Senior Application Security Engineer @

21 hours ago


Warszawa, Mazovia, Czech Republic PepsiCo Full time

What will you bring to the team?  

  • Bachelor's degree in computer science, engineering, or a related field,
  • 6-7 years of recent and relevant experience, along with 2+ years of directly related software  engineering or development experience.
  • Extensive expertise in application security and vulnerability management, encompassing exploit  development, security research, and advanced security engineering.
  • Strong expertise in secure software development, including the identification and mitigation of  vulnerabilities at the source code level.
  • Practical experience with SAST, Secret Management, DAST, API security, SCA, and container  scanning tools.
  • Expertise in CI/CD pipeline security, encompassing supply chain security, integrity validation, and  secure artifact management.
  • Proficiency in conducting manual security assessments, which includes secure code review and  detection of logic flaws.
  • A comprehensive understanding of cryptography that includes effective key management, best  practices for encryption, and awareness of potential cryptographic failures.
  • A solid understanding of web and mobile application security vulnerabilities, such as the OWASP  Top 10, SSRF, RCE, deserialization attacks, and memory corruption exploits.
  • Experience in designing and implementing security hardening strategies for cloud-native  architectures on AWS, Azure, or GCP.
  • Advanced proficiency in API security, encompassing JWT validation, OAuth vulnerabilities, SSRF  protections, and server-side access control models.
  • Proficient in Infrastructure-as-Code security (Terraform, CloudFormation) and container security  (Kubernetes, Docker).
  • Practical experience in runtime security and eBPF-based security monitoring to identify and  address threats.
  • Knowledge of policy-as-code frameworks (OPA, HashiCorp Sentinel) for dynamically enforcing  security policies.
  • Proficient in scripting and automation using Python and/or Go.
  • Familiarity with binary exploitation techniques, reverse engineering, and vulnerability research.
  • Proficiency in WAF solutions like Imperva, Cloudflare, Akamai, AWS WAF, or Azure Front Door.
  • A strong understanding of CDN security, which encompasses bot mitigation, DDoS protection,  rate limiting, and caching strategies.
  • Experience tuning WAF rulesets, implementing anomaly detection, and automating WAF policy  enforcement.
  • Ability to evaluate and enhance CDN security measures to defend against web-based threats and  harmful payloads.

PepsiCo's Global Application Security Program harmonizes security with all development workflows to  identify and manage application security risks. Our mission is to ensure that security risks are visible and  actionable for the business, promoting prompt and effective resolution of security findings, empowering  our development teams to build securely by default, and fostering continuous improvement. 

This role emphasizes optimizing security tools, improving signal-to-noise ratios, and ensuring that  findings are prioritized and actionable without impeding development speed. The ideal candidate will  enhance security capabilities for thousands of developers by fine-tuning security signals, integrating risk based prioritization, and efficiently implementing automated security guardrails. 

Why should you join this team? 

  • you will have maximum autonomy & 100% ownership
  • this is a high-impact role which will affect all future applications at PepsiCo

How do we work and what do we offer? 

  • we work in a hybrid model (1 day per week from the office in Warsaw, Plac Konesera)
  • we offer a contract of employment
  • the most important benefits of this position: annual bonus, private healthcare, life insurance, Multisport,  private pension plan, employee assistance program, company car or equivalent

What are your daily tasks?  

