GetGlobalJob

Application Security Architect

Capital · Warsaw, Mazowieckie, Poland | Sofia City +2

Hybrid
Apply on the original site ↗Sign in to save

Sign in and upload your CV to see how well you match this job.

Sign in

Job overview

Location
Warsaw, Mazowieckie, Poland | Sofia City +2
Workplace
Hybrid
Date posted
Sep 29, 2026
Last checked at the source
Oct 11, 2026
Job source
Company's official careers site

Responsibilities

Security Architecture & Standards: • Define and maintain secure-by-default reference architectures for common patterns: web apps, mobile backends, microservices, public and partner APIs, and event-driven services • Own core application security architecture decisions: authentication and authorisation, session management, API security, secrets management, multi-tenant isolation, and security logging and auditing • Lead the redesign of user authentication and the delivery of security features into the product • Develop and roll out application security standards, secure-coding guidelines, configuration standards, reusable design patterns, and architecture decision records (ADRs) that engineers can apply without a security expert in the room • Define internal policies for the safe use of AI-assisted and vibe-coding tools • Define security requirements for acquired technology and guide its secure integration Threat Modelling & Design Review: • Establish and run a threat-modelling operating model, covering scope, cadence, templates, and facilitation, proportionate to each product's risk tier • Own the security review stage of the new product approval process, covering architecture design and configuration • Lead design reviews for high-impact initiatives: new products, new auth flows, payment and sensitive-data flows, platform migrations, and major refactors • Identify design-level risks and agree practical, prioritised mitigations with engineering teams Secure SDLC, DevSecOps & Supply Chain: • Assess the current state of application security, propose improvements, and drive the secure SDLC strategy with Engineering and Security leadership • Oversee AppSec processes and own the tooling strategy (SAST, DAST, IAST, SCA, and secrets scanning), including how findings flow back to engineering • Embed security controls as guardrails in CI/CD through policy-as-code, with agreed enforcement and escalation paths • Partner with DevOps to organise repository management and prevent supply-chain attacks, covering safe component usage, dependency management, SBOMs, and build integrity • Improve the security of our internal tools

Requirements

Experience: • 8+ years in technology, including 5+ years in a dedicated application or product security role, with a strong engineering background and hands-on architecture or design ownership • Proven track record creating, documenting, and rolling out security standards, patterns, and best practices across a complex engineering organisation • Deep, demonstrable threat-modelling experience across product portfolios Technical: • Experience designing and implementing a secure SDLC in a cloud-native environment. Strong AWS knowledge is required, and exposure to GCP or other clouds is welcome • Strong command of OWASP standards (Top 10, ASVS) and DevSecOps practice, including AppSec tooling (SAST, DAST, IAST, SCA, secrets scanning) and vulnerability management • Deep understanding of modern distributed architectures: microservices, REST and GraphQL APIs, event-driven systems, OAuth2/OIDC, and containerised workloads (Docker, Kubernetes). You should be able to reason about their trust boundaries, attack surface, and data flows across web and mobile clients Collaboration: • Exceptional ability to influence and align engineering teams without direct authority, and to brief both engineers and executives • Pragmatism and strategic thinking: you balance the ideal with the achievable, protect delivery throughput, and turn long-term direction into an actionable plan • Clear written communication through diagrams, ADRs, and patterns, plus a track record of mentoring and cross-functional collaboration

Skills

Visa and relocation

The posting doesn't mention visa sponsorship. Check the original posting or ask the company.

The posting doesn't mention relocation.

Job description

Responsibilities: Security Architecture & Standards: • Define and maintain secure-by-default reference architectures for common patterns: web apps, mobile backends, microservices, public and partner APIs, and event-driven services • Own core application security architecture decisions: authentication and authorisation, session management, API security, secrets management, multi-tenant isolation, and security logging and auditing • Lead the redesign of user authentication and the delivery of security features into the product • Develop and roll out application security standards, secure-coding guidelines, configuration standards, reusable design patterns, and architecture decision records (ADRs) that engineers can apply without a security expert in the room • Define internal policies for the safe use of AI-assisted and vibe-coding tools • Define security requirements for acquired technology and guide its secure integration Threat Modelling & Design Review: • Establish and run a threat-modelling operating model, covering scope, cadence, templates, and facilitation, proportionate to each product's risk tier • Own the security review stage of the new product approval process, covering architecture design and configuration • Lead design reviews for high-impact initiatives: new products, new auth flows, payment and sensitive-data flows, platform migrations, and major refactors • Identify design-level risks and agree practical, prioritised mitigations with engineering teams Secure SDLC, DevSecOps & Supply Chain: • Assess the current state of application security, propose improvements, and drive the secure SDLC strategy with Engineering and Security leadership • Oversee AppSec processes and own the tooling strategy (SAST, DAST, IAST, SCA, and secrets scanning), including how findings flow back to engineering • Embed security controls as guardrails in CI/CD through policy-as-code, with agreed enforcement and escalation paths • Partner with DevOps to organise repository management and prevent supply-chain attacks, covering safe component usage, dependency management, SBOMs, and build integrity • Improve the security of our internal tools Requirements: Experience: • 8+ years in technology, including 5+ years in a dedicated application or product security role, with a strong engineering background and hands-on architecture or design ownership • Proven track record creating, documenting, and rolling out security standards, patterns, and best practices across a complex engineering organisation • Deep, demonstrable threat-modelling experience across product portfolios Technical: • Experience designing and implementing a secure SDLC in a cloud-native environment. Strong AWS knowledge is required, and exposure to GCP or other clouds is welcome • Strong command of OWASP standards (Top 10, ASVS) and DevSecOps practice, including AppSec tooling (SAST, DAST, IAST, SCA, secrets scanning) and vulnerability management • Deep understanding of modern distributed architectures: microservices, REST and GraphQL APIs, event-driven systems, OAuth2/OIDC, and containerised workloads (Docker, Kubernetes). You should be able to reason about their trust boundaries, attack surface, and data flows across web and mobile clients Collaboration: • Exceptional ability to influence and align engineering teams without direct authority, and to brief both engineers and executives • Pragmatism and strategic thinking: you balance the ideal with the achievable, protect delivery throughput, and turn long-term direction into an actionable plan • Clear written communication through diagrams, ADRs, and patterns, plus a track record of mentoring and cross-functional collaboration Nice to have: • Experience in fintech, trading, brokerage, or another regulated environment • Awareness of relevant regulatory and compliance drivers: FCA and CySEC operational resilience, GDPR, and PCI DSS • Software supply-chain security, including SBOMs and artifact and build integrity • Experience securing AI-integrated product features, or using AI to scale an AppSec programme • Experience building or running a Security Champions programme • CSSLP, GIAC GDSA, or a hands-on offensive security certification. Certifications are valued but secondary to demonstrated experience What you'll get in return: • You will join the company, that cares about work and life balance • Annual Bonus based on the performance review cycle • Generous Annual Leave Policy • Medical Insurance and Pension fund, with additional benefit packages based on the location • Hybrid working model (3 days from our modern office and 2 days fully remotely) • Comprehensive Workation Policy with 30 more remote days available. • Possibility of taking two additional days of paid leave per year to dedicate to volunteering efforts.
Apply on the original site ↗Job source: Company's official careers site

GetGlobalJob is not the employer or a recruiting agency. You apply on the original publisher's site: always check the posting before sharing your details, and never pay for a job.

Check your fit for this job

Create your free account and upload your CV to see how well you match this job and which skills you're missing.

Check my fit