Application Security Manager (Product & AI Security)

15.5k - 22k PLN/ mies.UoP
SeniorFull-time·Umowa o pracę
#447403·Dodano wczoraj·0
Źródło: nofluffjobs.com
Aplikuj teraz

Tech Stack / Keywords

CybersecuritySecuritySDLCSASTDASTTestingCD pipelinesOWASPDevOpsSaaSAPICloudStakeholder managementAIrisk managementCloud securityAzureAWSGCPSonarQubeISODegreeCISSPCISMOSCPOSWEGIAC

Firma i stanowisko

At Grant Thornton Capability Center Poland (GTCC), employees contribute to meaningful work supporting operations of a multinational platform with over 25,000 professionals across 20+ firms. GTCC provides scale, coordination, and operational support to help teams work across markets and time zones, ensuring consistent delivery. The role is within GTCC Poland, located in Poznań, supporting the Grant Thornton Advisors multinational platform.

Wymagania

  • 8+ years of experience in Cybersecurity, Application Security, Product Security, Information Security, or related field.
  • Strong hands-on experience in Application Security/Product Security and Secure SDLC practices.
  • Experience with SAST, DAST, and SCA tools, including Veracode or comparable platforms.
  • Experience integrating application security testing into CI/CD pipelines and DevSecOps processes.
  • Understanding of application vulnerabilities, triage, remediation, risk prioritization, and exception management.
  • Experience conducting application security risk assessments, security architecture reviews, and application design reviews.
  • Knowledge of OWASP standards, especially OWASP ASVS, applied in product and application security assessments.
  • Experience working with Product, Engineering, DevOps, and Architecture teams across software lifecycle.
  • Experience conducting third-party/SaaS security assessments and reviewing vendor security evidence.
  • Strong understanding of modern application, API, integration, and cloud architectures.
  • Excellent stakeholder management, communication, and influencing skills.
  • Fluency in English and Polish.

Nice to have:

  • Experience with AI security assessments, AI governance, AI risk management, or agentic AI security.
  • Experience with threat modeling, API security, application security architecture, and risk assessment.
  • Knowledge of cloud security in Azure, AWS, or GCP.
  • Experience with tools such as Checkmarx, Fortify, Snyk, SonarQube, or equivalent SAST/DAST/SCA platforms.
  • Understanding of third-party security evidence and frameworks including SOC 1, SOC 2, ISO 27001, Trust Center reviews, and vendor security questionnaires.
  • Experience supporting M&A integration, application onboarding, or security integration of acquired technologies.
  • Ability to build scalable processes, metrics, dashboards, and reporting for leadership and governance.
  • Leadership, mentoring, and ownership mindset with ability to influence without authority.
  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering, or related discipline.
  • Preferred certifications: CISSP, CSSLP, CISM, OSCP, OSWE, CEH, GIAC, Azure, AWS, GCP Security certifications, or AI Security/Risk certifications.

Obowiązki

  • Own and manage application security processes and platforms, including Veracode or comparable SAST/DAST/SCA tools, application onboarding, scan configuration, reporting, and operational support.
  • Integrate security testing into CI/CD pipelines and promote Secure SDLC and DevSecOps practices.
  • Review, triage, and prioritize application security findings, define remediation guidance, and track vulnerabilities through closure.
  • Conduct application security risk assessments, architecture/design reviews, and security reviews of APIs, integrations, data flows, and controls.
  • Assess AI-enabled applications, AI use cases, and agentic AI solutions to identify security risks and mitigation actions.
  • Support AI Security Review Committee activities by reviewing proposed AI use cases and providing risk-based security recommendations.
  • Conduct third-party SaaS and technology product security assessments with TPRM, procurement, business, and vendor stakeholders.
  • Support cybersecurity integration of newly acquired/onboarded applications including application onboarding and remediation tracking.
  • Develop and maintain application security standards, processes, runbooks, metrics, dashboards, and leadership-level reporting.
  • Communicate security risks and recommendations clearly to technical, business, and executive stakeholders.

Benefity

  • Hybrid working model (2 days office, 3 days remote)
  • Stable employment with employment contract
  • Private medical care
  • Benefits package including MultiSport and benefits platform
  • Opportunity to work internationally with experienced experts
  • Culture of teamwork, trust, and knowledge sharing
  • Well-structured onboarding program
  • Clear career development paths
  • Access to learning and certification programs
  • Access to training platforms and tools
  • Inclusive workplace for people with disabilities
  • Modern office in Poznań (Malta Office Park)
  • Sport subscription
  • Free coffee
  • Bike parking
  • Mobile phone
  • In-house trainings
  • Training budget
Elastyczne godziny
Opieka zdrowotna
Karta sportowa
Dofinansowanie szkoleń
Szkolenia wewnętrzne
Telefon
Parking dla rowerów
Napoje w biurze
Grant Thornton Capability Center Poland

Grant Thornton Capability Center Poland

6 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj teraz