  • Optimize and refine the settings for application security scanning to achieve a high signal-to noise ratio while producing actionable insights.
  • Establish, enforce, and continuously improve security standards for all application security  scanning tools to ensure consistency and effectiveness.
  • Develop and maintain risk-based prioritization models to identify and address critical  vulnerabilities first.
  • Create a system to assess false positives, refine rules, and guarantee overall scanner  effectiveness across all tools.
  • Collaborate with the AppSec Development team to seamlessly integrate the outputs of security  tools into centralized findings management.
  • Perform detailed analyses of scanner outputs, improving detection logic and removing  redundant or low-value findings.
  • Lead scalability efforts for security scanning, reducing developer friction while ensuring  comprehensive coverage.
  • Identify scanning gaps and implement enhancements to effectively address modern application  architectures, including APIs, containers, and cloud-native solutions.
  • Oversee the design, implementation, and optimization of the Web Application Firewall to  protect against web-based threats.
  • Establish strong CDN security measures, guaranteeing DDoS protection, bot mitigation, and  suitable caching controls.
  • Develop and implement security guardrails that facilitate secure software development with  minimal manual intervention.
  • Establish governance processes that ensure AppSec tools and practices align with business risks  and security goals.
  • Continuously assess the performance of security tools, optimizing investments for maximum risk  reduction.
  • Collaborate with development teams to integrate secure-by-default coding patterns and  architectural best practices.
  • Conduct focused security assessments of high-risk applications, pinpointing and addressing  scanning deficiencies before critical issues emerge.
  • Connect security findings to actual business risks, shaping security strategy and guiding  executive-level reporting.
  • Foster a security culture driven by data, utilizing metrics to direct and enhance security scanning  operations.
  • Mentor and guide junior engineers while promoting a culture of learning, growth, and technical  excellence.
  • Conduct technical design reviews, assess security tools, and facilitate architectural discussions to  enhance tool effectiveness.
  • Promote collaboration across development, platform, and security teams to enhance enterprise level security. 
,[] Requirements: Degree, Security, SAST, DAST, API, CD pipeline, Cryptography, OWASP, AWS, Azure, GCP, OAuth, Terraform, CloudFormation, Kubernetes, Docker, HashiCorp, Python, Go, Golang, WAF, Cloudflare, CDN Additionally: International projects, Private healthcare, Company car, Multisport, Modern office, No dress code, Free beverages, Free coffee.

  • Warszawa, Mazovia, Czech Republic PepsiCo Full time

    Job DescriptionWe are seeking a highly skilled Chief Application Security Architect to join our team at PepsiCo. In this role, you will be responsible for optimizing security tools, improving signal-to-noise ratios, and ensuring that findings are prioritized and actionable without impeding development speed.About the TeamPepsiCo's Global Application Security...


  • Warszawa, Mazovia, Czech Republic Strategic Staffing Solutions Full time

    Company Overview: At Strategic Staffing Solutions International (S3I), we pride ourselves on delivering high-quality talent to drive business success.Salary and Benefits: Our competitive salary range is 14,000 - 24,200 PLN per month, with additional benefits for B2B contractors based on experience level. A 6-month contract with possible extension provides...


  • Warszawa, Mazovia, Czech Republic AVENGA Full time

    Highly competent with SIEM Engineering and Detection EngineeringGood understanding and knowledge of common industry cyber securityframeworks, standards and methodologies, including; OWASP, MITRE ATT&CK and NIST is essentialAble to work in fast paced environmentsGreat written and oral communication skillsPassion for security and love to learn and grow...


  • Warszawa, Mazovia, Czech Republic DENTONS BUSINESS SERVICES EMEA Full time

    3+ years in Microsoft Infrastructure or Security Engineering roles.Strong interest in cybersecurity with a solid engineering background.Automation experience (e.g., PowerShell).Securing Windows platforms, Microsoft 365, and Azure.Knowledge of OS/cloud attack vectors, system hardening, and secure privilege escalation.Project delivery from initiation to...


  • Warszawa, Mazovia, Czech Republic ITDS Full time

    You're ideal for this role if you have a strong background in software development and security.We're looking for a highly skilled Secure Supply Chain Software Engineer to join our team. As a key member of our engineering team, you will be working on designing, building, and integrating security systems that protect applications across backend, frontend,...


  • Warszawa, Mazovia, Czech Republic ITDS Full time

    You're ideal for this role if you have:3+  years of industry experience as a programmer, developer, SWE, or similar roles.Expertise in at least one programming language: Golang, Java, or PythonKnowledge of Linux, Docker, Kubernetes, Terraform, and AWSExperience with DevOps and Infrastructure as Code (IAC) principlesUnderstanding of networking protocols such...


  • Warszawa, Mazovia, Czech Republic Devire Full time

    At Devire, we are committed to excellence in recruitment, outsourcing, and employer branding services. As a leading international company, we have been representing top employers on the European market for over 30 years, conducting comprehensive projects to find senior talent and implementing innovative IT solutions.We are seeking an experienced Senior...


  • Warszawa, Mazovia, Czech Republic Devire Full time

    10+ years of experience in software engineering, development, or similar roles.Broad knowledge of multiple programming languages, with deep expertise in at least one of Golang, Java, or Python.Familiarity with Linux, Docker, Kubernetes, Terraform, and AWS.Understanding of networking protocols (TCP, UDP, ICMP, ARP, DNS, TLS, HTTP, SSH, etc.).Experience with...


