Mid Cybersecurity Engineer - AppSec/SecDev
⚲ Warszawa, Wola
Do uzgodnienia
Opis stanowiska
Nasze wymagania:
Proven track record in deep-dive manual penetration testing of web/mobile applications, APIs and AI-driven features, alongside strong secure code review skills.
Solid understanding of financial tech security standards and regulations, including PCI-DSS, PSD3/DORA, OWASP Top 10 (and API Top 10), and secure data handling (PII/banking data protection).
Practical experience embedding security into the SDLC. Ability to analyze software architectures, review new feature proposals, and lead threat modeling sessions to ensure security controls are integrated from day one.
Hands-on experience designing, tuning, and deploying SAST, DAST, and SCA solutions inside fast-paced CI/CD pipelines without blocking deployment velocity.
Strong ability to independently triage, risk-score, and manage vulnerabilities across APIs, microservices, and financial infrastructure.
Familiarity with microservices architectures, cloud environment security, containerization, and secure system configuration.
A self-starter mindset with the ability to take full ownership of tasks, estimate effort, and clearly communicate actionable security guidance to engineering and product teams.
O projekcie:
Flexible working hours in the hybrid model (4/1) - working hours start between 7:00 a.m. and 9:00 a.m. We also have 30 days of occasional remote work.
Annual bonus based on your annual performance and company results.
Our team is based in Warsaw and Poznań.
Zakres obowiązków:
Design, execute, and report manual and automated security tests across APIs, microservices, and fintech infrastructure, identifying vulnerabilities and assessing business risks.
Manage the vulnerability lifecycle from identification and risk-scoring (tailored to financial impact) to tracking remediation with engineering teams.
Review architectural designs and new financial feature proposals, serving as the main security liaison for engineering teams and driving collaborative threat modeling sessions.
Support DevSecOps practices by integrating and fine-tuning automated security mechanisms (SAST/DAST/SCA) into the CI/CD pipeline, reducing technical debt while maintaining release velocity.
Support the development of the secure system configurations, monitor cloud applications, and preventive measures against emerging fintech threat vectors.
Collaborate with product and tech teams, consulting on security-enhancing solutions and verifying their implementation.
Partner closely with product and tech teams during ceremonies (design, grooming) to consult on security-enhancing solutions and verify their successful implementation.
Take ownership of impactful security initiatives from design through delivery, providing clear estimates, prioritization, and independent problem resolution.
Contribute to raising the team’s security maturity by creating documentation, hosting knowledge-sharing sessions, mentoring newcomers, and supporting the technical hiring process.
Oferujemy:
Well-located offices (with e.g. fully equipped kitchens, bicycle parking, terraces full of greenery) and excellent work tools (e.g., raised desks, ergonomic chairs, interactive conference rooms).
A 16" or 14" MacBook Pro or corresponding Dell with Windows (if you don't like Macs) and all the necessary accessories.
A wide selection of fringe benefits in a cafeteria plan - you choose what you like (e.g., medical, sports or lunch packages, insurance, purchase vouchers).
English classes that we pay for related to the specific nature of your job.
A training budget, inter-team tourism (see more here), hackathons, and an internal learning platform where you will find multiple trainings.
An additional day off for volunteering, which you can use alone, with a team, or with a larger group of people connected by a common goal.
Social events for Allegro people - Spin Kilometers, Family Day, Fat Thursday, Advent of Code, and many other occasions we enjoy.
Proven track record in deep-dive manual penetration testing of web/mobile applications, APIs and AI-driven features, alongside strong secure code review skills.
Solid understanding of financial tech security standards and regulations, including PCI-DSS, PSD3/DORA, OWASP Top 10 (and API Top 10), and secure data handling (PII/banking data protection).
Practical experience embedding security into the SDLC. Ability to analyze software architectures, review new feature proposals, and lead threat modeling sessions to ensure security controls are integrated from day one.
Hands-on experience designing, tuning, and deploying SAST, DAST, and SCA solutions inside fast-paced CI/CD pipelines without blocking deployment velocity.
Strong ability to independently triage, risk-score, and manage vulnerabilities across APIs, microservices, and financial infrastructure.
Familiarity with microservices architectures, cloud environment security, containerization, and secure system configuration.
