Security Engineer
We are looking for an experienced Application Security Engineer or Penetration Tester to help strengthen the security of our web and mobile applications.
This is a hands-on role that combines penetration testing, secure code review, security engineering, and collaboration with development teams. You will identify real security risks, recommend practical solutions, and help integrate security throughout the software development lifecycle.
Main responsibilities
- Plan, coordinate, and perform penetration tests of web and mobile applications;
- Conduct infrastructure security assessments and security audits.
- Identify vulnerabilities, threats, and security risks affecting web and mobile applications;
- Clearly communicate identified vulnerabilities, their business impact, and recommended remediation actions;
- Evaluate, recommend, and implement security solutions for web and mobile applications;
- Perform secure code reviews and provide practical guidance to development teams;
- Analyze security events and monitor the security posture of applications;
- Implement and maintain security standards and controls within the Secure Software Development Life Cycle;
- Integrate application security tools and security testing into CI/CD pipelines;
- Investigate security incidents and recommend remediation and preventive measures;
- Deliver training and awareness sessions on secure software development practices;
- Work closely with developers, engineering teams, and other stakeholders to improve application security.
Must-have requirements
- At least three years of professional experience as a Penetration Tester, Application Security Engineer, or Security Engineer;
- Hands-on experience conducting penetration tests of web and mobile applications;
- Experience identifying, validating, and assessing the impact of application security vulnerabilities;
- Ability to explain vulnerabilities, risks, and remediation recommendations to both technical and non-technical stakeholders;
- Practical experience performing secure code reviews;
- Basic proficiency in at least one programming language, such as C#, Python, or JavaScript;
- Strong understanding of the Software Development Life Cycle;
- Hands-on experience implementing or maintaining application security tools, including:
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Software Composition Analysis (SCA)
- Familiarity with integrating security controls and testing tools into CI/CD pipelines and Secure SDLC processes;
- Professional proficiency in Ukrainian and English at B2 level or higher.
- Strong analytical, communication, and problem-solving skills.
Nice to have
- Knowledge of security risks related to artificial intelligence and large language models;
- Hands-on experience testing or securing AI- and LLM-based solutions;
- Knowledge of Polish.
This role gives you the opportunity to combine offensive security skills with practical security engineering. You will not only identify vulnerabilities but also help teams fix them, improve development processes, and build more secure products from the start.
You will work across penetration testing, secure code review, security tooling, CI/CD, and Secure SDLC. If you enjoy solving complex security challenges and working closely with development teams, we would be happy to hear from you.