  • Warszawa, Mazovia, Czech Republic Strategic Staffing Solutions Full time

    SKILLS AND EXPERIENCE WE ARE LOOKING FOR3+ years of industry experience as a programmer, developer, SWE, or similar job roles. General knowledge of multiple languages, and in-depth knowledge of at least one of: Golang, Java, Python General knowledge of Linux, Docker, Kubernetes, Terraform, AWS Knowledgeable about networking (TCP, UDP, ICMP, ARP, DNS, TLS,...


  • Warszawa, Mazovia, Czech Republic T-Mobile Polska Full time

    We are seeking a highly experienced Senior Software Engineering Manager to lead our in-house software development teams at T-Mobile Polska. Our teams are responsible for delivering high-quality engineering solutions and driving innovation in the application supporting sales and care processes for individual clients.Key Responsibilities:Oversee the...


  • Warszawa, Mazovia, Czech Republic monday sp. z o.o. Full time

    Strong technical skills and a passion for developing features end-to-end (client and server).Experience building web applications and/or distributed systems from scratch.Understanding of product and a passion for building software that provides a great experience.Strive for excellence, biased for action and collaboration with team members.Team player, strong...


  • Warszawa, Mazovia, Czech Republic Falck Digital Technology Full time

    Company Overview: Falck Digital Technology is a global leader in healthcare and emergency response, dedicated to improving the well-being of people and saving lives.Job Description: We are seeking an experienced IAM Engineer to join our team in Warsaw. As a key member of our IT department, you will be responsible for designing, deploying, and maintaining IAM...


  • Warszawa, Mazovia, Czech Republic AVENGA Full time

    Job DescriptionWe are seeking an experienced Senior SecOps Engineer @ Avenga who will be responsible for overseeing the security operations of our cloud infrastructure, SaaS applications, and native mobile application. The ideal candidate will have a strong background in SIEM Engineering and Detection Engineering, as well as excellent communication...


  • Warszawa, Mazovia, Czech Republic Devire Full time

    We are looking for a seasoned Chief Security Architect to join our client's team and contribute to strengthening the software supply chain.This role focuses on ensuring that deployed code meets the highest security standards by combining third-party security tools with internally developed systems. We enhance the security of various codebases, including...


  • Warszawa, Mazovia, Czech Republic HUAWEI Full time

    At least 3 years of experience with Android OSDevelopment/maintenance experience in the following areas: finance (banking, payment), social media (chats, audio/video calls), multimedia (player, gallery)Experience in 3rd party application analysis: reverse engineering (APK Tool)Good command of Java/C/C++ (standard libraries)Knowledge of Gradle/Ant/Make...


  • Warszawa, Mazovia, Czech Republic Devire Full time

    Devire is an international company with a strong presence in the European market, specializing in recruitment, outsourcing, and employer branding services. For over 30 years, we have been representing leading employers and implementing innovative solutions in the IT sector.We are seeking a skilled Java Developer to join our dynamic technology team within the...


  • Warszawa, Mazovia, Czech Republic Strategic Staffing Solutions Full time

    About the Role:We are seeking a highly skilled Senior Cloud Infrastructure Developer to join our dynamic team in Warsaw. As a key member of our infrastructure team, you will be responsible for designing, developing, and maintaining infrastructure solutions using Python, AWS, and Terraform.Key Responsibilities:Design and implement scalable cloud...


  • Warszawa, Mazovia, Czech Republic Asana Full time

    About youExpertise in programming, distributed systems design, and infrastructureExperience building and operating scalable, reliable, and highly-available services4+ years designing and implementing production code for backend, infrastructure, and/or data systems2+ years mentoring/coaching other team members on design and execution of projectsEagerness to...


  • Warszawa, Mazovia, Czech Republic Citibank Europe PLC Full time

    Are you a seasoned technology leader looking to take on a new challenge in the world of finance?Citibank Europe PLC is seeking an experienced Senior Java Engineer Lead to join our team and help us drive innovation in our real-time systems.This is a unique opportunity to leverage your technical expertise and leadership skills to lead a small team of...


  • Warszawa, Mazovia, Czech Republic Ework Group Full time

    About Ework GroupWe are a dynamic team of experts in cloud technology, dedicated to delivering innovative solutions for our clients.Job DescriptionAs a Cloud Engineer at Ework Group, you will be responsible for designing, developing, and maintaining cloud-native applications and services on cloud platforms.You will work closely with engineers and other...