A self-starter mindset with the ability to take full ownership of tasks, estimate effort, and clearly communicate actionable security guidance to engineering and product teams.
O projekcie:
Flexible working hours in the hybrid model (4/1) - working hours start between 7:00 a.m. and 9:00 a.m. We also have 30 days of occasional remote work.
Annual bonus based on your annual performance and company results.
Our team is based in Warsaw and Poznań.
Zakres obowiązków:
Design, execute, and report manual and automated security tests across APIs, microservices, and fintech infrastructure, identifying vulnerabilities and assessing business risks.
Manage the vulnerability lifecycle from identification and risk-scoring (tailored to financial impact) to tracking remediation with engineering teams.
Review architectural designs and new financial feature proposals, serving as the main security liaison for engineering teams and driving collaborative threat modeling sessions.
Support DevSecOps practices by integrating and fine-tuning automated security mechanisms (SAST/DAST/SCA) into the CI/CD pipeline, reducing technical debt while maintaining release velocity.
Support the development of the secure system configurations, monitor cloud applications, and preventive measures against emerging fintech threat vectors.
Collaborate with product and tech teams, consulting on security-enhancing solutions and verifying their implementation.
Partner closely with product and tech teams during ceremonies (design, grooming) to consult on security-enhancing solutions and verify their successful implementation.
Take ownership of impactful security initiatives from design through delivery, providing clear estimates, prioritization, and independent problem resolution.
Contribute to raising the team’s security maturity by creating documentation, hosting knowledge-sharing sessions, mentoring newcomers, and supporting the technical hiring process.
Oferujemy:
Well-located offices (with e.g. fully equipped kitchens, bicycle parking, terraces full of greenery) and excellent work tools (e.g., raised desks, ergonomic chairs, interactive conference rooms).
A 16" or 14" MacBook Pro or corresponding Dell with Windows (if you don't like Macs) and all the necessary accessories.
A wide selection of fringe benefits in a cafeteria plan - you choose what you like (e.g., medical, sports or lunch packages, insurance, purchase vouchers).
English classes that we pay for related to the specific nature of your job.
A training budget, inter-team tourism (see more here), hackathons, and an internal learning platform where you will find multiple trainings.
An additional day off for volunteering, which you can use alone, with a team, or with a larger group of people connected by a common goal.
Social events for Allegro people - Spin Kilometers, Family Day, Fat Thursday, Advent of Code, and many other occasions we enjoy.
🔍 Dekoder Ogłoszenia
🔴
Proven track record in deep-dive manual penetration testing of web/mobile applications, APIs and AI-driven features, alongside strong secure code review skills.
Oczekują od Ciebie samodzielnego przeprowadzania zaawansowanych testów penetracyjnych i przeglądów kodu, co może oznaczać dużą odpowiedzialność i konieczność wykazywania się szeroką wiedzą techniczną.
🔴
Practical experience embedding security into the SDLC. Ability to analyze software architectures, review new feature proposals, and lead threat modeling sessions to ensure security controls are integrated from day one.
Oznacza to, że będziesz musiał aktywnie wpływać na proces tworzenia oprogramowania od samego początku, co może wymagać dużej asertywności i umiejętności przekonywania innych zespołów.
🔴
Hands-on experience designing, tuning, and deploying SAST, DAST, and SCA solutions inside fast-paced CI/CD pipelines without blocking deployment velocity.
Wymagają od Ciebie nie tylko znajomości narzędzi, ale także umiejętności ich integracji w sposób, który nie spowalnia procesu wdrażania, co może być technicznie wymagające i czasochłonne.
🔴
A self-starter mindset with the ability to take full ownership of tasks, estimate effort, and clearly communicate actionable security guidance to engineering and product teams.
Oczekują od Ciebie samodzielności i przejmowania pełnej odpowiedzialności, co może oznaczać brak ścisłego nadzoru i konieczność samodzielnego rozwiązywania problemów.
🟡
Flexible working hours in the hybrid model (4/1) - working hours start between 7:00 a.m. and 9:00 a.m. We also have 30 days of occasional remote work.
Elastyczne godziny pracy mogą oznaczać konieczność dostosowania się do potrzeb zespołu lub projektu, a 30 dni zdalnej pracy może być rozłożone w sposób, który nie zawsze jest w pełni dogodny.