative measures to reduce recurring vulnerabilities and manual remediation.
- Drive a shift-left security approach by integrating automated security testing, policies, and secure development practices into CI/CD pipelines.
- Act as the primary liaison with external penetration testing providers and partner with Group Security on vulnerability management, risk ratings, and remediation requirements.
- Provide expert guidance on securing web applications, APIs, authentication, and cloud-native architectures, particularly .NET and Angular solutions.
- Act as the Application Security SME, promoting secure-by-default design principles across solution delivery.
- Maintain application security standards, policies, and processes aligned with OWASP, NIST, and industry best practices.
- Monitor emerging threats, OWASP trends, attack techniques, and security tooling to address evolving application security risks.
- Deliver secure coding guidance and security awareness to developers, technical leads, architects, and delivery teams.
- Report on application security posture, vulnerability trends, remediation performance, and risk reduction to governance and steering groups.
Benefity
- The opportunity to influence technological solutions and product direction in an international financial organization.
- Ambitious projects with a high degree of autonomy and responsibility.
- A stable, long-term assignment with flexible working hours and a hybrid work model.
Elastyczne godziny
Karta sportowa
Dofinansowanie szkoleń
Opieka zdrowotna
Spotkania integracyjne
Napoje w biurze
Parking dla aut
Parking dla rowerów
Chill room
AXA Avanssur SA Spółka Akcyjna Oddział II w Polsce
4 aktywne oferty